Security & Penetration Testing
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Reach is here to help when things don’t go as expected. Please explain why you are reporting an issue with this volunteer, organisation or opportunity, and our team will contact you within five working days. Message
About Ignite Hubs
We are an award-winning education charity for children and young people based in London. We target girls and those from disadvantaged and underrepresented backgrounds to increase social mobility… Children / families Education +4 more Read more about Ignite Hubs
What will you be doing?
Ignite Hubs is currently developing an online platform that connects children and young people with tutors for one-to-one tutoring sessions. Because the platform puts adults and young people in direct contact and holds personal data about children, testing its security is as much safeguarding work as it is a technical exercise.
Working alongside our CTO and developers, you would take on small, scoped pieces of testing across a modern single-page web application, its APIs and its cloud configuration, and write up what you find so the team can act on it. Typical pieces of work include:
- Testing a feature or user journey, such as registration, tutor matching, booking or a live session, against the OWASP Top 10, or the APIs against the OWASP API Security Top 10
- Testing access control and account separation, so that a tutor can only reach the learners assigned to them and nobody uninvited can join or observe a one-to-one session
- Testing authentication, session handling and privilege boundaries between the different user roles the platform supports
- Reviewing cloud and platform configuration, such as database-level access controls, storage of material shared during sessions, and secrets handling
- Writing up findings clearly, with evidence and practical fixes, then re-testing once they are resolved
Pieces of work are scoped to align with a volunteer’s availability. You will not be on call, you will not carry sole responsibility for the platform’s security, and nobody is expected to cover all of the above.
Requirements
- A practical understanding of common web application vulnerabilities and how they are exploited
- Hands-on testing experience, whether professional or through labs, CTFs, coordinated bug bounty work or your own projects
- Familiarity with an interception proxy such as Burp Suite Community Edition or OWASP ZAP
- The ability to write up a finding clearly enough for a developer to reproduce it and fix it
- Sound ethical judgement, and a willingness to work only within the agreed scope
- Willingness to sign a confidentiality agreement and rules of engagement, and to complete a DBS check if required
Desirable (a bonus rather than a checklist, and nobody has all of them):
- A relevant certification, or study towards one
- Experience testing modern JavaScript single-page applications and their APIs
- Experience reviewing cloud, database or build pipeline configuration
- Experience testing role-based or multi-tenant access control, or real-time session, messaging and file-sharing features
- Awareness of UK GDPR and the ICO Age Appropriate Design Code
We are looking for someone who can give regular time, though we know availability varies from week to week. Testing works well in short, focused bursts, so we are happy to agree test windows around your availability.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…