Penetration Tester | Ethical Hacking | Red Team Operations
Salary: £65,000 – £90,000 per year (Depending on Experience)
Location: United Kingdom – Remote or Hybrid (London / Manchester preferred)
Type: Full-Time
Industry: Cybersecurity / Information Security / Penetration Testing
Job Owner: Tariq Masood
Job Description
We are seeking a skilled and certified Penetration Tester to join our growing cybersecurity team, responsible for identifying, exploiting, and mitigating security vulnerabilities across digital environments.
In this role, you’ll conduct penetration tests, perform red team operations, and deliver strategic recommendations to strengthen the organization’s cyber defense posture.
This is an exciting opportunity for professionals who thrive on solving complex security challenges and want to work on real-world offensive security engagements that directly impact organizational resilience.
Experience
3–5+ years of hands-on experience in penetration testing, red teaming, or ethical hacking.
Key Responsibilities
- Conduct penetration tests across web applications, APIs, mobile platforms, networks, and cloud environments.
 - Perform vulnerability scanning, manual exploitation, and post-exploitation analysis.
 - Simulate real-world attacks through red team exercises, including phishing and social engineering.
 - Document and prioritize vulnerabilities, misconfigurations, and security flaws.
 - Collaborate with defensive security and incident response teams to validate and remediate findings.
 - Generate technical reports and executive summaries with clear remediation recommendations.
 - Stay current with the latest CVE disclosures, threat actor tactics, and offensive security tools.
 
Required Skills
- Expertise in penetration testing tools such as Burp Suite, Metasploit, Nmap, Wireshark, Kali Linux, and Hydra.
 - Strong understanding of OWASP Top 10, network protocols, and exploit development.
 - Knowledge of MITRE ATT&CK, Cyber Kill Chain, and red team methodologies.
 - Familiarity with firewalls, DNS, HTTP/HTTPS, and encryption protocols.
 - Excellent documentation, report writing, and stakeholder communication skills.
 - One or more industry certifications such as OSCP, CEH, CREST CRT, or GPEN.
 
Desired Skills
- Scripting or automation experience with Python, PowerShell, or Bash.
 - Experience in cloud security testing (AWS, Azure, GCP).
 - Knowledge of DevSecOps and CI/CD pipeline security.
 - Exposure to adversary emulation, purple teaming, or threat intelligence integration.
 - Understanding of physical penetration testing and social engineering tactics.
 
Job Benefits
- Competitive salary with annual performance bonus
 - Fully remote or hybrid working options
 - Private healthcare and pension scheme
 - Funded certifications and training (OSCP, CREST, GPEN, etc.)
 - 25+ days holiday plus bank holidays
 - Conference attendance support (DEF CON, Black Hat, BSides)
 - Collaborative culture within a high-performing security team
 
Education
- Degree not required, but a strong technical background and relevant security certifications are preferred.
 
Additional Details
- Experience Required: 3–5 years in penetration testing or ethical hacking
 - Work Mode: Remote / Hybrid (UK-based)
 - Sponsorship: Not considered