Penetration Tester

Sencode Ltd
UK
about 1 month ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£36,000.0 - £45,000.0
Working hours
Regular working hours
Job source

Tech stack

Private Networks Active Directory Application Programming Interfaces (APIs) Amazon Web Services Software System Penetration Testing User Authentication Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Continuous Integration Linux
+10 more
Fat Client Mobile Application Software Python (Programming Language) Network Protocols Open Web Application Security Session Management Web Applications Google Cloud Cloud Platform System Devsecops

Job description

We are seeking a skilled Penetration Tester to join our delivery team. This is a hands-on, client-facing role focused on conducting high-quality technical assessments and producing clear, practical reports.

You will work across a range of engagements including web applications, APIs, cloud platforms, internal and external infrastructure, and authenticated environments. The role requires strong technical ability, structured methodology, and the confidence to work directly with clients.

Key Responsibilities

  • Deliver penetration testing engagements across:

  • Web applications and APIs

  • Cloud environments (AWS, Azure, GCP)

  • Internal and external infrastructure

  • Mobile applications where required

  • Perform manual testing supported by appropriate tooling, focusing on real-world exploitability.

  • Produce clear, structured, and client-ready technical reports within agreed delivery timelines.

  • Participate in client debrief calls to explain findings and remediation steps.

  • Support retest activities and validation of remediation.

  • Follow CREST-aligned methodologies and internal quality assurance processes.

  • Contribute to internal research, tooling, and methodology improvements.

  • Maintain accurate engagement notes and evidence within the Sencode Portal.

Requirements

  • Proven hands-on penetration testing experience across web and infrastructure environments.

  • Strong understanding of:

  • Web application vulnerabilities (OWASP Top 10 and beyond)

  • Authentication, authorisation, and session management flaws

  • Network protocols and common infrastructure weaknesses

  • Experience using industry-standard tools

  • Comfortable working in Linux-based testing environments.

  • Ability to script or automate tasks using Python, Bash, or similar.

  • Strong report writing and communication skills.

Desirable:

  • Experience with cloud security testing.

  • Mobile or thick-client testing experience.

  • Active Directory and internal network exploitation.

  • Exposure to CI/CD or DevSecOps environments.

Certifications

One of the following is required:

  • OSCP (OffSec Certified Professional) OR CREST CRT (Registered Penetration Tester)

Personal Attributes

  • Professional, reliable, and delivery-focused.

  • Comfortable working in a client-facing consultancy environment.

  • Able to manage time across multiple engagements.

  • Detail-oriented with strong written communication skills.

  • Motivated to pursue ongoing professional development.

Benefits & conditions

Pulled from the full job description

  • Company pension
  • Work from home
  • On-site parking

About the company

Sencode is a UK-based, CREST-accredited penetration testing and cybersecurity consultancy working with public and private sector organisations across the UK and Europe. We specialise in high-quality assurance services including web, mobile, API, cloud, and infrastructure penetration testing.

Our engagements focus on realistic, risk-driven testing and clear, actionable reporting rather than checklist compliance. We work with organisations ranging from scaling SaaS companies to critical-sector enterprises.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Loading talks and stories from around this role…