> Markdown version of [/jobs/ext/2255882-security-penetration-testing-engineer-london](https://www.wearedevelopers.com/jobs/ext/2255882-security-penetration-testing-engineer-london). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security / Penetration Testing Engineer - London - **Company:** Cognizant - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Business Logic, Software System Penetration Testing, Automation of Tests, Information Technology Consulting, Cross-Origin Resource Sharing (Ajax Programming), Cross-Site Request Forgery, Digital Technology, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Web Application Security, Session Management, Simple Object Access Protocol (SOAP), SQL Injection, Software Security, Test Scripts, Cross-Site Scripting (XSS), Rate Limiting, Bug Reporting, Information Technology, Graphql, Restful APIs - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815095577-security--penetration-testing-engineer--london ## About the Role * CREST certification (CRT/CPT/CPSA or equivalent) is a must. * Penetration Testing Expertise - Strong hands-on experience in API and UI/Web application penetration testing. * Security Standards Knowledge - OWASP Top 10, OWASP API Top 10, ASVS, CVSS scoring, and CREST methodologies. * API Security - REST/GraphQL/SOAP testing, OAuth2/OIDC, JWT handling, rate limiting, and authorization flaws (BOLA/BFLA). * Web Application Security - XSS, CSRF, SQL Injection, Clickjacking, session management, CSP/CORS issues. * Documentation & Reporting - Ability to create detailed test plans, risk logs, and clear vulnerability reports. * Compliance Awareness - Familiarity with ISO 27001, PCI-DSS, NIST guidelines. ## Description Security / Penetration Testing Engineer - London Role will be part of our Quality Engineering & Assurance (QE&A) Practice. With more than 650 clients across industry verticals and a global footprint, Cognizant QE&A practice is a recognized thought leader in quality engineering and Assurance. As enterprises simplify, modernize and secure their legacy environments for the digital era, robust quality Engineering and assurance is essential. Quality takes an end-to-end connotation and must straddle both legacy and digital systems. Cognizant QE&A is reimagining QE&A, employing an end-to-end ecosystem approach with intelligent and automated QA processes. In so doing, increasing quality and speed to promote faster business and technology change, as well as a better customer experience. Key Responsibilities * Gather security requirements and define penetration testing scope by reviewing design and interface documents. * Prepare detailed test plans, scenarios, and rules of engagement aligned with CREST and OWASP standards. * Conduct API penetration testing (REST, GraphQL, SOAP) focusing on authentication, authorization, and business logic flaws. * Perform UI/Web application penetration testing for vulnerabilities such as XSS, CSRF, SQL Injection, and session management issues. * Identify and document security issues with clear reproduction steps, evidence, and remediation recommendations. * Raise defects in tracking tools and collaborate with development teams for timely resolution. * Provide regular status updates to stakeholders and elevate risks or challenges proactively. * Prepare comprehensive test reports including executive summaries, technical details, and risk ratings (CVSS). * Support re-testing after fixes and validate remediation effectiveness. * Ensure compliance with industry standards (OWASP ASVS, API Top 10, ISO 27001, PCI-DSS). * Recommend security best practices and contribute to continuous improvement of testing methodologies. * Maintain strong documentation and communication throughout the engagement lifecycle. Required Skills & Certifications * CREST certification (CRT/CPT/CPSA or equivalent) is a must. * Penetration Testing Expertise - Strong hands-on experience in API and UI/Web application penetration testing. * Security Standards Knowledge - OWASP Top 10, OWASP API Top 10, ASVS, CVSS scoring, and CREST methodologies. * API Security - REST/GraphQL/SOAP testing, OAuth2/OIDC, JWT handling, rate limiting, and authorization flaws (BOLA/BFLA). * Web Application Security - XSS, CSRF, SQL Injection, Clickjacking, session management, CSP/CORS issues. * Documentation & Reporting - Ability to create detailed test plans, risk logs, and clear vulnerability reports. * Compliance Awareness - Familiarity with ISO 27001, PCI-DSS, NIST guidelines. Seniority Level * Associate Employment Type * Full-time Job Function * Information Technology Industries * IT Services and IT Consulting ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)