> Markdown version of [/jobs/ext/1252261-penetration-tester-web-api-cloud-security-equity-only](https://www.wearedevelopers.com/jobs/ext/1252261-penetration-tester-web-api-cloud-security-equity-only). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - Web, API & Cloud Security(Equity Only) - **Company:** HolistiQ Holdings - **Location:** UK (Remote available) - **Salary:** £30,472.0 - £81,673.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Business Logic, Software System Penetration Testing, User Authentication, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing, Cloud Computing Security, Databases, Identity and Access Management, Mobile Application Software, Python (Programming Language), Network Security, Nmap, Open Web Application Security, Windows PowerShell, Regression Testing, Comptia Pentest+ CE, Secure Coding, Web Application Security, SQL Injection, Software Vulnerability Management, Web Applications, Web Platforms, Software Security, Kubernetes, Metasploit, Devsecops, Docker, Vulnerability Analysis - **Published:** July 13, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=67d094f58cc096df ## About the Role Practical experience in penetration testing, ethical hacking, vulnerability assessment, web application security, API security, network security, cloud security, Burp Suite, Nmap, OWASP, authentication testing, access control testing, exploit validation, vulnerability remediation, and technical security reporting. Experience with AWS, Azure, Docker, Kubernetes, CI/CD security, mobile application security, secure code review, Python, Bash, PowerShell, Metasploit, SQL injection testing, privilege escalation, or DevSecOps is advantageous. Certifications such as OSCP, OSWE, OSEP, BSCP, CREST, PNPT, CompTIA PenTest+, Security+, eJPT, eCPPT, or equivalent practical experience are desirable but not essential. ## Description HolistiQ Technologies is seeking a skilled Penetration Tester / Ethical Hacker to identify, exploit, document, and help remediate security vulnerabilities across web applications, APIs, cloud infrastructure, authentication systems, databases, mobile applications, and digital platforms. You will work alongside software engineers, technical architects, and cybersecurity professionals to secure projects throughout development, launch, and ongoing production operation., * Conduct web application, API, cloud, infrastructure, and mobile penetration testing. * Identify and safely exploit vulnerabilities, authentication flaws, broken access controls, API vulnerabilities, and business logic weaknesses. * Perform vulnerability assessments, security testing, exploit validation, and security regression testing. * Test against OWASP Top 10 and OWASP API Security Top 10 vulnerabilities. * Produce professional penetration testing reports with evidence, severity ratings, business impact, and remediation recommendations. * Retest vulnerabilities and verify security fixes. * Perform security testing following material platform updates and production changes. * Immediately escalate critical vulnerabilities and security incidents. * Work collaboratively with developers and security teams to improve application and infrastructure security. * Conduct all testing within documented scope and written Security Testing Authorisations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)