> Markdown version of [/jobs/ext/1999330-security-pen-tester-infosec](https://www.wearedevelopers.com/jobs/ext/1999330-security-pen-tester-infosec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Pen Tester - InfoSec - **Company:** NEXT Retail Ltd. - **Location:** Leicester, UK - **Salary:** £47,928.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cyber Security, Cloud Platform System - **Published:** August 9, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5834467851 ## About the Role * Technical Expertise: Experience of professional pen testing experience supported by an OSCP, CREST CRT, or equivalent certification. * Analytical Thinking: A solution-oriented mindset with a deep understanding of operating systems, networking, and cloud environments like AWS, Azure, or GCP. * Communication Skills: The ability to translate complex technical risks into simple, actionable insights for everyone. * Adaptability: Comfort working independently or collaborating within a diverse team to solve complex problems. * Organisation: Excellent time management skills and the ability to scope tests effectively to meet business needs. * Professional Growth: A proactive approach to development and a willingness to share knowledge to help the wider team succeed. #LI-LE1 #LI-Hybrid ## Description At NEXT, we don't stand still. Enacting our 'Let's Take It On' spirit means pushing boundaries and learning to evolve. As part of the team, you will: * Plan and execute authorised pen tests across our networks, applications, and infrastructure to simulate security breaches and assess risk. * Identify security gaps caused by technical flaws or human error and advise on best-practice remediations. * Innovate with fresh testing methods, scripts, and automated tools to enhance our security posture. * Communicate technical risks through high-quality reports, explaining the potential business impact to stakeholders with clarity. * Collaborate with Detection Engineers and SOC teams to turn findings into long-term security playbooks. * Monitor the evolving threat landscape through continuous learning and collaboration with national cybersecurity bodies. ## Related Videos - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)