> Markdown version of [/jobs/ext/3564755-junior-penetration-tester-fully-remote](https://www.wearedevelopers.com/jobs/ext/3564755-junior-penetration-tester-fully-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Penetration Tester - Fully Remote - **Company:** Harvey Nash - **Location:** Cardiff, UK (Remote available) - **Experience:** Starter - **Salary:** £45,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing, Linux, Networking Basics, Nmap, Web Applications, Cloud Platform System, Metasploit, Vulnerability Analysis - **Published:** October 3, 2026 - **Apply:** https://www.totaljobs.com/job/junior-penetration-tester/harvey-nash-job108072811 ## About the Role * At least one year's experience in a security-focused IT role, or two years in a broader IT role with a genuine passion for cybersecurity * A solid grasp of networking fundamentals, operating systems (Windows and Linux) and common security concepts * Strong written communication skills and an eye for detail * A curious, self-driven mindset and a real desire to learn Bonus points for * Exposure to offensive security, ethical hacking or vulnerability testing * Experience with tools such as Burp Suite, Nmap or Metasploit * Home lab, CTF or bug bounty experience * Working towards or already holding a certification like CREST Registered Tester or OSCP * Familiarity with cloud platforms such as AWS or Azure ## Description * Supporting and delivering penetration tests across infrastructure, web applications and cloud environments * Identifying, validating and documenting vulnerabilities * Writing clear, professional reports that explain technical findings and recommended fixes to both technical and non-technical audiences * Learning from senior consultants through mentoring, shadowing and knowledge sharing * Keeping up to date with the latest tools, techniques and threats in offensive security ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers)