Penetration Tester - Bristol

Oscar Associates Ltd
Bristol, UK
1 day ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
£45,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Burp Suite Code Review Cyber Security Network Protocols Nmap Red Team (Cyber Security) Information Technology Metasploit Vulnerability Analysis

Job description

  • Plan and deliver penetration tests across networks, systems, and applications, identifying vulnerabilities and security weaknesses
  • Carry out detailed vulnerability assessments, security audits, and risk analysis, producing clear reports with practical remediation guidance
  • Work alongside the red team to run realistic attack simulations and evaluate client security controls
  • Build and use exploitation tools to demonstrate real-world impact and help clients understand their risk exposure
  • Write well-structured, client-ready reports covering findings, risk ratings, and recommended fixes
  • Act as a key point of contact for clients by scoping engagements, presenting results, and advising on how to strengthen their security posture
  • Keep up to date with emerging threats and testing techniques, and continually refine tools and methodology
  • Take on elements of project and client management as part of engagement delivery

Technologies:

  • Network
  • Security

Requirements

  • A degree in Computer Science, Cyber Security, Information Security, or a related discipline
  • CHECK Team Member, CREST Registered Tester, or an equivalent recognised certification
  • At least 2 years of hands-on experience in penetration testing and vulnerability assessment
  • Solid grounding in network protocols, operating systems, and core security technologies
  • Confident use of tools such as Metasploit, Burp Suite, and Nmap
  • Strong analytical and problem-solving skills, with genuine curiosity about current threats and attack techniques
  • Comfortable communicating technical findings clearly to both technical teams and senior stakeholders
  • Able to work independently on client sites as well as collaboratively within a wider consulting team
  • Confident presenting and delivering training where required
  • Beneficial, but not essential: code review experience
  • Beneficial, but not essential: exposure to audit frameworks such as ISO 27001, CTAS, or CAS(T)
  • Beneficial, but not essential: experience mentoring or informally leading within a technical team

About the company

We are a well-established and highly regarded cyber security consultancy delivering high-end penetration testing, vulnerability assessment, and red teaming services to clients across critical sectors including telecoms, finance, defence, rail, and aerospace. Our team has a strong track record of working on complex, high-stakes engagements ranging from national infrastructure projects to global enterprise clients. This role is based out of our Bristol office with regular travel to client sites. You will join a collaborative technical team with real investment in development, including funded certifications, access to modern tooling, and the chance to contribute to wider security research initiatives. Performance-based incentives sit on top of a competitive base salary.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

Videos

See all

Related articles

See all