Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
Aug 20, 2026
Full time
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
Graduate Cyber Security Consultant & Penetration Tester Location: Bristol, UK (Office-based) Type: Full-Time About Us We are working with a leading UK technology firm providing specialist consultancy across high-impact and critical sectors. They are looking to onboard an ambitious graduate to join their expert team, offering full training and direct mentorship from industry leaders. The Role This entry-level position is designed for recent graduates looking to launch a career in cybersecurity. You will work on site at the Bristol office, assisting clients in identifying, mitigating, and managing security risks while receiving structured development to accelerate your growth. Key Responsibilities Conduct security assessments, vulnerability scans, and supervised penetration testing. Analyze technical risks and produce detailed reports with actionable recommendations. Communicate findings and security advice clearly to clients. Assist with incident response procedures and stay up to date with compliance standards. Continuously expand your knowledge of emerging cybersecurity tools and techniques. What We're Looking For Education: A Bachelor s degree, preferably in a STEM discipline. Skills: Strong analytical, problem-solving, and communication skills. Mindset: A strong passion for information security and a high willingness to learn. Bonus: Relevant certifications or internships are a plus, but not required. What s on Offer Competitive salary and performance incentives Mentorship, career guidance, and funding for professional certifications Hands-on experience with advanced tools on challenging projects A collaborative and supportive team environment
Jul 31, 2026
Full time
Graduate Cyber Security Consultant & Penetration Tester Location: Bristol, UK (Office-based) Type: Full-Time About Us We are working with a leading UK technology firm providing specialist consultancy across high-impact and critical sectors. They are looking to onboard an ambitious graduate to join their expert team, offering full training and direct mentorship from industry leaders. The Role This entry-level position is designed for recent graduates looking to launch a career in cybersecurity. You will work on site at the Bristol office, assisting clients in identifying, mitigating, and managing security risks while receiving structured development to accelerate your growth. Key Responsibilities Conduct security assessments, vulnerability scans, and supervised penetration testing. Analyze technical risks and produce detailed reports with actionable recommendations. Communicate findings and security advice clearly to clients. Assist with incident response procedures and stay up to date with compliance standards. Continuously expand your knowledge of emerging cybersecurity tools and techniques. What We're Looking For Education: A Bachelor s degree, preferably in a STEM discipline. Skills: Strong analytical, problem-solving, and communication skills. Mindset: A strong passion for information security and a high willingness to learn. Bonus: Relevant certifications or internships are a plus, but not required. What s on Offer Competitive salary and performance incentives Mentorship, career guidance, and funding for professional certifications Hands-on experience with advanced tools on challenging projects A collaborative and supportive team environment
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client's perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies. About the Team Vector Command is an always on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large scale reconnaissance, identifying exposed or high value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities-it tests the customer's entire security posture and defense in depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments. About the Role Your primary responsibility is to deliver Rapid7's Vector Command Continuous Red Teaming service. In this role, you will investigate emerging threats, uncover novel vulnerabilities across large external attack surfaces, and attempt to breach customer perimeter defenses to gain initial access. When new N day or zero day vulnerabilities emerge, this role rapidly analyzes them, recreates proof of concepts, and assesses customer environments for exposure. Between these high priority efforts, the researcher actively hunts for novel vulnerabilities and unique attack paths across customer attack surfaces to support initial access operations. Specifically, your focus will be to: Evaluate large external attack surfaces to identify vulnerabilities that enable initial access. Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction. Analyze, develop, and exploit N day and newly released zero day vulnerabilities relevant to customer environments. Identify novel attacks through black box evaluation of customer web applications, leading to initial access or exposure of sensitive data. Develop and maintain positive relationships with clients and understand their business and needs. Participate in industry conferences and professional organizations. Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices. Translate technical concepts and convey them to non security personnel. Mentor and coach junior staff to promote growth, project contributions, and knowledge sharing. Meet professional practice standards and demonstrate exceptional skill in core service areas. The Skills and Qualities You'll Bring 5+ years in an active technical security role & 4+ years Penetration Testing Consulting experience Expert knowledge of the following: Modern penetration testing tools and methods Network and web based application security concepts Windows/Linux/UNIX internals Exploit research and development Experience using multiple interpreted languages (Ruby, Python, PHP, etc.) and compiled languages (Java, C, C++, Assembly, etc.) Technical competencies, including previous technical consulting experience High quality report writing and peer reviewing Strong knowledge of common regulatory structures and obligations and common IT governance. The ability to effectively lead teams of penetration testers while on engagements Be comfortable explaining findings and recommendations to technical and non technical audiences including C Level and Board briefings Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet facing attack surfaces. Certifications such as OSCP, OSCE, GXPN, OSEE, CREST Experience with Red & Purple Teams Excellent communication skills both with internal and external stakeholders Collaborative mindset, contributing to knowledge sharing and cross training Demonstrate a commitment to the end to end testing process, from the initial pre engagement planning to providing accountable support during the final remediation phase. Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we've been doing for the past 20 years. If you're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
