Penetration Tester
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
You will deliver high-quality, ethical penetration testing engagements aligned with CREST standards. A hands-on technical role with opportunities to grow and develop your skills as part of a social enterprise contributing to Scotland’s wider cyber resilience ecosystem., * Deliver CREST-aligned penetration testing engagements, including:
- Infrastructure and network testing
- Web and application testing
- Cloud and hybrid environments
- Execute tests in line with agreed methodologies and best practice
- Produce clear, high-quality technical and executive-level reports
- Communicate findings and risk in a clear, constructive manner to a range of stakeholders
- Support remediation discussions and re-testing where required
- Maintain accurate records and testing artefacts in line with governance and assurance requirements
- Contribute to continuous improvement of tools, methodologies, and internal knowledge sharing.
- Stay informed about emerging cyber threats, fraud trends, and regulatory changes affecting organisations.
- Achieve and maintain CREST accreditation.
Requirements
A hands-on technical role with opportunities to grow and develop your skills as part of a social enterprise contributing to Scotland’s wider cyber resilience ecosystem., You will be joining a caring and committed team with a strong sense of purpose., * 1-2 years of proven experience delivering penetration testing in professional or client-facing environments.
- Understanding of common vulnerabilities and attack techniques (e.g. OWASP Top 10, MITRE ATT&CK).
- Experience with industry-standard tools (e.g. Burp Suite, Nmap, Metasploit, Nessus or equivalents).
- Ability to write clear, high-quality technical reports.
- Strong ethical mindset and commitment to responsible disclosure.
Desirable
- CREST penetration testing certifications, such as CPSA or CRT.
- Experience in cloud security testing (AWS, Azure, GCP).
- Knowledge of secure architecture or defensive controls.
- Additional certifications (e.g. OSCP, CHECK, CISSP, cloud security certs).
Benefits & conditions
Pulled from the full job description
- Gym membership
- Company pension, What We Offer
- Meaningful work with real-world impact across Scotland’s cyber ecosystem
- Flexible and hybrid working arrangements
- Support for continued professional development and certification
- A collaborative, mission-driven culture
- Competitive salary and benefits package (commensurate with experience)
About the company
The Cyber and Fraud Centre Scotland supports organisations across Scotland to strengthen their resilience against cybercrime and fraud. We are Scotland’s only cyber social enterprise working at the intersection of cyber security, threat intelligence, and harm prevention, we partner with businesses, public sector bodies, and law enforcement to reduce risk and improve security maturity nationwide.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
The 8 Best Code Testing Tools
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Understanding and Mitigating Common Web Vulnerabilities