Penetration Tester page is loaded Specialist Penetration Testerlocations: London Office: Cambridge Officetime type: Full timeposted on: Posted Todayjob requisition id: JR101596Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting nearly 10,000 organizations from unknown threats using its proprietary AI.The Darktrace Active AI Security Platform(TM) delivers a proactive approach to cyber resilience to secure the business across the entire digital estate - from network to cloud to email. Breakthrough innovations from our R&D teams have resulted in over 200 patent applications filed. Darktrace's platform and services are supported by over 2,400 employees around the world. To learn more, visit . Job D escription : As a Penetration Tester within the internal cybersecurity team, you'll play a key role in identifying and mitigating security risks across the organisation's digital landscape. This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities.You'll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams. Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats.Key responsibilities include: Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments. Simulating real-world attack scenarios to assess system and infrastructure resilience. Producing detailed technical reports and executive summaries for stakeholders. Collaborating with internal teams to validate findings and support remediation efforts. Staying up to date with emerging threats, vulnerabilities, and offensive security techniques.Please note this is a hybrid role, with a compulsory attendance of 2 days a week in either the Cambridge or London office.To succeed in this role, you'll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks. A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively. Other qualifications and skills include: Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell, Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security, Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills. Desirable Attributes Ability to mentor junior testers and contribute to internal tooling. Benefits: 23 days' holiday + all public holidays, rising to 25 days after 2 years of service, Additional day off for your birthday, Private medical insurance which covers you, your cohabiting partner and children, Life insurance of 4 times your base salary, Salary sacrifice pension scheme, Enhanced family leave, Confidential Employee Assistance Program, Cycle to work scheme.
Apr 19, 2026
Full time
Penetration Tester page is loaded Specialist Penetration Testerlocations: London Office: Cambridge Officetime type: Full timeposted on: Posted Todayjob requisition id: JR101596Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting nearly 10,000 organizations from unknown threats using its proprietary AI.The Darktrace Active AI Security Platform(TM) delivers a proactive approach to cyber resilience to secure the business across the entire digital estate - from network to cloud to email. Breakthrough innovations from our R&D teams have resulted in over 200 patent applications filed. Darktrace's platform and services are supported by over 2,400 employees around the world. To learn more, visit . Job D escription : As a Penetration Tester within the internal cybersecurity team, you'll play a key role in identifying and mitigating security risks across the organisation's digital landscape. This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities.You'll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams. Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats.Key responsibilities include: Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments. Simulating real-world attack scenarios to assess system and infrastructure resilience. Producing detailed technical reports and executive summaries for stakeholders. Collaborating with internal teams to validate findings and support remediation efforts. Staying up to date with emerging threats, vulnerabilities, and offensive security techniques.Please note this is a hybrid role, with a compulsory attendance of 2 days a week in either the Cambridge or London office.To succeed in this role, you'll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks. A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively. Other qualifications and skills include: Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell, Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security, Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills. Desirable Attributes Ability to mentor junior testers and contribute to internal tooling. Benefits: 23 days' holiday + all public holidays, rising to 25 days after 2 years of service, Additional day off for your birthday, Private medical insurance which covers you, your cohabiting partner and children, Life insurance of 4 times your base salary, Salary sacrifice pension scheme, Enhanced family leave, Confidential Employee Assistance Program, Cycle to work scheme.
A cybersecurity company in Cambridge is seeking a Specialist Penetration Tester to join their internal team. The role involves identifying and mitigating security risks through penetration testing and simulating real-world attacks. The ideal candidate will have a strong background in offensive security, familiarity with industry-standard tools, and relevant certifications. This hybrid position requires attendance 2 days a week at the office. Benefits include holiday allowances, private medical insurance, and a salary sacrifice pension scheme.
Apr 18, 2026
Full time
A cybersecurity company in Cambridge is seeking a Specialist Penetration Tester to join their internal team. The role involves identifying and mitigating security risks through penetration testing and simulating real-world attacks. The ideal candidate will have a strong background in offensive security, familiarity with industry-standard tools, and relevant certifications. This hybrid position requires attendance 2 days a week at the office. Benefits include holiday allowances, private medical insurance, and a salary sacrifice pension scheme.
Sunderland Hybrid Permanent What this role looks like At tombola, everything we build is in house, which means security is not something we bolt on at the end, it is built in from the start. As a Product Security Engineer, you will sit right at the heart of that. You will work closely with our development teams, getting real visibility of what is being built and shaping how we keep it secure as we go. This is not a role where you are hidden away running tests in isolation. You will be collaborating, influencing, translating risk into real action, and helping teams make better security decisions every day. You will play a key part in protecting our platform, our players, and our business as we continue to grow. We're big on working together, so you'll spend around 3 days a week in our Sunderland office getting that face to face time with the team, with around 2 days working from home for a bit of focus and flexibility. What you will be doing You will be involved across three key areas of product security: External testing Working with third party partners to meet regulatory requirements and making sure we are always one step ahead. Supporting annual and quarterly security testing Choosing the right external tools and providers Turning findings into clear, actionable improvements across our platform Internal testing Taking ownership of how we proactively test and improve our security internally. Running automated and manual security testing across our sites Identifying and prioritising vulnerabilities across the platform Continuously improving our tooling to keep pace with evolving threats Secure development lifecycle (SDLC) Embedding security into how we build, not just how we test. Partnering with developers, product and infrastructure teams Helping prioritise and resolve vulnerabilities early in the lifecycle Supporting pre go live testing to reduce risk Building and integrating security tooling into CI CD pipelines Empowering teams to make better security decisions from day one What we are looking for You do not need to tick every box, but this is the kind of experience that will help you thrive: A genuine interest in security and staying up to date with new threats Experience working in or alongside a security function Confidence identifying problems and figuring out the best way to solve them Understanding of security frameworks and standards such as ISO, NIST or PCI Experience working with developers or within a secure development lifecycle Awareness of common vulnerabilities such as OWASP Top Ten Familiarity with cloud platforms and modern development environments Ability to script or automate tasks where needed Experience working with third party vendors or penetration testers What will set you apart Ability to translate technical findings into something clear and actionable Confidence working with both technical and non technical stakeholders A mindset that naturally considers risk and security in everything Someone who builds strong relationships and influences teams in the right way Passion for doing things properly, not just quickly Why tombola? We are not your typical tech company. Everything we build is ours, which means you will have real ownership and real impact. You will be part of a team that genuinely cares about: Doing things the right way Supporting each other Building products we are proud of Plus we have some pretty great benefits too click here to check them out. At tombola we know that our differences make us stronger and that thinking differently is key to long term success. We work hard to create a culture of inclusivity where everyone can celebrate our Free to be mevalue. We are committed to creating opportunities for everyone here at tombola, we welcome applications from all backgrounds and encourage individuals to apply, even if you don't meet every requirement.