May 30, 2026
Full time
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client's perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies. About the Team Vector Command is an always on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large scale reconnaissance, identifying exposed or high value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities-it tests the customer's entire security posture and defense in depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments. About the Role Your primary responsibility is to deliver Rapid7's Vector Command Continuous Red Teaming service. In this role, you will investigate emerging threats, uncover novel vulnerabilities across large external attack surfaces, and attempt to breach customer perimeter defenses to gain initial access. When new N day or zero day vulnerabilities emerge, this role rapidly analyzes them, recreates proof of concepts, and assesses customer environments for exposure. Between these high priority efforts, the researcher actively hunts for novel vulnerabilities and unique attack paths across customer attack surfaces to support initial access operations. Specifically, your focus will be to: Evaluate large external attack surfaces to identify vulnerabilities that enable initial access. Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction. Analyze, develop, and exploit N day and newly released zero day vulnerabilities relevant to customer environments. Identify novel attacks through black box evaluation of customer web applications, leading to initial access or exposure of sensitive data. Develop and maintain positive relationships with clients and understand their business and needs. Participate in industry conferences and professional organizations. Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices. Translate technical concepts and convey them to non security personnel. Mentor and coach junior staff to promote growth, project contributions, and knowledge sharing. Meet professional practice standards and demonstrate exceptional skill in core service areas. The Skills and Qualities You'll Bring 5+ years in an active technical security role & 4+ years Penetration Testing Consulting experience Expert knowledge of the following: Modern penetration testing tools and methods Network and web based application security concepts Windows/Linux/UNIX internals Exploit research and development Experience using multiple interpreted languages (Ruby, Python, PHP, etc.) and compiled languages (Java, C, C++, Assembly, etc.) Technical competencies, including previous technical consulting experience High quality report writing and peer reviewing Strong knowledge of common regulatory structures and obligations and common IT governance. The ability to effectively lead teams of penetration testers while on engagements Be comfortable explaining findings and recommendations to technical and non technical audiences including C Level and Board briefings Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet facing attack surfaces. Certifications such as OSCP, OSCE, GXPN, OSEE, CREST Experience with Red & Purple Teams Excellent communication skills both with internal and external stakeholders Collaborative mindset, contributing to knowledge sharing and cross training Demonstrate a commitment to the end to end testing process, from the initial pre engagement planning to providing accountable support during the final remediation phase. Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we've been doing for the past 20 years. If you're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Senior Penetration Tester £90,000-£95,000 Horsham (3 days a week onsite) VIQU are supporting a leading organisation in seeking an experienced Senior Penetration Tester to join its growing Cyber Security function. As a Senior Penetration Tester, you will lead and deliver complex security assessments across networks, applications, cloud environments, and emerging technologies. Key Responsibilities Lead the scoping, planning, and execution of advanced penetration tests across web, network, cloud, and enterprise systems Conduct offensive security assessments to identify, validate, and exploit vulnerabilities while providing actionable remediation guidance Design and support purple team exercises to enhance detection and response capabilities Simulate advanced attack scenarios using frameworks such as MITRE ATT&CK Produce high-quality technical reports for both technical and non-technical stakeholders Mentor junior team members and promote security testing best practices Requirements 5+ years of hands-on penetration testing experience across network, web, cloud, internal, red team, or purple team environments Excellent knowledge of: MITRE ATT&CK OWASP Threat modelling Attack surface analysis Experience with automated, dynamic, and static security testing tools Knowledge of regulatory frameworks including GDPR, PCI-DSS, and related compliance standards Apply now to speak with VIQU IT in confidence. Or reach out to Noah Yeoman via the VIQU Website Do you know someone great? We'll thank you with up to £1,000 if your referral is successful (terms apply). For more exciting roles and opportunities like this, please follow us on IT Recruitment
May 20, 2026
Full time
Senior Penetration Tester £90,000-£95,000 Horsham (3 days a week onsite) VIQU are supporting a leading organisation in seeking an experienced Senior Penetration Tester to join its growing Cyber Security function. As a Senior Penetration Tester, you will lead and deliver complex security assessments across networks, applications, cloud environments, and emerging technologies. Key Responsibilities Lead the scoping, planning, and execution of advanced penetration tests across web, network, cloud, and enterprise systems Conduct offensive security assessments to identify, validate, and exploit vulnerabilities while providing actionable remediation guidance Design and support purple team exercises to enhance detection and response capabilities Simulate advanced attack scenarios using frameworks such as MITRE ATT&CK Produce high-quality technical reports for both technical and non-technical stakeholders Mentor junior team members and promote security testing best practices Requirements 5+ years of hands-on penetration testing experience across network, web, cloud, internal, red team, or purple team environments Excellent knowledge of: MITRE ATT&CK OWASP Threat modelling Attack surface analysis Experience with automated, dynamic, and static security testing tools Knowledge of regulatory frameworks including GDPR, PCI-DSS, and related compliance standards Apply now to speak with VIQU IT in confidence. Or reach out to Noah Yeoman via the VIQU Website Do you know someone great? We'll thank you with up to £1,000 if your referral is successful (terms apply). For more exciting roles and opportunities like this, please follow us on IT Recruitment