Penetration Tester

Cyber and Fraud Centre - Scotland
Edinburgh, UK
11 days ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
£35,000.0 - £45,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software System Penetration Testing Application Testing Microsoft Azure Burp Suite Cloud Computing Cloud Computing Security Fraud Prevention and Detection Information Systems Security Architecture Professional Nmap Open Web Application Security Google Cloud
+4 more
Mitre Att&ck Cyber Threat Analysis Metasploit Nessus

Job description

You will deliver high-quality, ethical penetration testing engagements aligned with CREST standards. A hands-on technical role with opportunities to grow and develop your skills as part of a social enterprise contributing to Scotland’s wider cyber resilience ecosystem., * Deliver CREST-aligned penetration testing engagements, including:

  • Infrastructure and network testing
  • Web and application testing
  • Cloud and hybrid environments
  • Execute tests in line with agreed methodologies and best practice
  • Produce clear, high-quality technical and executive-level reports
  • Communicate findings and risk in a clear, constructive manner to a range of stakeholders
  • Support remediation discussions and re-testing where required
  • Maintain accurate records and testing artefacts in line with governance and assurance requirements
  • Contribute to continuous improvement of tools, methodologies, and internal knowledge sharing.
  • Stay informed about emerging cyber threats, fraud trends, and regulatory changes affecting organisations.
  • Achieve and maintain CREST accreditation.

Requirements

A hands-on technical role with opportunities to grow and develop your skills as part of a social enterprise contributing to Scotland’s wider cyber resilience ecosystem., You will be joining a caring and committed team with a strong sense of purpose., * 1-2 years of proven experience delivering penetration testing in professional or client-facing environments.

  • Understanding of common vulnerabilities and attack techniques (e.g. OWASP Top 10, MITRE ATT&CK).
  • Experience with industry-standard tools (e.g. Burp Suite, Nmap, Metasploit, Nessus or equivalents).
  • Ability to write clear, high-quality technical reports.
  • Strong ethical mindset and commitment to responsible disclosure.

Desirable

  • CREST penetration testing certifications, such as CPSA or CRT.
  • Experience in cloud security testing (AWS, Azure, GCP).
  • Knowledge of secure architecture or defensive controls.
  • Additional certifications (e.g. OSCP, CHECK, CISSP, cloud security certs).

Benefits & conditions

Pulled from the full job description

  • Gym membership
  • Company pension, What We Offer
  • Meaningful work with real-world impact across Scotland’s cyber ecosystem
  • Flexible and hybrid working arrangements
  • Support for continued professional development and certification
  • A collaborative, mission-driven culture
  • Competitive salary and benefits package (commensurate with experience)

About the company

The Cyber and Fraud Centre Scotland supports organisations across Scotland to strengthen their resilience against cybercrime and fraud. We are Scotland’s only cyber social enterprise working at the intersection of cyber security, threat intelligence, and harm prevention, we partner with businesses, public sector bodies, and law enforcement to reduce risk and improve security maturity nationwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

Videos

See all

Related articles

See all