Penetration Tester

Job Category: Cybersecurity

Penetration Tester | Ethical Hacking | Red Team Operations

Salary: £65,000 – £90,000 per year (Depending on Experience)
Location: United Kingdom – Remote or Hybrid (London / Manchester preferred)
Type: Full-Time
Industry: Cybersecurity / Information Security / Penetration Testing
Job Owner: Tariq Masood


Job Description

We are seeking a skilled and certified Penetration Tester to join our growing cybersecurity team, responsible for identifying, exploiting, and mitigating security vulnerabilities across digital environments.

In this role, you’ll conduct penetration tests, perform red team operations, and deliver strategic recommendations to strengthen the organization’s cyber defense posture.

This is an exciting opportunity for professionals who thrive on solving complex security challenges and want to work on real-world offensive security engagements that directly impact organizational resilience.


Experience

3–5+ years of hands-on experience in penetration testing, red teaming, or ethical hacking.


Key Responsibilities

  • Conduct penetration tests across web applications, APIs, mobile platforms, networks, and cloud environments.
  • Perform vulnerability scanning, manual exploitation, and post-exploitation analysis.
  • Simulate real-world attacks through red team exercises, including phishing and social engineering.
  • Document and prioritize vulnerabilities, misconfigurations, and security flaws.
  • Collaborate with defensive security and incident response teams to validate and remediate findings.
  • Generate technical reports and executive summaries with clear remediation recommendations.
  • Stay current with the latest CVE disclosures, threat actor tactics, and offensive security tools.

Required Skills

  • Expertise in penetration testing tools such as Burp Suite, Metasploit, Nmap, Wireshark, Kali Linux, and Hydra.
  • Strong understanding of OWASP Top 10, network protocols, and exploit development.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and red team methodologies.
  • Familiarity with firewalls, DNS, HTTP/HTTPS, and encryption protocols.
  • Excellent documentation, report writing, and stakeholder communication skills.
  • One or more industry certifications such as OSCP, CEH, CREST CRT, or GPEN.

Desired Skills

  • Scripting or automation experience with Python, PowerShell, or Bash.
  • Experience in cloud security testing (AWS, Azure, GCP).
  • Knowledge of DevSecOps and CI/CD pipeline security.
  • Exposure to adversary emulation, purple teaming, or threat intelligence integration.
  • Understanding of physical penetration testing and social engineering tactics.

Job Benefits

  • Competitive salary with annual performance bonus
  • Fully remote or hybrid working options
  • Private healthcare and pension scheme
  • Funded certifications and training (OSCP, CREST, GPEN, etc.)
  • 25+ days holiday plus bank holidays
  • Conference attendance support (DEF CON, Black Hat, BSides)
  • Collaborative culture within a high-performing security team

Education

  • Degree not required, but a strong technical background and relevant security certifications are preferred.

Additional Details

  • Experience Required: 3–5 years in penetration testing or ethical hacking
  • Work Mode: Remote / Hybrid (UK-based)
  • Sponsorship: Not considered

Apply for this position

Allowed Type(s): .pdf, .doc, .docx

Ready to Take the Next Step?

Build your high-performing team with MastarRec’s specialist recruitment solutions.