> Markdown version of [/jobs/ext/2159775-penetration-tester-bristol](https://www.wearedevelopers.com/jobs/ext/2159775-penetration-tester-bristol). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - Bristol - **Company:** Oscar Associates Ltd - **Location:** Bristol, UK - **Experience:** Experienced - **Salary:** £45,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, Code Review, Cyber Security, Network Protocols, Nmap, Red Team (Cyber Security), Information Technology, Metasploit, Vulnerability Analysis - **Published:** August 21, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5849539993 ## About the Role * A degree in Computer Science, Cyber Security, Information Security, or a related discipline * CHECK Team Member, CREST Registered Tester, or an equivalent recognised certification * At least 2 years of hands-on experience in penetration testing and vulnerability assessment * Solid grounding in network protocols, operating systems, and core security technologies * Confident use of tools such as Metasploit, Burp Suite, and Nmap * Strong analytical and problem-solving skills, with genuine curiosity about current threats and attack techniques * Comfortable communicating technical findings clearly to both technical teams and senior stakeholders * Able to work independently on client sites as well as collaboratively within a wider consulting team * Confident presenting and delivering training where required * Beneficial, but not essential: code review experience * Beneficial, but not essential: exposure to audit frameworks such as ISO 27001, CTAS, or CAS(T) * Beneficial, but not essential: experience mentoring or informally leading within a technical team ## Description * Plan and deliver penetration tests across networks, systems, and applications, identifying vulnerabilities and security weaknesses * Carry out detailed vulnerability assessments, security audits, and risk analysis, producing clear reports with practical remediation guidance * Work alongside the red team to run realistic attack simulations and evaluate client security controls * Build and use exploitation tools to demonstrate real-world impact and help clients understand their risk exposure * Write well-structured, client-ready reports covering findings, risk ratings, and recommended fixes * Act as a key point of contact for clients by scoping engagements, presenting results, and advising on how to strengthen their security posture * Keep up to date with emerging threats and testing techniques, and continually refine tools and methodology * Take on elements of project and client management as part of engagement delivery Technologies: * Network * Security ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)