Penetration Tester (25826)
Letterkenny - Ireland
Job Summary
Job Type: Permanent
Location: Letterkenny GDC Co. Donegal (Hybrid - 2 days onsite per week)
Careers at TCS: It means more
TCS is a purpose-led transformation company built on belief. We do not just help businesses to transform through technology. We support them in making a meaningful difference to the people and communities they serve - our clients include some of the biggest brands in the UK and worldwide. For you it means more to make an impact that matters through challenging projects which demand ambitious innovation and thought leadership.
- Gain access to endlesslearning opportunities.
- Fast track your growth with diverse career opportunities internally.
- Grow your career while being exposed to new technologies.
The Role
Responsible for planning and executing penetration testing engagements across web applications APIs cloud platforms mobile applications and infrastructure environments. Conduct vulnerability assessments performs manual security testing and validate exploitable weaknesses using industry-recognised methodologies and frameworks. Analyse security risks assess business impact and develop practical remediation recommendations to reduce organisational exposure. Produce detailed technical and executive reports communicate findings to stakeholders and support remediation validation through re-testing activities. Contribute to continuous improvement of security testing processes standards and knowledge sharing across the cyber security function.
Your responsibilities:
- Plan and scope penetration testing engagements including defining objectives rules of engagement testing methodologies (Black Box Gray Box White Box) schedules and target attack surfaces.
- Perform reconnaissance and information gathering to identify exposed services technologies APIs integrations and potential attack vectors within the target environment.
- Conduct vulnerability assessments using approved security scanning tools validating results eliminating false positives and prioritizing findings based on risk and business impact.
- Execute manual penetration testing across web applications APIs mobile applications cloud environments and infrastructure to identify security weaknesses not detected through automated methods.
- Assess application and infrastructure security controls including authentication authorization session management access controls encryption and secure configuration practices.
- Perform advanced security testing activities including business logic testing abuse-case testing exploit validation and verification of OWASP Top 10 and API Security Top 10 vulnerabilities.
- Analyse and assess risk exposure by determining the technical and business impact of identified vulnerabilities and developing realistic attack scenarios and exploitation paths.
- Produce and present penetration testing reports documenting findings evidence proof-of-concepts remediation recommendations and executive risk summaries for stakeholders.
- Support remediation and re-testing activities validating implemented fixes confirming closure of vulnerabilities and assisting with risk acceptance and exception review processes.
- Maintain governance and continuous improvement adhering to recognised frameworks such as OWASP NIST OSSTMM and ISSAF while contributing to testing methodologies playbooks knowledge sharing audits compliance activities and mentoring junior team members.
Essential skills/knowledge/experience:
- Web Application API and Mobile Application Security Testing.
- Network and Infrastructure Penetration Testing.
- Cloud Security Testing (AWS Azure GCP).
- Vulnerability Assessment and Risk Analysis.
- Authentication and Authorization Testing.
- Secure Coding and SDLC awareness
- Threat Modeling and Attack Surface Analysis.
- Security Reporting and Risk Communication
- Experience in the following tools : Burp Suite Nessus Metasploit Wireshark Nmap OWASP ZAP Core Impact (preferred) mobile application testing tools and custom exploitation scripts.
- Experience in Web API Mobile Cloud and Infrastructure security assessments.
- Proven experience conducting manual penetration testing and vulnerability validation.
- Certification (Desirable): CompTIA Security CVA OSCP OWSE CEH GWAPT GPEN CRTO CISSP
TCS is consistently voted a Top Employer in the UK and globally. Our competitive salary packages feature pension health care life assurance laptop and access to extensive training resources and discounts within the larger Tata network.
We offer health & wellness initiatives and sports events; we are the proud sponsor of the London Marathon and partner with our local communities in Ireland.
Diversity Inclusion and Wellbeing
Tata Consultancy Services UK&I is committed to meeting the accessibility needs of all individuals in accordance with the Ireland Employment Equality Acts 1998-2011 (as amended) and the Equal Status Acts 2000-2012 (as amended).
We welcome and embrace diversity in race nationality ethnicity disability neurodiversity gender identity age physical ability gender reassignment sexual orientation. We are a disability inclusive employer and encourage disabled people to apply for this role.
As a Disability Confident Employer we offer an interview to applicants with disabilities or long-term conditions who meet the minimum criteria for the role. Please email us at if you would like to opt in.
If you are an applicant who needs any adjustments to the application process or interview please contact us with the subject line: Adjustment Requestto request an adjustment. We welcome requests prior to you completing the application and at any stage of the recruitment process.
Beware of Fraudulent offers
This is to notify you that TCS does not ask for any sort of payment or security deposit from candidates at any stage of the recruitment process. The firm never sends out job offers from free internet email services like Gmail Yahoo Mail and so on. TCS has not authorised any third-party company to collect money on their behalf. As a vigilant job seeker beware of fraudulent recruitment activity and protect your interests! You can write to to report any fraudulent activity.
Due to the high volume of applications we will be unable to contact each applicant individually on the status of their application. If you have not received a direct response within 30 days then it should be deemed unsuccessful on this occasion.
Join us and do more of what matters. Apply online now.
About Company
We strongly believe global challenges need global solutions. We are continually engaging with our employees, clients, partners, public institutions, and community organisations across the world to step up and rise to the occasion. We are #OneTCS. A part of the Tata group, India's lar ... View more