> Markdown version of [/jobs/ext/1999282-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1999282-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** Citation Ltd - **Location:** Cardiff, UK - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cyber Security, Linux, Python (Programming Language), Wireless Security, Windows PowerShell, Web Applications, SC Clearance - **Published:** August 9, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/43176635/ ## About the Role About Citation CyberCitation Cyber is one of the UK's leading cyber security consultancies, delivering penetration testing, Cyber Essentials certification, consultancy, training and managed cyber security services to organisations across both the public and private sectors.As an NCSC CHECK provider and CREST member company, we're continuing to grow our penetration testing team and are looking for a talented Security Consultant to join us.Whether you're already a CHECK Team Member (CTM) or you're an experienced penetration tester ready to take that next step, we'd love to hear from you. The RoleYou'll work as part of our penetration testing team delivering a wide range of technical security assessments across client environments, helping organisations identify vulnerabilities and strengthen their cyber resilience.Your work will include:Infrastructure or Web application penetration testingCloud security assessmentsProducing clear, high-quality technical reportsPresenting findings and remediation advice to clientsSupporting vulnerability validation and re-testingContributing to internal tooling, research and knowledge sharing What we're looking forEssentialCommercial penetration testing experience within a consultancy or equivalent environmentStrong technical reporting skillsExperience conducting infrastructure and web application penetration testsGood understanding of Windows, Linux and Active Directory environmentsFamiliarity with Azure and/or AWS security testingExperience using industry-standard penetration testing tools and methodologiesExcellent written and verbal communication skillsA passion for continuous learning and technical development DesirableCurrent CHECK Team Member (CTM) statusCurrent SC Security Clearance (or eligibility to obtain it)CREST CRT / Cyber Scheme CSTM or equivalent certificationOSCP or equivalent practical penetration testing certificationExperience with API, mobile or wireless security testingScripting or automation experience using Python, PowerShell or Bash Why Join Citation Cyber?We're building a consultancy where technical excellence, innovation and professional development go hand in hand.When you join us you'll benefit from:Working for an NCSC CHECK provider and CREST memberA varied mix of commercial, defence and public sector projectsFunded training and industry certificationsClear progression towards CHECK Team Member, CHECK Team Leader and senior technical rolesHybrid and flexible workingA collaborative technical culture where knowledge sharing is encouragedOpportunities to contribute to research, tooling and new service developmentCompetitive salary and benefits About YouYou're passionate about offensive security and enjoy solving complex technical challenges. You produce high-quality work, communicate clearly with clients and are always looking to improve your skills.Whether you're already delivering CHECK assessments or you're looking to achieve CHECK status in the near future, you'll be joining a team that will support your professional development and provide exposure to challenging and rewarding engagements.Ready to Apply?If you're looking to take the next step in your penetration testing career and want to work with an ambitious, growing cyber security consultancy, we'd love to hear from you. ## Description Security Consultant (Penetration Testing)Location: Hybrid (UK)Salary: Competitive + BenefitsSecurity Clearance: Current SC preferred ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)