Overview
In this role you will lead and execute hands-on penetration testing across web apps, APIs, and network infrastructures within a collaborative risk advisory team. You’ll deliver Cyber Essentials Plus assessments and broader security reviews, translating findings into actionable remediation for clients. The work blends technical delivery (majority) with advisory activities to broaden your consulting scope. You’ll help shape security outcomes for diverse clients while developing offensive security expertise in a growth-focused practice.
Responsibilities
- Lead and support penetration testing engagements across web applications, APIs, and internal/external network infrastructure
- Define objectives, scope, and rules of engagement with clients and plan testing
- Apply manual and tool-assisted testing using established methodologies (OWASP, PTES, MITRE ATT&CK)
- Deliver Cyber Essentials Plus assessments from scoping to certification support
- Conduct wider technical assessments (vulnerability, cloud security, CIS benchmarks) and build/configuration reviews
- Produce clear, high-quality deliverables and present findings to technical and non-technical audiences
- Apply risk ratings, explain business impact, and support remediation and retesting
- Support advisory engagements such as cyber risk assessments, security control reviews, and security design advice
- Build client relationships and contribute to business development, proposals, scoping, and thought leadership
- Maintain knowledge of threat landscape and contribute to QA and continuous improvement of methodologies/tools
Key requirements
- Experience delivering client-facing penetration tests across web apps, APIs, and networks
- Strong manual testing capability with practical use of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus
- Ability to script/automate tasks using Python, PowerShell, Bash, or similar
- Knowledge of modern web architecture, vulnerabilities, TCP/IP, Windows/Linux security, Active Directory/Microsoft Entra ID attack paths
- Experience with vulnerability assessments and configuration reviews against CIS benchmarks
- Working knowledge of Cyber Essentials and Cyber Essentials Plus; assessor experience is beneficial
- Ability to manage engagements within scope, timelines, budget, and quality with clear testing evidence
- Strong written and verbal communication to explain findings and business impact
- Proactive, client-oriented mindset with willingness to learn and work with SMEs to larger enterprises
- Proactive
- Strong stakeholder management
- Clear communicator (technical and non-technical)
- Kali Linux
- Burp Suite
- Nmap
…
