Infrastructure Penetration Tester

Digital Waffle
Charing Cross, United Kingdom
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
£ 80K

Job location

Charing Cross, United Kingdom

Tech stack

Microsoft Windows
Microsoft Active Directory
Amazon Web Services (AWS)
Software System Penetration Testing
Azure
Burp Suite
Cloud Computing
Linux
Network Service
NMap
Metasploit
Nessus

Job description

Deliver internal and external network and infrastructure penetration tests, including on-premises and cloud-hosted environments * Perform testing of Windows & Linux infrastructure, Active Directory, network services, and security appliances * Conduct vulnerability exploitation, privilege escalation, and lateral movement to demonstrate full attack paths * Lead small engagement teams and oversee delivery quality, documentation, and client communication * Produce high-quality, concise, and risk-aligned reports with actionable remediation guidance * Support scoping calls, stakeholder workshops, and post-engagement debriefs * Contribute to tooling, methodology enhancement, and internal research initiatives * Stay up-to-date with emerging vulnerabilities, exploits, and attacker techniques

Requirements

We are seeking an experienced Senior Penetration Tester with a strong background in infrastructure security testing to join a growing offensive security team. The ideal candidate will have deep technical expertise, the ability to lead and independently deliver complex engagements, and a passion for uncovering and exploiting vulnerabilities across enterprise environments. You will play a key role in strengthening the organisation's security posture by conducting infrastructure-focused assessments, mentoring junior testers, and influencing remediation strategies., * 3-5+ years' professional penetration testing/offensive security experience * Strong understanding of enterprise infrastructure, AD security, networking, and protocols * Proficiency with tools such as Nmap, Nessus, Metasploit, BloodHound, Burp Suite, Kali/Linux toolsets * Solid track record of delivering infrastructure pentests end-to-end * Excellent communication skills, including producing business-focused reporting

Preferred Qualifications * CHECK Team Member (CSTM) or CHECK Team Leader (CTL) * CREST CRT/CCT, OSCP, OSEP, or equivalent recognised industry certifications * Experience in cloud infrastructure testing (Azure/AWS), desirable but not essential * SC or DV clearance beneficial (or eligibility to obtain it)

Apply for this position