> Markdown version of [/jobs/ext/1444751-security-consultant-ii-web-application-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1444751-security-consultant-ii-web-application-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Consultant II (Web Application Penetration Tester) - **Company:** NetSPI - **Location:** Manchester, UK - **Experience:** Experienced - **Salary:** £33,242.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Application Programming Interfaces (APIs), Apple Mac Systems, Software System Penetration Testing, Burp Suite, C Sharp (Programming Language), C++ (Programming Language), CompTIA Security+, Computer Programming, Linux, Perl (Programming Language), Python (Programming Language), Kali Linux, Open Web Application Security, Ruby, Web Applications, Scripting, GWAPT, Information Technology, Metasploit, Nessus, Workday - **Published:** July 26, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5815364971 ## About the Role * Bachelor's degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience * Minimum of 2-3 years of work experience in application penetration testing * Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus) * Familiarity with offensive and defensive IT concepts and protocols * Extensive understanding of the OWASP Top 10 and various security frameworks. * Working knowledge of Windows, Linux and MacOS operating systems internals * Ability to work independently and as part of a team * Proficient communication skills, both written and verbal * Willingness to travel up to 5-10% * This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs Preferred Qualifications: * Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences * Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#) * Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT) ## Description Join the mission as a Security Consultant II. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices. Responsibilities: * Conduct penetration testing engagements on web applications and underlying APIs. * Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture. * Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes * Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Fireside Chat with Werner Vogels, VP & CTO, Amazon.com & Daniel Gebler, CTO at Picnic](https://www.wearedevelopers.com/videos/1405-fireside-chat-with-werner-vogels-vp-cto-amazon-com-daniel-gebler-cto-at-picnic) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)