Penetration Tester

Big Red Recruitment
London, UK
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
£40,000.0 - £45,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Apple Mac Systems Software System Penetration Testing Burp Suite Cyber Security Computer Networks Linux Routing Nmap Web Application Security Service Development Studio Wireshark
+6 more
Web Applications SC Clearance Metasploit Nessus Operational Systems Vulnerability Analysis

Job description

We are seeking a Penetration Tester to join a growing Offensive Security team within a specialist cyber security consultancy. This is an exciting opportunity to join at a time of significant investment and growth, helping to strengthen existing testing services while contributing to the development of new capabilities across areas such as Red Teaming, Operational Technology (OT), Threat-Led Security Testing and emerging technologies.

The successful candidate will play a key role in delivering penetration testing engagements, supporting process improvement initiatives, and helping to build a scalable and mature testing function. This position offers excellent opportunities for professional development, certification support and future progression into senior or leadership positions., * Conduct vulnerability assessments and penetration testing engagements across:

  • Internal infrastructure
  • External infrastructure
  • Web applications
  • Networks and systems
  • Perform configuration and build reviews using recognised security frameworks and benchmarks.
  • Produce clear, concise and actionable technical reports detailing findings, risk ratings and remediation recommendations.
  • Utilise industry-standard security testing tools including Burp Suite, Nessus, Metasploit, Nmap, Wireshark and related technologies.
  • Work directly with clients and stakeholders, presenting findings and providing remediation guidance where required.
  • Support the continuous improvement of testing methodologies, processes and documentation.
  • Assist in creating and maintaining standard operating procedures, testing guides and knowledge-sharing materials.
  • Collaborate with wider cyber security teams to support service development and research initiatives.
  • Contribute to research and development activities across new security testing disciplines and technologies.
  • Participate in occasional out-of-hours and on-site engagements where client requirements dictate.

Requirements

  • Minimum 2 years’ experience in penetration testing, vulnerability assessment or offensive security.
  • Experience conducting:
  • Internal and external infrastructure testing
  • Web application security testing
  • Security assessments and audits
  • Vulnerability identification and validation
  • Strong understanding of networking concepts, protocols, routing and firewall technologies.
  • Experience working with Windows, Linux and macOS environments.
  • Familiarity with security assessment tools such as:
  • Burp Suite
  • Nessus
  • Metasploit
  • Nmap
  • Wireshark
  • Experience producing high-quality technical reports and client-facing documentation.
  • Excellent communication and stakeholder management skills.
  • Strong organisational skills and ability to manage workload independently.
  • Comfortable working in a consultancy or client-facing environment.
  • Eligible to obtain UK Security Clearance.

Desirable Skills & Certifications

  • CREST CRT, CPSA, CCT or equivalent certification.
  • OSCP or similar offensive security qualification.
  • Cyber Scheme accreditation.
  • CHECK Team Member status.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

58 sec

Securing uncontaminated AI training data and mandating Linux authentication

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all