Penetration Tester - Bristol
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Plan and deliver penetration tests across networks, systems, and applications, identifying vulnerabilities and security weaknesses
- Carry out detailed vulnerability assessments, security audits, and risk analysis, producing clear reports with practical remediation guidance
- Work alongside the red team to run realistic attack simulations and evaluate client security controls
- Build and use exploitation tools to demonstrate real-world impact and help clients understand their risk exposure
- Write well-structured, client-ready reports covering findings, risk ratings, and recommended fixes
- Act as a key point of contact for clients by scoping engagements, presenting results, and advising on how to strengthen their security posture
- Keep up to date with emerging threats and testing techniques, and continually refine tools and methodology
- Take on elements of project and client management as part of engagement delivery
Technologies:
- Network
- Security
Requirements
- A degree in Computer Science, Cyber Security, Information Security, or a related discipline
- CHECK Team Member, CREST Registered Tester, or an equivalent recognised certification
- At least 2 years of hands-on experience in penetration testing and vulnerability assessment
- Solid grounding in network protocols, operating systems, and core security technologies
- Confident use of tools such as Metasploit, Burp Suite, and Nmap
- Strong analytical and problem-solving skills, with genuine curiosity about current threats and attack techniques
- Comfortable communicating technical findings clearly to both technical teams and senior stakeholders
- Able to work independently on client sites as well as collaboratively within a wider consulting team
- Confident presenting and delivering training where required
- Beneficial, but not essential: code review experience
- Beneficial, but not essential: exposure to audit frameworks such as ISO 27001, CTAS, or CAS(T)
- Beneficial, but not essential: experience mentoring or informally leading within a technical team
About the company
We are a well-established and highly regarded cyber security consultancy delivering high-end penetration testing, vulnerability assessment, and red teaming services to clients across critical sectors including telecoms, finance, defence, rail, and aerospace. Our team has a strong track record of working on complex, high-stakes engagements ranging from national infrastructure projects to global enterprise clients. This role is based out of our Bristol office with regular travel to client sites. You will join a collaborative technical team with real investment in development, including funded certifications, access to modern tooling, and the chance to contribute to wider security research initiatives. Performance-based incentives sit on top of a competitive base salary.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities