Penetration Tester - Web, API & Cloud Security(Equity Only)

HolistiQ Holdings
UK
29 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£30,472.0 - £81,673.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Business Logic Software System Penetration Testing User Authentication Microsoft Azure Bash Shell Burp Suite Cloud Computing Cloud Computing Security Databases Identity and Access Management
+20 more
Mobile Application Software Python (Programming Language) Network Security Nmap Open Web Application Security Windows PowerShell Regression Testing Comptia Pentest+ CE Secure Coding Web Application Security SQL Injection Software Vulnerability Management Web Applications Web Platforms Software Security Kubernetes Metasploit Devsecops Docker Vulnerability Analysis

Job description

HolistiQ Technologies is seeking a skilled Penetration Tester / Ethical Hacker to identify, exploit, document, and help remediate security vulnerabilities across web applications, APIs, cloud infrastructure, authentication systems, databases, mobile applications, and digital platforms.

You will work alongside software engineers, technical architects, and cybersecurity professionals to secure projects throughout development, launch, and ongoing production operation., * Conduct web application, API, cloud, infrastructure, and mobile penetration testing.

  • Identify and safely exploit vulnerabilities, authentication flaws, broken access controls, API vulnerabilities, and business logic weaknesses.
  • Perform vulnerability assessments, security testing, exploit validation, and security regression testing.
  • Test against OWASP Top 10 and OWASP API Security Top 10 vulnerabilities.
  • Produce professional penetration testing reports with evidence, severity ratings, business impact, and remediation recommendations.
  • Retest vulnerabilities and verify security fixes.
  • Perform security testing following material platform updates and production changes.
  • Immediately escalate critical vulnerabilities and security incidents.
  • Work collaboratively with developers and security teams to improve application and infrastructure security.
  • Conduct all testing within documented scope and written Security Testing Authorisations.

Requirements

Practical experience in penetration testing, ethical hacking, vulnerability assessment, web application security, API security, network security, cloud security, Burp Suite, Nmap, OWASP, authentication testing, access control testing, exploit validation, vulnerability remediation, and technical security reporting.

Experience with AWS, Azure, Docker, Kubernetes, CI/CD security, mobile application security, secure code review, Python, Bash, PowerShell, Metasploit, SQL injection testing, privilege escalation, or DevSecOps is advantageous.

Certifications such as OSCP, OSWE, OSEP, BSCP, CREST, PNPT, CompTIA PenTest+, Security+, eJPT, eCPPT, or equivalent practical experience are desirable but not essential.

Benefits & conditions

Successful candidates will be appointed as Contributor Members and participate in a profit-sharing model under which 60% of Net Profit from Projects is allocated collectively to eligible Contributor Members and distributed based on level of seniority and participation.

This is not a traditional employment opportunity. We are looking for someone who wants to help build, protect, and scale innovative technology platforms while sharing in the long-term value they create.

The salary field shown on Indeed is a platform requirement and should be treated as a placeholder only.

Pay: £30,471.56-£81,672.68 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

Videos

See all

Related articles

See all