76 to 100 of 510 Permanent Penetration Testing Jobs

AI Software Engineer

Hiring Organisation
Infosec
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
client, a leading technology business specialising in cybersecurity and penetration testing, is seeking an AI Software Engineer to join its permanent, fully remote team in the UK. This senior-level role focuses on building intelligent AI agents that can plan, reason, operate security tooling and identify exploitable vulnerabilities … within controlled environments. Key Responsibilities: Design, build and deploy AI agents that automate penetration testing, including planning, tool use and reasoning over security findings Develop sandboxed cyber-lab and range infrastructure using containers and Kubernetes Deliver AI features from initial design through to production, including evaluations, guardrails ...

Penetration Testing Program Governance & Vendor Strategy

Location
Greater London, England, United Kingdom
J.P. Morgan is seeking a Program Governance Lead for Penetration Testing to coordinate vendor management and delivery excellence across the program. This role focuses on governance, strategy, and commercial aspects, not hands-on testing. The successful candidate will operate across vendor relationships, reporting structures, and cross-functional governance … forums to ensure consistent outcomes and alignment with the Penetration Testing strategy. #J-18808-Ljbffr ...

Information Security Lead (GRC)

Hiring Organisation
Enorth Resourcing Limited
Location
Bedford, Bedfordshire, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £70,000 per annum
supplier security and audit remediation, alongside Cyber Essentials and wider certification activities. You'll also work closely with technical teams across vulnerability management, patching, penetration testing, incident response, Business Continuity and Disaster Recovery, ensuring security risks and audit findings translate into practical improvements. SKILLS & EXPERIENCE We're particularly … Information Security Governance. • Security Audits & Assurance: Internal Audits, External Audits, Certification Audits, Audit Evidence, Remediation, Customer Assurance and Supplier Assurance. • Cyber Security: Vulnerability Management, Penetration Testing, Patch Management, Incident Response and Security Controls. • Resilience & Compliance: Cyber Essentials, Business Continuity, Disaster Recovery, DPIAs, BIAs and Third-Party Risk. ...

Automotive Cyber Security Lead

Location
Greater London, England, United Kingdom
operational technology (OT), embedded systems, relevant international cyber security standards and regulations (including ISO/SAE 21434, UNECE R155, UNECE R156, and ISO 26262), penetration testing methodologies, and the broader transport ecosystem. In addition to technical delivery, the individual will play a key role in supporting business development … Road Vehicle Cybersecurity Engineering) UNECE R155 (Cyber Security Management System) UNECE R156 (Software Update Management System) ISO 26262 (Functional Safety) Conduct or support penetration testing, vulnerability assessments, architecture reviews, risk assessments, and Threat Analysis and Risk Assessments (TARA) for automotive clients. Provide expert interpretation of cyber security requirements ...

Penetration Tester

Hiring Organisation
DGH Recruitment
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£55,000
Penetration Tester DGH Recruitment are currently recruiting on behalf of a leading client in the Accountancy industry who require a Penetration Tester to join the firm in London. Key Responsibilities: * Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. … Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. * Apply manual and tool-assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. * Deliver Cyber ...

Penetration Tester - Cloud Security, Active Directory, APIs

Hiring Organisation
Hays Specialist Recruitment Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Penetration Tester - Cloud Security, Active Directory, APIs Market Rate (Inside IR35) 6 Months initially Hybrid in London A client of mine is looking for a hands-on Penetration Tester to support their cybersecurity function, with some responsibilities across security operations and incident response. The right candidate will have … experience conducting infrastructure, Web Application, API, Cloud and Active Directory penetration tests within complex environments. Key Requirements: Proven commercial experience as a Penetration Tester, within a large enterprise environment. Strong hands-on Penetration Testing experience across Web Applications, APIs, infrastructure, Active Directory and cloud environments. Proven ...

Senior Security Engineer, AWS Security Verification & Validation Team

Hiring Organisation
Amazon
Location
United Kingdom
Salary
£ 70 K
looking for a Senior Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will be a technical leader on a team, owning complex security testing engagements … massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the security engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from ...

Senior Security Engineer, AWS Security Verification & Validation Team

Hiring Organisation
Amazon
Location
Moffat, Dumfries & Galloway, UK
Employment Type
Full-time
looking for a Senior Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will be a technical leader on a team, owning complex security testing engagements … massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the security engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from ...

Senior Cloud Security Engineer

Hiring Organisation
Vitality Corporate Services Limited
Location
Stockport, Greater Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£75,000
Partner closely with architecture teams to support the design and delivery of new Security Operations Centre (SOC) capabilities Support the planning and delivery of penetration testing activities, owning the coordination and remediation of identified findings Actively contribute to the continuous improvement of Vitalitys Information Security posture, staying current … need to thrive? Strong knowledge of cloud security across modern environments Advanced knowledge and hands-on experience with attack methodologies and security testing Experience across penetration testing (application and network), AppSec, wireless security and vulnerability management Experience implementing and managing security controls (e.g. DLP, patching, RBAC ...

Penetration Tester

Location
Greater London, England, United Kingdom
office] Position Type: Full-Time Role Overview The Product, Application and Offensive Security Engineer is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with … product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns ...

AVP Penetration Testing Lead

Location
United Kingdom
Barclays is seeking an experienced Penetration Tester - AVP to join its Security Assurance team in the UK. You will contribute to the delivery of penetration testing across annual lifecycle testing and change/project engagements, working with web, API, infrastructure, cloud, and other technologies. You will … lead complex assessments, develop testing methodologies, and communicate findings and remediation guidance to stakeholders. #J-18808-Ljbffr ...

Cyber Controls Manager

Location
Greater London, England, United Kingdom
traceability between cyber risks, regulatory requirements and implemented controls. Define control objectives and collaborate with technical teams to develop implementation guidance, testing criteria and evidence requirements. Support the continuous enhancement of the control environment in response to emerging threats, incidents, audits and lessons learned. Provide leadership and direction … identifying weaknesses, gaps or degraded controls and recommending corrective action. Evaluate control effectiveness against current and emerging cyber threats. Track the outcomes of control testing activities, including penetration testing, vulnerability assessments and security exercises, ensuring identified actions are progressed to completion. Governance, Reporting & Stakeholder Engagement Attend governance ...

Security Consultant - Consultancy

Location
Bristol, England, United Kingdom
giving team members the chance to work on high-impact digital transformation projects and collaborate with experienced professionals. This role involves conducting security assessments, penetration testing, and red team exercises, including government-accredited CHECK engagements, to help clients strengthen their security posture. Ready to take your … house developed tools for security testing. Conduct manual reviews to identify issues within customer infrastructure and web applications. Perform various types of security testing, including network penetration, web application, mobile security assessments, and social engineering. Participate in red team engagements, employing creative strategies to outsmart defenders. Explore various ...

Senior Offensive Security Engineer (Autonomous testing)

Location
City of Edinburgh, Scotland, United Kingdom
leadership, innovative thinking, curiosity, and existing deep technical expertise to help Quorum Cyber close the distance between AI speed and efficiency, and human insight. Penetration testing, API and web application testing, and red teaming are delivered the traditional way: a skilled human, a scope document, a fixed … agent-building are both non-negotiable. Offensive security depth Around 7 years hands-on, including at least 4 delivering client-facing engagements. Network testing: external and internal, Active Directory attack paths, privilege escalation, lateral movement, post-exploitation. Web and API testing: the OWASP Top 10 and, more importantly ...

IT Manager

Location
Lincoln, England, United Kingdom
threat logs, KnowBe4 training programs, and Secret Server credential storage. Network Security: Implementfirewallcontrols and email security standards (SMTP, TLS) to safeguard business data. Compliance & Testing: Contributeto ISO 27001 compliance (policy/documentation); review penetration testing and vulnerability scans to proactively mitigate risk. Business Continuity,Operational Reliability Disaster … Recovery:Monitorbackup systems, conduct regular restore testing, and support annual external audits and DR testing initiatives. Proactive Monitoring: Manage system uptime, antivirus/EDR, and SIEM tools to quicklyidentifyand resolve performance anomalies. Network Admin: Support Azure VPN connectivity and applied IP routing and subnetting fundamentals to resolve complex ...

Staff Cybersecurity Software & Systems Engineer (F/M/D)

Hiring Organisation
TE connectivity
Location
Cambridge, Cambridgeshire, United Kingdom
Salary
£ 70 K
/IaC scans, SBOM) and define release gates.Maintain security workflows and coach engineers on secure coding and threat‐driven design.Validation & Supplier EngagementSupport V&V, penetration testing, and remediation, and manage security alignment with suppliers.Compliance & DocumentationOwn the security compliance dossier, including Cybersecurity Plans, Interface Agreements, Security Cases, and Audit … Hardware Security Modules (HSM), secure element integration, and sensor-level protection. Skilled in cloud-native security practices, and zero-trust architecture. Experienced in advanced testing techniques, including penetration testing, fuzzing, and reverse engineering of embedded firmware. Knowledgeable in privacy engineering and compliance with regulatory frameworks like GDPR ...

