Cyber Security Penetration Tester

Company: Accenture
Apply for the Cyber Security Penetration Tester
Location: Edinburgh
Job Description:

Overview

In this role you will perform hands-on security testing of client web apps, APIs and infrastructure, within a collaborative team supported by senior testers. You will identify vulnerabilities, demonstrate impact, and provide actionable remediation guidance. The position supports your growth toward recognised certifications and broader technical skills. You’ll work across engagements with CHECK leadership and peers, contributing to secure, resilient client outcomes.

Pay / Benefits

  • funded certification pathway (CRT, CSTM, to CCT/CSTL)
  • dedicated time for training, research and lab work
  • mentoring from experienced testers and CHECK Team Leaders
  • hybrid work model (UK-wide, 1x in-office per month)
  • opportunities to contribute to tooling, methodology and innovation projects

Responsibilities

  • Perform manual and tool-assisted testing of web applications, APIs and internal/external infrastructure
  • Identify, validate and safely exploit vulnerabilities within rules of engagement (auth, authorization, injection, logic, misconfig)
  • Trace attack paths, explain business impact and remediation
  • Follow OWASP (WSTG, API Security Top 10), PTES and CHECK/CREST standards
  • Prepare for engagements by confirming scope and prerequisites
  • Write clear reports with reproducible evidence and risk-based remediation
  • Support client remediation and conduct retests
  • Escalate critical findings and communicate impact to stakeholders
  • Share knowledge through peer review, tooling improvements and technical write-ups

Key requirements

  • Typically 1–2 years’ commercial penetration testing experience across web apps, APIs, infrastructure
  • Good working knowledge of OWASP Top 10 and API Security Top 10
  • Practical experience with Burp Suite, Nmap and Metasploit
  • Ability to validate findings, rule out false positives and capture reproducible evidence
  • Clear technical writing that explains risk and remediation in plain language
  • Clear technical writing
  • Team collaboration
  • Problem-solving and analytical thinking
  • Burp Suite
  • Nmap
  • Metasploit

…

Posted: October 10th, 2026