> Markdown version of [/jobs/ext/3315957-penetration-tester-cloud-security-active-directory-apis](https://www.wearedevelopers.com/jobs/ext/3315957-penetration-tester-cloud-security-active-directory-apis). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - Cloud Security, Active Directory, APIs - **Company:** Hays plc - **Location:** London, UK - **Contract:** Temporary contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Security Information and Event Management, Software Vulnerability Management, Web Applications, Cloud Platform System, Splunk - **Published:** September 15, 2026 - **Apply:** https://www.hays.co.uk/job-detail/penetration-tester-%E2%80%93-cloud-security-active-directory-apis-london_4828163 ## About the Role A client of mine is looking for a hands-on Penetration Tester to support their cybersecurity function, with some responsibilities across security operations and incident response. The right candidate will have experience conducting infrastructure, Web Application, API, Cloud and Active Directory penetration tests within complex environments. Key Requirements: * Proven commercial experience as a Penetration Tester, within a large enterprise environment. * Strong hands-on Penetration Testing experience across Web Applications, APIs, infrastructure, Active Directory and cloud environments. * Proven experience conducting End-to-End Penetration Testing including scoping, execution, reporting and retesting. * Comfortable identifying, exploiting and validating vulnerabilities and providing remediation recommendations. * Knowledge of technologies such as Pentera, AppCheck, Microsoft Defender, Splunk, CrowdStrike or similar. * Exposure to vulnerability management and working with technical teams to remediate findings. * Comfortable supporting incident response activities, including triage, investigation and containment. * Experience using SIEM and security monitoring tools for alert analysis and threat detection. * Strong communication skills with the ability to explain technical findings to technical and non-technical stakeholders. Nice to have: * Immediately Available * Experience with vulnerability management programmes and MSSP engagement. * Relevant certifications such as OSCP, CREST CRT/CCT, CTM, CISSP or GIAC. * Previous experience within Higher Education, Public Sector or a large complex enterprise environment. ## Description Penetration Tester - Cloud Security, Active Directory, APIs Market Rate (Inside IR35) 6 Months initially Hybrid in London A client of mine is looking for a hands-on Penetration Tester to support their cybersecurity function, with some responsibilities across security operations and incident response. The right candidate will have experience conducting infrastructure, Web Application, API, Cloud and Active Directory penetration tests within complex environments. Key Requirements: * Proven commercial experience as a Penetration Tester, within a large enterprise environment. * Strong hands-on Penetration Testing experience across Web Applications, APIs, infrastructure, Active Directory and cloud environments. * Proven experience conducting End-to-End Penetration Testing including scoping, execution, reporting and retesting. * Comfortable identifying, exploiting and validating vulnerabilities and providing remediation recommendations. * Knowledge of technologies such as Pentera, AppCheck, Microsoft Defender, Splunk, CrowdStrike or similar. * Exposure to vulnerability management and working with technical teams to remediate findings. * Comfortable supporting incident response activities, including triage, investigation and containment. * Experience using SIEM and security monitoring tools for alert analysis and threat detection. * Strong communication skills with the ability to explain technical findings to technical and non-technical stakeholders. Nice to have: * Immediately Available * Experience with vulnerability management programmes and MSSP engagement. * Relevant certifications such as OSCP, CREST CRT/CCT, CTM, CISSP or GIAC. * Previous experience within Higher Education, Public Sector or a large complex enterprise environment. #4828163 - Raluca