Apr 15, 2026
Full time
Sunderland Hybrid Permanent What this role looks like At tombola, everything we build is in house, which means security is not something we bolt on at the end, it is built in from the start. As a Product Security Engineer, you will sit right at the heart of that. You will work closely with our development teams, getting real visibility of what is being built and shaping how we keep it secure as we go. This is not a role where you are hidden away running tests in isolation. You will be collaborating, influencing, translating risk into real action, and helping teams make better security decisions every day. You will play a key part in protecting our platform, our players, and our business as we continue to grow. We're big on working together, so you'll spend around 3 days a week in our Sunderland office getting that face to face time with the team, with around 2 days working from home for a bit of focus and flexibility. What you will be doing You will be involved across three key areas of product security: External testing Working with third party partners to meet regulatory requirements and making sure we are always one step ahead. Supporting annual and quarterly security testing Choosing the right external tools and providers Turning findings into clear, actionable improvements across our platform Internal testing Taking ownership of how we proactively test and improve our security internally. Running automated and manual security testing across our sites Identifying and prioritising vulnerabilities across the platform Continuously improving our tooling to keep pace with evolving threats Secure development lifecycle (SDLC) Embedding security into how we build, not just how we test. Partnering with developers, product and infrastructure teams Helping prioritise and resolve vulnerabilities early in the lifecycle Supporting pre go live testing to reduce risk Building and integrating security tooling into CI CD pipelines Empowering teams to make better security decisions from day one What we are looking for You do not need to tick every box, but this is the kind of experience that will help you thrive: A genuine interest in security and staying up to date with new threats Experience working in or alongside a security function Confidence identifying problems and figuring out the best way to solve them Understanding of security frameworks and standards such as ISO, NIST or PCI Experience working with developers or within a secure development lifecycle Awareness of common vulnerabilities such as OWASP Top Ten Familiarity with cloud platforms and modern development environments Ability to script or automate tasks where needed Experience working with third party vendors or penetration testers What will set you apart Ability to translate technical findings into something clear and actionable Confidence working with both technical and non technical stakeholders A mindset that naturally considers risk and security in everything Someone who builds strong relationships and influences teams in the right way Passion for doing things properly, not just quickly Why tombola? We are not your typical tech company. Everything we build is ours, which means you will have real ownership and real impact. You will be part of a team that genuinely cares about: Doing things the right way Supporting each other Building products we are proud of Plus we have some pretty great benefits too click here to check them out. At tombola we know that our differences make us stronger and that thinking differently is key to long term success. We work hard to create a culture of inclusivity where everyone can celebrate our Free to be mevalue. We are committed to creating opportunities for everyone here at tombola, we welcome applications from all backgrounds and encourage individuals to apply, even if you don't meet every requirement.
We are looking for a Senior Cyber and Systems Engineer to join Team OB in our Support Office. As a Senior Cyber and Systems Engineer at OB you will be protecting the company through strong IT security principles and implementing industry stand best practices. Working with and being the first point of contact for EDR partner and SOC you will ensure ongoing compliance with PCI DSS ensuring to adhere to its actively changing requirements. Our Support Office is based in Tolworth, near Chessington, only a 30-minute journey from London Waterloo. We offer hybrid working with a split of 3 days in the office and 2 days home working per week. A bit about us At Oliver Bonas (OB), our values of Work Hard, Play Hard & Be Kind are integral to everything we do. Collaboration, imagination, curiosity, and teamwork are key to our success, and everyone has their part to play in making OB a special place to work. Having fun is key, and a playful and positive approach creates an optimistic environment. We don't take ourselves too seriously, but we are serious about what we do. Our team knows their stuff. They're confident and creative and unafraid to challenge convention to find solutions, taking accountability for their actions, but always with kindness and humility. More about the role An OB Senior Cyber and Systems Engineer will: Work with our newly deployed SOC EDR partner in ensuring the network, cloud, and Retail Estate are secured from Cyber threats. Analyse any security breaches and report on findings and remediation's Monitor/Respond to Anti-Ransomware protection software Incidents. Handle and resolve security-related tickets from the helpdesk, including but not limited to Vipre spam filter and firewall unblock requests on store and Head Office networks. Monitor Netskope (Cloud Access Security Broker) for cloud usage on personal Google/Microsoft Accounts. This is to ensure the company's data is secured in line with the company's GDPR guidelines. Monitor and manage the three ESET antivirus consoles, ensuring they are updated regularly. Work in collaboration with the I.T Support team maintain up-to-date antivirus protection when installing new machines and address any issues promptly. Ensure ongoing compliance with PCI DSS standards. Conduct periodic checks to assess the status of compliance throughout the year. Manage annual compliance audit Conduct quarterly vulnerability scans and remediate any failed attempts Liaise with third party penetration testers and review findings Develop and implement action plans to address any identified compliance gaps. Oversee the management of digital certificates for services and applications. Ensure timely renewal and update of certificates to maintain secure operations. Assist in the delivery of cybersecurity training programs for end users. Promote security awareness and best practices across the organization. Conduct Regular Phishing Simulations Liaise with the Data Compliance manager on any Data Subject Requests Work with the IT support team, providing support on complex or urgent incidents where required. Ensure Network and infrastructure reflects the company's commitment to GDPR at all times and that our customers data is treated with utmost care and attention. Liaise with the GDPR compliance group and identify security risks and take actions where needed. Bonas Benefits: Generous employee discount up to 50% off all OB products Free access to our 24 hour employee assistance programme with Optima Health - offering financial, emotional and vocational support Flexible holiday - 30 days (including bank holidays) - increasing to 35 days with length of service Annual discretionary profit related bonus scheme Free membership for our Westfield Health Cash Plan or Private Medical Auto-enrolment into our pension plan Free access to our onsite gym Cycle to work scheme Refer a Friend incentive Quarterly free lunch Enhanced maternity, paternity, adoption and shared parental leave Equity, Diversity and Inclusivity Voice network and EDI team Mental Health First Aider support Education and support through 360L eLearning platform What we look for: CompTIA Network & Security+ or equivalent Certifications. IT experience across a range of different types of technology Solid understanding of IT infrastructure and current security posture Experience in complying with a PCI DSS audit and understanding its ongoing requirements. Strong problem-solving skills with a proven track record Background in I.T. support as well as Cyber security. Experience with Microsoft Entra Identity Protection/Conditional Access Experience of WAF solutions, such as Cloudflare is desirable. Knowledge of Email security protocols: DKIM/SPF/DMARC Diligent and a strong attention to detail Equity, Diversity & Inclusion at OB At Oliver Bonas, our promise is to do our bit to make living a joyful experience and give cause for optimism. This promise is central to our work in equity, diversity and inclusion (EDI). To bring joy to others, we must first ensure everyone at OB feels valued, included and most importantly, can be themselves at work. It is important to us that our brand reflects wider society and the communities in which we operate. As a result, we welcome all eligible applicants for this role however we are particularly interested in speaking to eligible candidates from the Black, Asian & Mixed Heritage communities. Oliver Bonas is a Disability Confident Committed employer under the Disability Confident employer scheme. To read more about our ED&I commitments, head over to the EDI page on our website:
Apr 15, 2026
Full time
We are looking for a Senior Cyber and Systems Engineer to join Team OB in our Support Office. As a Senior Cyber and Systems Engineer at OB you will be protecting the company through strong IT security principles and implementing industry stand best practices. Working with and being the first point of contact for EDR partner and SOC you will ensure ongoing compliance with PCI DSS ensuring to adhere to its actively changing requirements. Our Support Office is based in Tolworth, near Chessington, only a 30-minute journey from London Waterloo. We offer hybrid working with a split of 3 days in the office and 2 days home working per week. A bit about us At Oliver Bonas (OB), our values of Work Hard, Play Hard & Be Kind are integral to everything we do. Collaboration, imagination, curiosity, and teamwork are key to our success, and everyone has their part to play in making OB a special place to work. Having fun is key, and a playful and positive approach creates an optimistic environment. We don't take ourselves too seriously, but we are serious about what we do. Our team knows their stuff. They're confident and creative and unafraid to challenge convention to find solutions, taking accountability for their actions, but always with kindness and humility. More about the role An OB Senior Cyber and Systems Engineer will: Work with our newly deployed SOC EDR partner in ensuring the network, cloud, and Retail Estate are secured from Cyber threats. Analyse any security breaches and report on findings and remediation's Monitor/Respond to Anti-Ransomware protection software Incidents. Handle and resolve security-related tickets from the helpdesk, including but not limited to Vipre spam filter and firewall unblock requests on store and Head Office networks. Monitor Netskope (Cloud Access Security Broker) for cloud usage on personal Google/Microsoft Accounts. This is to ensure the company's data is secured in line with the company's GDPR guidelines. Monitor and manage the three ESET antivirus consoles, ensuring they are updated regularly. Work in collaboration with the I.T Support team maintain up-to-date antivirus protection when installing new machines and address any issues promptly. Ensure ongoing compliance with PCI DSS standards. Conduct periodic checks to assess the status of compliance throughout the year. Manage annual compliance audit Conduct quarterly vulnerability scans and remediate any failed attempts Liaise with third party penetration testers and review findings Develop and implement action plans to address any identified compliance gaps. Oversee the management of digital certificates for services and applications. Ensure timely renewal and update of certificates to maintain secure operations. Assist in the delivery of cybersecurity training programs for end users. Promote security awareness and best practices across the organization. Conduct Regular Phishing Simulations Liaise with the Data Compliance manager on any Data Subject Requests Work with the IT support team, providing support on complex or urgent incidents where required. Ensure Network and infrastructure reflects the company's commitment to GDPR at all times and that our customers data is treated with utmost care and attention. Liaise with the GDPR compliance group and identify security risks and take actions where needed. Bonas Benefits: Generous employee discount up to 50% off all OB products Free access to our 24 hour employee assistance programme with Optima Health - offering financial, emotional and vocational support Flexible holiday - 30 days (including bank holidays) - increasing to 35 days with length of service Annual discretionary profit related bonus scheme Free membership for our Westfield Health Cash Plan or Private Medical Auto-enrolment into our pension plan Free access to our onsite gym Cycle to work scheme Refer a Friend incentive Quarterly free lunch Enhanced maternity, paternity, adoption and shared parental leave Equity, Diversity and Inclusivity Voice network and EDI team Mental Health First Aider support Education and support through 360L eLearning platform What we look for: CompTIA Network & Security+ or equivalent Certifications. IT experience across a range of different types of technology Solid understanding of IT infrastructure and current security posture Experience in complying with a PCI DSS audit and understanding its ongoing requirements. Strong problem-solving skills with a proven track record Background in I.T. support as well as Cyber security. Experience with Microsoft Entra Identity Protection/Conditional Access Experience of WAF solutions, such as Cloudflare is desirable. Knowledge of Email security protocols: DKIM/SPF/DMARC Diligent and a strong attention to detail Equity, Diversity & Inclusion at OB At Oliver Bonas, our promise is to do our bit to make living a joyful experience and give cause for optimism. This promise is central to our work in equity, diversity and inclusion (EDI). To bring joy to others, we must first ensure everyone at OB feels valued, included and most importantly, can be themselves at work. It is important to us that our brand reflects wider society and the communities in which we operate. As a result, we welcome all eligible applicants for this role however we are particularly interested in speaking to eligible candidates from the Black, Asian & Mixed Heritage communities. Oliver Bonas is a Disability Confident Committed employer under the Disability Confident employer scheme. To read more about our ED&I commitments, head over to the EDI page on our website:
Location This role offers flexibility to work remotely from your own home, or as a hybrid arrangement and work from our offices in Oxford or Glasgow, if preferred. There is also a requirement for flexibility from employees to visit client sites across the UK as part of this role. Why join Dionach by Nomios? Since being acquired by Nomios in late 2024, Dionach by Nomios has continued its dynamic growth as a leading information security company. Specializing in penetration testing and information assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety of our clients. Dionach is also proud to be Great Place To Work Certified , a recognition based entirely on feedback from our team. We're committed to creating an environment where people feel supported, valued and able to grow. Learn more about our certification here: Working at Dionach Great Place to Work UK. We're in an exciting phase of expansion and are looking for self motivated individuals ready to thrive in a fun, flexible environment. At Dionach by Nomios, your contributions will have a genuine impact on the business, and you'll find opportunities for both interesting work and career development. Benefits Our employees are the heart of our business. We value our employees and invest in their growth and well being. Here's what we offer: Hybrid Working: Flexibility to work remotely or use our UK offices around client visits. Professional Growth: Access to training labs, certification sponsorship, and time for skill development. Well being Focus: Private health insurance, eye care plan, income protection, EAP scheme, and well being platform. Our Commitment to Diversity and Inclusion At Dionach by Nomios, we believe that diversity fuels innovation. We're dedicated to creating an inclusive workplace where everyone feels valued and respected. We welcome applications from all backgrounds, perspectives, and experiences, and we're committed to being an equal opportunity employer. We do not discriminate based on race, religion, gender, age, disability, or any other legally protected status. We encourage candidates from underrepresented groups to apply and are committed to providing a supportive and accessible environment for all our employees. If you require accommodations during the application process, let us know, and we'll work to meet your needs. The salary band advertised for this role is £55,000 to £80,000 per annum, depending on experience. What You'll Do Lead and mentor a team of Penetration testers, fostering a collaborative and high performance work environment. Lead and oversee complex infrastructure penetration tests ensuring that they are conducted thoroughly and in accordance with project requirement. Leading onsite customer engagements and serving as the technical authority on CHECK engagements. Review and validate the work of team members to ensure accuracy and thoroughness. Prepare and deliver comprehensive reports detailing findings, risks, and recommended remediation strategies to clients, including assisting with proposal writing and scoping. You will have the opportunity to work on a wide range of services: web and mobile application tests, internal tests, infrastructure tests, but also, social engineering. Ensure all testing activities comply with CHECK standards. What We're Looking For Experience: Significant experience in penetration testing, including network, web application and internal penetration testing as well as experience of leading customer engagements on site. Communication: Strong verbal and written skills for stakeholder management, collaboration and administration duties. Independence: Ability to work independently or as part of a team. Certifications: Holding a relevant certification: CREST Certified Tester - Infrastructure (CCT INF), CREST Certified Tester - Application (CCT APP), Cyber Scheme Team Leader (CSTL) infrastructure (CSTL-INF) or Web Application (CSTL-Web App). Eligibility: Right to work in the UK and eligibility for security clearance. Key Attributes Analytical thinker with a proactive, detail oriented approach. Excellent verbal and written communication skills. Ability to work effectively under pressure. Commitment to maintaining the highest ethical and professional standards. Prior experience leading a Penetration testing team. Are you an experienced Lead Penetration Tester looking to further improve your skills and take on more responsibilities? If so, this opportunity is perfect for you!
Apr 13, 2026
Full time
Location This role offers flexibility to work remotely from your own home, or as a hybrid arrangement and work from our offices in Oxford or Glasgow, if preferred. There is also a requirement for flexibility from employees to visit client sites across the UK as part of this role. Why join Dionach by Nomios? Since being acquired by Nomios in late 2024, Dionach by Nomios has continued its dynamic growth as a leading information security company. Specializing in penetration testing and information assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety of our clients. Dionach is also proud to be Great Place To Work Certified , a recognition based entirely on feedback from our team. We're committed to creating an environment where people feel supported, valued and able to grow. Learn more about our certification here: Working at Dionach Great Place to Work UK. We're in an exciting phase of expansion and are looking for self motivated individuals ready to thrive in a fun, flexible environment. At Dionach by Nomios, your contributions will have a genuine impact on the business, and you'll find opportunities for both interesting work and career development. Benefits Our employees are the heart of our business. We value our employees and invest in their growth and well being. Here's what we offer: Hybrid Working: Flexibility to work remotely or use our UK offices around client visits. Professional Growth: Access to training labs, certification sponsorship, and time for skill development. Well being Focus: Private health insurance, eye care plan, income protection, EAP scheme, and well being platform. Our Commitment to Diversity and Inclusion At Dionach by Nomios, we believe that diversity fuels innovation. We're dedicated to creating an inclusive workplace where everyone feels valued and respected. We welcome applications from all backgrounds, perspectives, and experiences, and we're committed to being an equal opportunity employer. We do not discriminate based on race, religion, gender, age, disability, or any other legally protected status. We encourage candidates from underrepresented groups to apply and are committed to providing a supportive and accessible environment for all our employees. If you require accommodations during the application process, let us know, and we'll work to meet your needs. The salary band advertised for this role is £55,000 to £80,000 per annum, depending on experience. What You'll Do Lead and mentor a team of Penetration testers, fostering a collaborative and high performance work environment. Lead and oversee complex infrastructure penetration tests ensuring that they are conducted thoroughly and in accordance with project requirement. Leading onsite customer engagements and serving as the technical authority on CHECK engagements. Review and validate the work of team members to ensure accuracy and thoroughness. Prepare and deliver comprehensive reports detailing findings, risks, and recommended remediation strategies to clients, including assisting with proposal writing and scoping. You will have the opportunity to work on a wide range of services: web and mobile application tests, internal tests, infrastructure tests, but also, social engineering. Ensure all testing activities comply with CHECK standards. What We're Looking For Experience: Significant experience in penetration testing, including network, web application and internal penetration testing as well as experience of leading customer engagements on site. Communication: Strong verbal and written skills for stakeholder management, collaboration and administration duties. Independence: Ability to work independently or as part of a team. Certifications: Holding a relevant certification: CREST Certified Tester - Infrastructure (CCT INF), CREST Certified Tester - Application (CCT APP), Cyber Scheme Team Leader (CSTL) infrastructure (CSTL-INF) or Web Application (CSTL-Web App). Eligibility: Right to work in the UK and eligibility for security clearance. Key Attributes Analytical thinker with a proactive, detail oriented approach. Excellent verbal and written communication skills. Ability to work effectively under pressure. Commitment to maintaining the highest ethical and professional standards. Prior experience leading a Penetration testing team. Are you an experienced Lead Penetration Tester looking to further improve your skills and take on more responsibilities? If so, this opportunity is perfect for you!
A leading cybersecurity firm in the UK is seeking a skilled Penetration Tester to join their Global Services team. The successful candidate will be responsible for delivering innovative social engineering campaigns aimed at improving client security postures. This role requires 5+ years of experience in a technical security capacity, advanced knowledge of social engineering techniques, and expertise in managing phishing operations at scale. Join a dynamic team dedicated to challenging cybersecurity norms.
Apr 13, 2026
Full time
A leading cybersecurity firm in the UK is seeking a skilled Penetration Tester to join their Global Services team. The successful candidate will be responsible for delivering innovative social engineering campaigns aimed at improving client security postures. This role requires 5+ years of experience in a technical security capacity, advanced knowledge of social engineering techniques, and expertise in managing phishing operations at scale. Join a dynamic team dedicated to challenging cybersecurity norms.
A leading information security company is seeking a Lead Penetration Tester to mentor a team and oversee complex testing engagements. This role offers flexibility to work remotely or hybrid from offices in Oxford or Glasgow. Key responsibilities include leading testing activities, preparing reports, and ensuring compliance with CHECK standards. The position requires significant experience in penetration testing, strong communication skills, and relevant certifications. A competitive salary band between £55,000 to £80,000 is offered, dependent on experience.
Apr 13, 2026
Full time
A leading information security company is seeking a Lead Penetration Tester to mentor a team and oversee complex testing engagements. This role offers flexibility to work remotely or hybrid from offices in Oxford or Glasgow. Key responsibilities include leading testing activities, preparing reports, and ensuring compliance with CHECK standards. The position requires significant experience in penetration testing, strong communication skills, and relevant certifications. A competitive salary band between £55,000 to £80,000 is offered, dependent on experience.
Location This role offers flexibility to work remotely from your own home, or as a hybrid arrangement and work from our offices in Oxford or Glasgow, if preferred. There is also a requirement for flexibility from employees to visit client sites across the UK as part of this role. Why join Dionach by Nomios? Since being acquired by Nomios in late 2024, Dionach by Nomios has continued its dynamic growth as a leading information security company. Specializing in penetration testing and information assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety of our clients. Dionach is also proud to be Great Place To Work Certified , a recognition based entirely on feedback from our team. We're committed to creating an environment where people feel supported, valued and able to grow. Learn more about our certification here: Working at Dionach Great Place to Work UK. We're in an exciting phase of expansion and are looking for self-motivated individuals ready to thrive in a fun, flexible environment. At Dionach by Nomios, your contributions will have a genuine impact on the business, and you'll find opportunities for both interesting work and career development. Benefits Our employees are the heart of our business. We value our employees and invest in their growth and well-being. Here's what we offer: Hybrid Working: Flexibility to work remotely or use our UK offices around client visits. Professional Growth: Access to training labs, certification sponsorship, and time for skill development. Well-being Focus: Private health insurance, eye care plan, income protection, EAP scheme, and well-being platform. Our Commitment to Diversity and Inclusion At Dionach by Nomios, we believe that diversity fuels innovation. We're dedicated to creating an inclusive workplace where everyone feels valued and respected. We welcome applications from all backgrounds, perspectives, and experiences, and we're committed to being an equal opportunity employer. We do not discriminate based on race, religion, gender, age, disability, or any other legally protected status. We encourage candidates from underrepresented groups to apply and are committed to providing a supportive and accessible environment for all our employees. If you require accommodations during the application process, let us know, and we'll work to meet your needs. The salary band advertised for this role is £40,000 to £65,000 per annum, depending on experience. What You'll Do Conduct penetration tests across various environments, including web applications, APIs, Cloud, and network infrastructure. Issue detailed reports outlining findings, risks, and recommendations for remediation. Translate complex technical findings into actionable insights for both technical and non-technical audiences. Stay updated with the latest security trends, tools, and techniques. Participate in research and development projects. Focus on your development by attaining industry recognised certifications. Be available for occasional on-call duties and on-site client engagements, as needed. What We're Looking For Certifications: Relevant certifications such as CREST CRT, CREST CCT, OSCP, OSWE, OSCE, or equivalent level. Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. Independence: Ability to work solo or as part of a team on penetration tests. Eligibility: Right to work in the UK and eligibility for security clearance. Key Attributes Analytical thinker with a proactive, detail oriented approach. Excellent verbal and written communication skills, capable of engaging with technical and non-technical stakeholders. Ability to work effectively under pressure and adapt to rapidly changing threat landscapes. Commitment to maintaining the highest ethical and professional standards. Are you an experienced penetration tester looking to further improve your skills and take on more responsibilities? If so, this opportunity is perfect for you! We look forward to receiving your applications!
Apr 12, 2026
Full time
Location This role offers flexibility to work remotely from your own home, or as a hybrid arrangement and work from our offices in Oxford or Glasgow, if preferred. There is also a requirement for flexibility from employees to visit client sites across the UK as part of this role. Why join Dionach by Nomios? Since being acquired by Nomios in late 2024, Dionach by Nomios has continued its dynamic growth as a leading information security company. Specializing in penetration testing and information assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety of our clients. Dionach is also proud to be Great Place To Work Certified , a recognition based entirely on feedback from our team. We're committed to creating an environment where people feel supported, valued and able to grow. Learn more about our certification here: Working at Dionach Great Place to Work UK. We're in an exciting phase of expansion and are looking for self-motivated individuals ready to thrive in a fun, flexible environment. At Dionach by Nomios, your contributions will have a genuine impact on the business, and you'll find opportunities for both interesting work and career development. Benefits Our employees are the heart of our business. We value our employees and invest in their growth and well-being. Here's what we offer: Hybrid Working: Flexibility to work remotely or use our UK offices around client visits. Professional Growth: Access to training labs, certification sponsorship, and time for skill development. Well-being Focus: Private health insurance, eye care plan, income protection, EAP scheme, and well-being platform. Our Commitment to Diversity and Inclusion At Dionach by Nomios, we believe that diversity fuels innovation. We're dedicated to creating an inclusive workplace where everyone feels valued and respected. We welcome applications from all backgrounds, perspectives, and experiences, and we're committed to being an equal opportunity employer. We do not discriminate based on race, religion, gender, age, disability, or any other legally protected status. We encourage candidates from underrepresented groups to apply and are committed to providing a supportive and accessible environment for all our employees. If you require accommodations during the application process, let us know, and we'll work to meet your needs. The salary band advertised for this role is £40,000 to £65,000 per annum, depending on experience. What You'll Do Conduct penetration tests across various environments, including web applications, APIs, Cloud, and network infrastructure. Issue detailed reports outlining findings, risks, and recommendations for remediation. Translate complex technical findings into actionable insights for both technical and non-technical audiences. Stay updated with the latest security trends, tools, and techniques. Participate in research and development projects. Focus on your development by attaining industry recognised certifications. Be available for occasional on-call duties and on-site client engagements, as needed. What We're Looking For Certifications: Relevant certifications such as CREST CRT, CREST CCT, OSCP, OSWE, OSCE, or equivalent level. Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. Independence: Ability to work solo or as part of a team on penetration tests. Eligibility: Right to work in the UK and eligibility for security clearance. Key Attributes Analytical thinker with a proactive, detail oriented approach. Excellent verbal and written communication skills, capable of engaging with technical and non-technical stakeholders. Ability to work effectively under pressure and adapt to rapidly changing threat landscapes. Commitment to maintaining the highest ethical and professional standards. Are you an experienced penetration tester looking to further improve your skills and take on more responsibilities? If so, this opportunity is perfect for you! We look forward to receiving your applications!
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client's perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies. About the Team Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities-it tests the customer's entire security posture and defense-in-depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments. About the Role Your primary responsibility is to deliver Rapid7's Vector Command Continuous Red Teaming service. In this role, you will design social engineering campaigns which function at scale, supporting numerous customers each month, emulating modern adversary TTPs. These campaigns focus on initial access, not click rates, and are often combined with external vulnerabilities or misconfigurations to demonstrate real-world impact. Specifically, your focus will be to: Deploy, configure, and maintain social engineering infrastructure to perform phishing operations at scale. Perform manual and automated reconnaissance at scale to identify targets for social engineering operations each month. Leverage external network vulnerabilities reported by Vector Command team members in targeted real world social engineering attacks (incorporate subdomain takeovers, cross site scripting, etc. into campaigns). Research the latest techniques in social engineering and implement them in monthly campaigns. Research and test methods to bypass social engineering defenses such as email filters, download restrictions, multi factor authentication mechanisms, etc. Be an expert in sending phishing emails which make it to the client's inbox. Design and execute vishing campaigns. Incorporate payloads provided by the Red Team lead into phishing and vishing operations. Upon successful credential breach or payload execution, evaluate the impact and coordinate with Vector Command team members for post compromise breach simulation. Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction. Develop and maintain positive relationships with clients and understand their business and needs. Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices. The skills and qualities you'll bring include: 5+ years in an active technical security role Strong knowledge of the following: Advanced Social engineering techniques and tactics Infrastructure management and deployment (domain records, web servers, terraform, ansible, phishing website creation). Modern penetration testing tools and methods Network, wireless and web application security concepts Experience using interpreted languages (Ruby, Python, PHP, etc.) Knowledge of common regulatory structures and obligations and common I.T. governance. Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet facing attack surfaces Certifications such as OSCP, OSCE, GXPN, OSEE, CREST Experience with Red & Purple Teams Excellent communication skills both with internal and external stakeholders Collaborative mindset, contributing to knowledge sharing and cross training Demonstrate a commitment to the "end-to-end" testing process, from the initial pre engagement planning to providing accountable support during the final remediation phase. Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Apr 10, 2026
Full time
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client's perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies. About the Team Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities-it tests the customer's entire security posture and defense-in-depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments. About the Role Your primary responsibility is to deliver Rapid7's Vector Command Continuous Red Teaming service. In this role, you will design social engineering campaigns which function at scale, supporting numerous customers each month, emulating modern adversary TTPs. These campaigns focus on initial access, not click rates, and are often combined with external vulnerabilities or misconfigurations to demonstrate real-world impact. Specifically, your focus will be to: Deploy, configure, and maintain social engineering infrastructure to perform phishing operations at scale. Perform manual and automated reconnaissance at scale to identify targets for social engineering operations each month. Leverage external network vulnerabilities reported by Vector Command team members in targeted real world social engineering attacks (incorporate subdomain takeovers, cross site scripting, etc. into campaigns). Research the latest techniques in social engineering and implement them in monthly campaigns. Research and test methods to bypass social engineering defenses such as email filters, download restrictions, multi factor authentication mechanisms, etc. Be an expert in sending phishing emails which make it to the client's inbox. Design and execute vishing campaigns. Incorporate payloads provided by the Red Team lead into phishing and vishing operations. Upon successful credential breach or payload execution, evaluate the impact and coordinate with Vector Command team members for post compromise breach simulation. Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction. Develop and maintain positive relationships with clients and understand their business and needs. Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices. The skills and qualities you'll bring include: 5+ years in an active technical security role Strong knowledge of the following: Advanced Social engineering techniques and tactics Infrastructure management and deployment (domain records, web servers, terraform, ansible, phishing website creation). Modern penetration testing tools and methods Network, wireless and web application security concepts Experience using interpreted languages (Ruby, Python, PHP, etc.) Knowledge of common regulatory structures and obligations and common I.T. governance. Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet facing attack surfaces Certifications such as OSCP, OSCE, GXPN, OSEE, CREST Experience with Red & Purple Teams Excellent communication skills both with internal and external stakeholders Collaborative mindset, contributing to knowledge sharing and cross training Demonstrate a commitment to the "end-to-end" testing process, from the initial pre engagement planning to providing accountable support during the final remediation phase. Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
A leading information security company in the UK is seeking an experienced penetration tester. This role involves conducting comprehensive penetration tests on various environments, including web applications and Cloud services. The ideal candidate will have at least two years of experience, relevant certifications, and strong communication skills. The position offers flexibility to work remotely or in hybrid arrangements, competitive salary ranging from £40,000 to £65,000 per annum, and a focus on professional growth and well-being.
