Penetration Tester

Citation Ltd
Basingstoke, UK
5 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Cloud Computing Security Linux Python (Programming Language) Wireless Security Windows PowerShell
+3 more
Web Applications Scripting SC Clearance

Job description

You’ll work as part of our penetration testing team delivering a wide range of technical security assessments across client environments, helping organisations identify vulnerabilities and strengthen their cyber resilience.

Your work will include:

  • Infrastructure or Web application penetration testing
  • Cloud security assessments
  • Producing clear, high-quality technical reports
  • Presenting findings and remediation advice to clients
  • Supporting vulnerability validation and re-testing
  • Contributing to internal tooling, research and knowledge sharing

Requirements

Whether you’re already a CHECK Team Member (CTM) or you’re an experienced penetration tester ready to take that next step, we’d love to hear from you., Essential

  • Commercial penetration testing experience within a consultancy or equivalent environment
  • Strong technical reporting skills
  • Experience conducting infrastructure and web application penetration tests
  • Good understanding of Windows, Linux and Active Directory environments
  • Familiarity with Azure and/or AWS security testing
  • Experience using industry-standard penetration testing tools and methodologies
  • Excellent written and verbal communication skills
  • A passion for continuous learning and technical development

Desirable

  • Current CHECK Team Member (CTM) status
  • Current SC Security Clearance (or eligibility to obtain it)
  • CREST CRT / Cyber Scheme CSTM or equivalent certification
  • OSCP or equivalent practical penetration testing certification
  • Experience with API, mobile or wireless security testing
  • Scripting or automation experience using Python, PowerShell or Bash, You’re passionate about offensive security and enjoy solving complex technical challenges. You produce high-quality work, communicate clearly with clients and are always looking to improve your skills.

Whether you’re already delivering CHECK assessments or you’re looking to achieve CHECK status in the near future, you’ll be joining a team that will support your professional development and provide exposure to challenging and rewarding engagements.

Benefits & conditions

When you join us you’ll benefit from:

  • Working for an NCSC CHECK provider and CREST member
  • A varied mix of commercial, defence and public sector projects
  • Funded training and industry certifications
  • Clear progression towards CHECK Team Member, CHECK Team Leader and senior technical roles
  • Hybrid and flexible working
  • A collaborative technical culture where knowledge sharing is encouraged
  • Opportunities to contribute to research, tooling and new service development
  • Competitive salary and benefits

About the company

Citation Cyber is one of the UK’s leading cyber security consultancies, delivering penetration testing, Cyber Essentials certification, consultancy, training and managed cyber security services to organisations across both the public and private sectors.

As an NCSC CHECK provider and CREST member company, we’re continuing to grow our penetration testing team and are looking for a talented Security Consultant to join us.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ World Congress 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders ¡ LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker ¡ World Congress 2022

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani ¡ Europe 2026 Virtual

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 ¡ LIVE

Videos

See all

Related articles

See all