Staff Cybersecurity Software & Systems Engineer (F/M/D)

Hiring Organisation
TE Connectivity
Location
Cambridgeshire, United Kingdom
Employment Type
Full Time
SBOM) and define release gates. Maintain security workflows and coach engineers on secure coding and threat‐driven design. Validation & Supplier Engagement Support V&V, penetration testing, and remediation, and manage security alignment with suppliers. Compliance & Documentation Own the security compliance dossier, including Cybersecurity Plans, Interface Agreements, Security Cases … Hardware Security Modules (HSM), secure element integration, and sensor-level protection. Skilled in cloud-native security practices, and zero-trust architecture. Experienced in advanced testing techniques, including penetration testing, fuzzing, and reverse engineering of embedded firmware. Knowledgeable in privacy engineering and compliance with regulatory frameworks like GDPR ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment and security scanning activities using relevant tools. Provide input into penetration testing activities and interpret findings for remediation. Deliver training, coaching, and knowledge transfer to enhance the existing cybersecurity team's skills in CrowdStrike … enterprise environments. Experience supporting or working alongside managed SOC providers. At least 2 years’ experience in vulnerability assessment tools (desirable). Exposure to penetration testing and web application security testing (desirable). Expert‐level experience with CrowdStrike Falcon (Prevent, Insight, Discover). Strong expertise in Splunk, including ...

Penetration Tester

Location
Greater London, England, United Kingdom
that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Role As a Penetration Tester, you will lead and conduct penetration tests and vulnerability assessments across a wide range of internal systems and security controls. Your work will … directly strengthen our overall security posture through continuous testing, actionable insights and collaboration on remediation strategies. Responsibilities Perform in-depth penetration testing across a variety of technologies, including Kubernetes, Jenkins and Windows Domain Services. Deliver practical, impactful remediation advice to Control Owners based on identified vulnerabilities. Support ...

Senior Application Security Engineer

Hiring Organisation
TripleLift
Location
London, United Kingdom
Salary
£ 70 K
organization.ResponsibilitiesPlay a critical role in building and maintaining a global security compliance program based on NIST CSF.Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.Automate security testing … risks early in the SDLC.Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.Monitor and respond to application-layer security threats ...

Senior Application Security Engineer

Hiring Organisation
TripleLift
Location
London, UK
Employment Type
Full-time
organization. ResponsibilitiesPlay a critical role in building and maintaining a global security compliance program based on NIST CSF.Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools. Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities. … Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves. Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories. Participate in threat modeling and design/architecture spec reviews ...

Penetration Testing Lead: Strategy, Mentorship & Automation

Location
Manchester, England, United Kingdom
Lloyds Banking Group is seeking an experienced Penetration Testing Lead to shape the group’s testing capability and roadmap for both human-led and autonomous security testing. You will lead a team of testers, collaborate with engineering, security and business stakeholders, and drive improvements across the testing lifecycle. The role requires deep technical expertise in application, API, cloud, infrastructure and network testing, and a proven ability to communicate risks and remediation to #J-18808-Ljbffr ...

IT/OT Penetration Tester

Hiring Organisation
PA Consulting
Location
London, UK
Employment Type
Full-time
security assessments within agreed deadlinesProduce written and verbal reports for clients to an excellent standard. Develop and share knowledge with the rest of the penetration testing teamWork with teams across PA Consulting, providing technical knowledge and expertise where requiredBe self-motivated and client oriented, aiming to exceed expectations … other industry recognised certifications such as the OSCP or CREST/CyberScheme qualificationsHave developed their SME knowledge in one or more fields of penetration testing, such as mobile application testing, Cloud, Operational Technology, or a specific industry/environment such as telecoms, defence, or maritimeDesire to help ...

IT/OT Penetration Tester

Hiring Organisation
PA Consulting
Location
Pimlico, Hertfordshire, UK
Employment Type
Full-time
security assessments within agreed deadlinesProduce written and verbal reports for clients to an excellent standard. Develop and share knowledge with the rest of the penetration testing teamWork with teams across PA Consulting, providing technical knowledge and expertise where requiredBe self-motivated and client oriented, aiming to exceed expectations … other industry recognised certifications such as the OSCP or CREST/CyberScheme qualificationsHave developed their SME knowledge in one or more fields of penetration testing, such as mobile application testing, Cloud, Operational Technology, or a specific industry/environment such as telecoms, defence, or maritimeDesire to help ...

Senior Cybersecurity Tester / Researcher

Hiring Organisation
UK Telecoms lab
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent, Part Time
senior member of the team, youll also play an important role in supporting and mentoring others, helping to develop the next generation of security testing specialists. What Youll Be Doing Lead and deliver security assessments across complex hardware, software, and telecoms systems. Conduct hands-on penetration testing within a dedicated in-house lab environment, ensuring safe and controlled testing. Apply advanced testing techniques including both positive and negative approaches (e.g. fuzzing) to rigorously assess network functions and protocols. Identify, investigate, and clearly articulate vulnerabilities and security risks to both technical and non-technical audiences. Develop ...