Apr 10, 2026
Full time
A leading information security company in the UK is seeking an experienced penetration tester. This role involves conducting comprehensive penetration tests on various environments, including web applications and Cloud services. The ideal candidate will have at least two years of experience, relevant certifications, and strong communication skills. The position offers flexibility to work remotely or in hybrid arrangements, competitive salary ranging from £40,000 to £65,000 per annum, and a focus on professional growth and well-being.
Location This role offers flexibility to work remotely from your own home, or as a hybrid arrangement and work from our offices in Oxford or Glasgow, if preferred. There is also a requirement for flexibility from employees to visit client sites across the UK as part of this role. Why join Dionach by Nomios? Since being acquired by Nomios in late 2024, Dionach by Nomios has continued its dynamic growth as a leading information security company. Specializing in penetration testing and information assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety of our clients. Dionach is also proud to be Great Place To Work Certified , a recognition based entirely on feedback from our team. We're committed to creating an environment where people feel supported, valued and able to grow. Learn more about our certification here: Working at Dionach Great Place to Work UK. We're in an exciting phase of expansion and are looking for self-motivated individuals ready to thrive in a fun, flexible environment. At Dionach by Nomios, your contributions will have a genuine impact on the business, and you'll find opportunities for both interesting work and career development. Benefits Our employees are the heart of our business. We value our employees and invest in their growth and well-being. Here's what we offer: Hybrid Working: Flexibility to work remotely or use our UK offices around client visits. Professional Growth: Access to training labs, certification sponsorship, and time for skill development. Well-being Focus: Private health insurance, eye care plan, income protection, EAP scheme, and well-being platform. Our Commitment to Diversity and Inclusion At Dionach by Nomios, we believe that diversity fuels innovation. We're dedicated to creating an inclusive workplace where everyone feels valued and respected. We welcome applications from all backgrounds, perspectives, and experiences, and we're committed to being an equal opportunity employer. We do not discriminate based on race, religion, gender, age, disability, or any other legally protected status. We encourage candidates from underrepresented groups to apply and are committed to providing a supportive and accessible environment for all our employees. If you require accommodations during the application process, let us know, and we'll work to meet your needs. The salary band advertised for this role is £40,000 to £65,000 per annum, depending on experience. What You'll Do Conduct penetration tests across various environments, including web applications, APIs, Cloud, and network infrastructure. Issue detailed reports outlining findings, risks, and recommendations for remediation. Translate complex technical findings into actionable insights for both technical and non-technical audiences. Stay updated with the latest security trends, tools, and techniques. Participate in research and development projects. Focus on your development by attaining industry recognised certifications. Be available for occasional on-call duties and on-site client engagements, as needed. What We're Looking For Certifications: Relevant certifications such as CREST CRT, CREST CCT, OSCP, OSWE, OSCE, or equivalent level. Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. Independence: Ability to work solo or as part of a team on penetration tests. Eligibility: Right to work in the UK and eligibility for security clearance. Key Attributes Analytical thinker with a proactive, detail oriented approach. Excellent verbal and written communication skills, capable of engaging with technical and non-technical stakeholders. Ability to work effectively under pressure and adapt to rapidly changing threat landscapes. Commitment to maintaining the highest ethical and professional standards. Are you an experienced penetration tester looking to further improve your skills and take on more responsibilities? If so, this opportunity is perfect for you! We look forward to receiving your applications!
