Penetration Tester
Role details
Job location
Tech stack
Job description
test reports to understand technical impact, exploitability, and business risk.* Develop, document and maintain remediation guidance, patterns, and blue-prints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations).* Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-level and business-level recommendations.* Coordinate remediation activities across multiple teams, ensuring, clear ownership, agreed timelines, and risk-based prioritization.* Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure.* Manage and track the remediation backlog, including SLAs, aging finings, and critical issues when needed.* Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes.* Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners.* Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions.* Contribute to continuous improvement of the pentest-to-remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines.* Compile technical documents, track and document remediation metadata + Engagement details (who, what, when, where) + Testing team members and roles + Tools and methodologies used + Schedule and timelines + Target systems and environments + Constraints, exclusions, and limitations + Testing activities and event logs* Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references.* Contribute to the continuous improvement of testing methodologies, tooling, automation.* Stay ahead of with emerging threats, vulnerabilities, and, OverviewThis job is brought to you by Jobs/Redefined, the UK's leading over-50s age inclusive jobs board. The Role: The Vulnerability Management Manager is a global role within ION's central services division and will support the Group Security strategy and operational..., Delivery Team Lead - SAP | D365 | Oracle at Boss ERP Consulting We are seeking an experienced DV cleared Senior Strategic Tester who will serve as a critical advisor to the end client, shaping and overseeing all testing strategy, planning, and assurance activities across..., 3 weeks ago Be among the first 25 applicants We are looking for a Security Engineer. You'll be directly responsible for safeguarding Ometria's digital assets by actively managing risks to maintain a secure and resilient environment. You will work closely with our Product..., Platform Security Engineer - ION Location: London, United Kingdom The RoleION Markets Information Security Team is looking to hire a Platform Security Engineer that supports the division's security strategy through definition and implementation of security controls across...
Requirements
offensive security techniques.* Participate in R&D initiatives as guided from leadership.* Support knowledge sharing and mentoring within the team.Required Skills & Experience* Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud-native based environments).* Proficiency with tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed.* Experience in automating pentesting tasks.* Solid understanding of application security, network protocols, and operating systems.* Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes).* Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least on major language stack (e.g. Java/Springboot, .NET, JavaScript/Node, Python)* Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners.* Experience working in large, complex enterprise environments.* Proficient communication skills in English, both written and verbal.* Relevant certifications and engagement with the security community is a plus* Threat Modelling experience is a plus.* Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles.* Ability to identify, assess, and communicate technical and project risks to partners.* Understanding project requirements and aligning work with agreed upon objectives and timelines.**Career Stage:Senior AssociateLondon Stock Exchange Group (LSEG) Information:**Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.LSEG is a leading global, financial markets, Are you ready to take the lead in offensive security? Join a multi-award-winning cybersecurity provider recognised for delivering world-class managed security services, CREST-accredited penetration testing, and cutting-edge cyber defence strategies. With a proven track..., Senior Penetration Tester If you're passionate about security and privacy, and want to use your offensive security skills to help safeguard private, uncensored access to the internet for millions of customers, we'd love to speak with you.Who you are You're a natural at...
Benefits & conditions
Tier 2 (Manchester, Birmingham, Edinburgh, Bristol): 89,600 GBP - 134,400 GBP Final salary will be determined based on several factors, including a candidate's qualifications, skills, competencies, experience, expertise, education and location. In some cases, final...