Job Title: Penetration Tester
Location: UK
Job Type: Permanent / Contract
Work Arrangement: On-site / Hybrid / Remote
Salary: 65000-85000
---
About the Role:
We are seeking a skilled Penetration Tester to join our client s security team and help identify exploit and remediate vulnerabilities in complex environments. You will simulate real-world attacks to assess the effectiveness of defensive mechanisms report on weaknesses and support strategic improvements to security posture.
---
Key Responsibilities:
Perform penetration tests on web applications APIs internal/external infrastructure mobile apps cloud platforms and physical environments.
Conduct vulnerability assessments and exploit weaknesses in systems using both manual techniques and automated tools.
Develop and deliver clear actionable technical and executive-level reports on findings and remediation.
Collaborate with internal teams (IT DevSecOps Network Engineering) to understand environments and advise on secure architecture.
Keep up to date with the latest threats tools and techniques in offensive security.
Support red teaming social engineering and physical security assessments (as required).
Contribute to the development and enhancement of internal tools methodologies and testing frameworks.
---
Required Skills & Experience:
Proven experience conducting penetration tests in real-world environments.
Strong knowledge of security testing tools (e.g. Burp Suite Nmap Metasploit Cobalt Strike Kali Linux etc.).
Proficiency in exploiting vulnerabilities and producing high-quality PoC reports.
Solid understanding of network protocols operating systems (Windows/Linux) and web technologies.
Scripting ability in Python Bash PowerShell or similar languages.
Experience with MITRE ATT&CK OWASP Top 10 and CVE-based assessments.
---
Certifications (Desirable):
OSCP (Offensive Security Certified Professional)
CREST CRT or CCT
GIAC GPEN / GWAPT / GXPN
eJPT eCPPT or equivalent
CHECK Team Member/Leader (if UK-based)
---
Ideal Candidate Profile:
Curious creative and detail-oriented mindset with a passion for ethical hacking.
Strong communication skills able to explain technical risks to non-technical stakeholders.
Comfortable working independently or within a team in fast-paced environments.