Overview
In this role you will lead hands-on penetration testing across complex environments, delivering security assessments for public sector, CNI, and large enterprises. You’ll work with cloud, containerized tech, and on-prem infrastructure to identify vulnerabilities and communicate risk to clients. You’ll help shape testing methodologies and mentor junior consultants, contributing to secure architectures and service offerings. This role suits a technically strong security professional seeking impactful, varied engagements and SC clearance.
Pay / Benefits
- remote work
Responsibilities
- Deliver manual penetration testing and security assessments across infrastructure, networks, operating systems, web applications and APIs
- Test security across Azure, AWS and other cloud environments
- Assess Kubernetes, Docker, IAM and CI/CD environments
- Perform internal and external infrastructure penetration tests
- Identify, exploit and document security vulnerabilities
- Produce high-quality technical reports and present findings to clients
- Collaborate with clients to communicate technical risks and environment needs
- Contribute to security architecture and security control reviews
- Mentor junior consultants with knowledge sharing and guidance
- Keep up to date with emerging vulnerabilities and industry developments
- Contribute to the development of pentesting methodologies, tooling and service offerings
Key requirements
- Proven commercial experience in penetration testing / offensive security
- Strong hands-on experience across infrastructure and/or application penetration testing
- Experience with cloud environments, particularly Azure and/or AWS
- Experience with Kubernetes, Docker, APIs and CI/CD
- Strong understanding of current attack techniques, vulnerabilities and defensive controls
- Excellent report writing and client-facing communication skills
- Current UK Security Clearance (SC)
- Client-facing communication
- Mentoring junior testers
- Technical guidance and collaboration
- Penetration testing (infrastructure and/or applications)
- Azure and/or AWS cloud security
- Kubernetes and Docker
…