Apr 10, 2026
Full time
Location This role offers flexibility to work remotely from your own home, or as a hybrid arrangement and work from our offices in Oxford or Glasgow, if preferred. There is also a requirement for flexibility from employees to visit client sites across the UK as part of this role. Why join Dionach by Nomios? Since being acquired by Nomios in late 2024, Dionach by Nomios has continued its dynamic growth as a leading information security company. Specializing in penetration testing and information assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety of our clients. Dionach is also proud to be Great Place To Work Certified , a recognition based entirely on feedback from our team. We're committed to creating an environment where people feel supported, valued and able to grow. Learn more about our certification here: Working at Dionach Great Place to Work UK. We're in an exciting phase of expansion and are looking for self-motivated individuals ready to thrive in a fun, flexible environment. At Dionach by Nomios, your contributions will have a genuine impact on the business, and you'll find opportunities for both interesting work and career development. Benefits Our employees are the heart of our business. We value our employees and invest in their growth and well-being. Here's what we offer: Hybrid Working: Flexibility to work remotely or use our UK offices around client visits. Professional Growth: Access to training labs, certification sponsorship, and time for skill development. Well-being Focus: Private health insurance, eye care plan, income protection, EAP scheme, and well-being platform. Our Commitment to Diversity and Inclusion At Dionach by Nomios, we believe that diversity fuels innovation. We're dedicated to creating an inclusive workplace where everyone feels valued and respected. We welcome applications from all backgrounds, perspectives, and experiences, and we're committed to being an equal opportunity employer. We do not discriminate based on race, religion, gender, age, disability, or any other legally protected status. We encourage candidates from underrepresented groups to apply and are committed to providing a supportive and accessible environment for all our employees. If you require accommodations during the application process, let us know, and we'll work to meet your needs. The salary band advertised for this role is £40,000 to £65,000 per annum, depending on experience. What You'll Do Conduct penetration tests across various environments, including web applications, APIs, Cloud, and network infrastructure. Issue detailed reports outlining findings, risks, and recommendations for remediation. Translate complex technical findings into actionable insights for both technical and non-technical audiences. Stay updated with the latest security trends, tools, and techniques. Participate in research and development projects. Focus on your development by attaining industry recognised certifications. Be available for occasional on-call duties and on-site client engagements, as needed. What We're Looking For Certifications: Relevant certifications such as CREST CRT, CREST CCT, OSCP, OSWE, OSCE, or equivalent level. Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. Independence: Ability to work solo or as part of a team on penetration tests. Eligibility: Right to work in the UK and eligibility for security clearance. Key Attributes Analytical thinker with a proactive, detail oriented approach. Excellent verbal and written communication skills, capable of engaging with technical and non-technical stakeholders. Ability to work effectively under pressure and adapt to rapidly changing threat landscapes. Commitment to maintaining the highest ethical and professional standards. Are you an experienced penetration tester looking to further improve your skills and take on more responsibilities? If so, this opportunity is perfect for you! We look forward to receiving your applications!
A leading information security company in the UK seeks experienced penetration testers who can work remotely or in a hybrid model. Applicants should possess relevant certifications and have at least two years of experience in penetration testing, including web and network environments. The role involves conducting tests, issuing detailed reports, and engaging with stakeholders. Join us to advance your skills in a supportive environment committed to your professional growth and inclusivity.
Apr 06, 2026
Full time
A leading information security company in the UK seeks experienced penetration testers who can work remotely or in a hybrid model. Applicants should possess relevant certifications and have at least two years of experience in penetration testing, including web and network environments. The role involves conducting tests, issuing detailed reports, and engaging with stakeholders. Join us to advance your skills in a supportive environment committed to your professional growth and inclusivity.
About the opportunity Are you ready to launch a career in cyber security? Netcom Training's fully-funded Cyber Security course (NCFE Certificate in Cyber Security Practices, Level 3) equips you with the practical skills employers in Greater Manchester are actively seeking. From threat intelligence and security testing to incident response and ethical compliance, you'll gain hands-on experience that prepares you for today's fast-growing cyber security and IT roles. Our learners have gone on to roles such as Cyber Security Analyst, Junior Penetration Tester, SOC Analyst, and IT Support, working with companies across tech, logistics, public services, and digital sectors. Complete the course and gain a guaranteed interview with a leading employer, helping you start your career protecting businesses, data, and digital systems. Course Details Start Date: 30/03 Duration: 14 weeks Format: Online, practical workshops Schedule: Mon-Thurs 6-9PM What you'll learn Cyber Principles: Understand core frameworks and security principles. Threat Intelligence: Develop expertise to identify risks and analyze threats. Vulnerability Testing: Conduct cyber security testing, identify vulnerabilities, and implement controls. Incident Response: Prepare for and respond to live cyber security incidents. Ethics & Law: Understand legislation and ethical conduct within the cyber security sector. Professional Skills: Build the behaviours required for the modern cyber security workplace. Career Pathway Successful participants are guaranteed an interview with us or our network of UK-wide partners working with leading brands. Potential Roles: Trainee Cyber Security Analyst, SOC Analyst, Junior Information Security Officer. Starting Salaries: Typically £22,000 - £35,000 (role dependent). Eligibility This is a government-funded opportunity. To apply, you must: Live in Greater Manchester. Be aged 19 or over. Earn below the gross annual wage cap of £32,400. Not currently be undertaking other government-funded training. Right to Work: You must have lived in the UK/EU for the last 3 years and have the right to work in the UK (Student/Graduate visas are not eligible). Cost This is a fully-funded course with no fees - complete the training, gain essential cyber security skills.
Apr 02, 2026
Full time
About the opportunity Are you ready to launch a career in cyber security? Netcom Training's fully-funded Cyber Security course (NCFE Certificate in Cyber Security Practices, Level 3) equips you with the practical skills employers in Greater Manchester are actively seeking. From threat intelligence and security testing to incident response and ethical compliance, you'll gain hands-on experience that prepares you for today's fast-growing cyber security and IT roles. Our learners have gone on to roles such as Cyber Security Analyst, Junior Penetration Tester, SOC Analyst, and IT Support, working with companies across tech, logistics, public services, and digital sectors. Complete the course and gain a guaranteed interview with a leading employer, helping you start your career protecting businesses, data, and digital systems. Course Details Start Date: 30/03 Duration: 14 weeks Format: Online, practical workshops Schedule: Mon-Thurs 6-9PM What you'll learn Cyber Principles: Understand core frameworks and security principles. Threat Intelligence: Develop expertise to identify risks and analyze threats. Vulnerability Testing: Conduct cyber security testing, identify vulnerabilities, and implement controls. Incident Response: Prepare for and respond to live cyber security incidents. Ethics & Law: Understand legislation and ethical conduct within the cyber security sector. Professional Skills: Build the behaviours required for the modern cyber security workplace. Career Pathway Successful participants are guaranteed an interview with us or our network of UK-wide partners working with leading brands. Potential Roles: Trainee Cyber Security Analyst, SOC Analyst, Junior Information Security Officer. Starting Salaries: Typically £22,000 - £35,000 (role dependent). Eligibility This is a government-funded opportunity. To apply, you must: Live in Greater Manchester. Be aged 19 or over. Earn below the gross annual wage cap of £32,400. Not currently be undertaking other government-funded training. Right to Work: You must have lived in the UK/EU for the last 3 years and have the right to work in the UK (Student/Graduate visas are not eligible). Cost This is a fully-funded course with no fees - complete the training, gain essential cyber security skills.