Penetration Tester

Worknest Secure
Stevenage, UK
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Microsoft Windows Active Directory Amazon Web Services Software System Penetration Testing Microsoft Azure Mobile Application Software Linux System Administration Open Web Application Security Phishing Web Applications Information Technology Wireless Technologies
+1 more
Vulnerability Analysis

Job description

  • Perform formal and comprehensive application, infrastructure and other penetration testing assessments where appropriate and required
  • Provide well-written, concise, technical and non-technical reports in English
  • Perform vulnerability assessments and provide findings with remediation actions
  • Support with various client pre-engagement interactions, including scoping activities and proposal drafting to ensure that client needs are met
  • Manage and deliver penetration testing project activities within strict deadlines
  • Support the QA process to ensure high quality client reports are delivered in accordance with applicable Service Level Agreement (SLA)
  • Any other appropriate job duties in line with the associated skill and experience of the post holder

Requirements

  • Proven industry experience in application and infrastructure penetration testing
  • CTM Status
  • Deep knowledge of assessing both Windows and Linux environments, including strong knowledge of Active Directory and wireless technologies
  • Ability in preparing and launching social engineering campaigns (both phishing and vishing)
  • Strong understanding of OWASP, PTES and other penetration testing methodologies
  • Knowledge of how modern web apps are designed, developed and deployed across different platforms
  • Ability to program or script in your preferred language
  • Relevant degree in Computer Science, Ethical Hacking, Engineering or other relevant subject
  • Relevant security qualifications (such as OSCP, CEH, GPEN)
  • Good knowledge and understanding of network and OS principles
  • Good knowledge of various operating systems
  • Good knowledge of virtualisation

Nice to have:

  • Knowledge of assessing cloud and hybrid environments (AWS and Azure)
  • Knowledge of assessing mobile applications (iOS/Android)
  • Knowledge of assessing hardware and embedded IoT devices, * Excellent spoken and written communication skills with strong attention-to-detail and accuracy
  • A passion for security and networks
  • Analytical and problem-solving skills with a can-do attitude and the ability to think laterally
  • Self-motivation with a commitment to continued development
  • Ability to work independently and as part of a team
  • Influencing and negotiation skills with the ability to build relationships at all levels
  • Willingness to learn

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Company pension
  • Private medical insurance
  • Discounted gym membership, * 25 days annual leave plus birthday leave
  • Company pension
  • Subsidised gym membership
  • Employee benefits platform
  • Regular team events
  • Private healthcare (individual cover)
  • Learning allowance for personal development
  • Flexible working policy

If you’re passionate about offensive security and committed to technical excellence, we’d love for you to join our team.

About the company

At WorkNest Secure, we help organisations strengthen their cyber security posture through industry-leading security services and solutions. As we continue to grow, we’re looking for talented CHECK Team Members to join our Offensive Security team as Offensive Security Consultants (Penetration Testers).

This is an exciting opportunity to join a fast-growing cyber security business, where you’ll play a key role in helping our clients identify and mitigate security risks. You’ll deliver CHECK-accredited penetration tests across a range of technologies and environments, providing clear, actionable insights that help organisations remain secure and resilient. Working alongside a highly skilled team, you’ll have the opportunity to contribute to challenging engagements, develop your expertise, and make a meaningful impact for our clients.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · WWC 2023

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

3:18 min

Eliminating passwords using Azure managed identities

Markus Möller · WWC 2021

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

Videos

See all

Related articles

See all