> Markdown version of [/jobs/ext/2311292-offensive-security-tester-or-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2311292-offensive-security-tester-or-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Tester or Penetration Tester - **Company:** Hackajob Ltd - **Location:** Greater London, UK (Remote available) - **Contract:** Permanent contract - **Skills:** Private Networks, Application Programming Interfaces (APIs), Software System Penetration Testing, Cyber Security, Mobile Application Software, Network Architecture, Wireless Security, Open Web Application Security, Red Team (Cyber Security), Web Applications, Web Services, Information Technology, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815463784-offensive-security-tester-or-penetration-tester ## About the Role * Would be nice have CREST Registered Penetration Tester (CRT) * Additional certifications preferred (e.g., OSCP, GPEN, CEH). Professional Skills * Strong technical writing and verbal communication skills. * Ability to explain complex technical issues to non-technical audiences. * Excellent time management and attention to detail, * Bachelor's degree in computer science, Cybersecurity, or related field. * Direct experience working in government, military, or intelligence organizations advantageous. * 3-5 years of experience in penetration testing or offensive security roles., * Experience conducting red team exercises and adversarial attack simulations. * Familiarity with threat modeling and risk assessment methodologies. * Background in information security or IT security operations. Success Metrics (6-12 Months) * Complete a minimum of 10 penetration testing engagements per quarter. * Achieve client satisfaction ratings of 90% or higher for testing services. * Deliver high-quality technical reports with zero critical errors. * Stay within defined scope and timelines for all engagements. ## Description * Conduct comprehensive penetration tests across web applications, network infrastructure, and mobile applications. * Perform external and internal network penetration testing using industry-standard methodologies. * Execute wireless security assessments, social engineering engagements, and red team exercises. * Conduct application security testing, including API and web service assessments. Vulnerability Assessment and Analysis * Identify, validate, and prioritize security vulnerabilities discovered during testing. * Analyze attack paths and assess the business impact of identified vulnerabilities. * Develop proof-of-concept exploits to demonstrate security risks. Technical Reporting and Communication * Produce detailed technical reports documenting findings, risks, and remediation recommendations. * Create executive summaries highlighting business impact and strategic risk concerns. * Present findings to technical teams and management stakeholders. Testing Methodology and Tool Management * Follow industry-standard penetration testing methodologies (e.g., OWASP, PTES, NIST). * Maintain and update penetration testing tools and exploitation frameworks. * Stay current with the latest attack techniques, vulnerabilities, and security research. Client Engagement and Support * Communicate effectively with clients throughout testing engagements. * Coordinate testing activities to minimize business disruption. * Support scoping discussions and provide security awareness briefings to client teams. ## Related Videos - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Rust Beyond Systems: Revolutionizing Web Development](https://www.wearedevelopers.com/videos/1111-rust-beyond-systems-revolutionizing-web-development) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)