Penetration Tester Work Across Internal Security, Compliance & Client Engagements A fast-growing security-focused business is looking for a Penetration Tester to join their expanding team. This is a hands-on, cross-functional role where you'll support internal security maturity, contribute to client-facing consultancy projects, and … SOC to simulate attack scenarios and improve detection Run internal vulnerability assessments and pen tests to support compliance and readiness for audits Deliver external penetrationtesting services — from scoping and testing to risk analysis and reporting What We're Looking For: Practical experience in penetrationtestingMore ❯
business and technical focused. You will have ideas of how to drive the business forward, and be skilled in the commercial aspects of security testing, above all you will know what clients are looking for when they buy security testing and how to deliver it. Management and delivery … of penetrationtesting services to clients to include the following: Scoping Financial and risk management Delivery of testing and the oversight of testers Review of deliverables (QA) Coaching and developing team members through sharing of experience and knowledge. Performance management of junior staff. Continuous development of self … the broader offerings to enable identification of business opportunities Required Skills and Experience: Passion for Hacking! Clear and demonstrable understanding of red-teaming/penetrationtesting, including NCSC and CREST accredited schemes such as xBEST, STAR/STAR-FS, CHECK. Proven experience of successfully managing and delivering testingMore ❯
Application Security Engineer/Penetration Tester – FinTech – AppSec, Burp Suite, Metasploit Oliver Bernard are currently seeking an Application Security Engineer, with strong PenetrationTesting experience, to join a FinTech client of ours on a contract basis. This hire is part of a security focused transformation where the … engineer will be responsible for identifying and mitigating security vulnerabilities, and risk, within their applications. You will have a focus on building security tools, penetrationtesting, and performing security assessments, whilst updating internal security processes and documentation in the process. To be considered, the following experience is required … 5+ years operating as an App Sec Engineer Extensive experience as a Penetration Tester Strong hands-on experience with tools such as Burp Suite and Metasploit Capable designing Security policies, procedures and best practices Able to investigate and respond to Security related incidents within applications, and work closely with More ❯
Security Engineer – IAM | DORA | Pen Testing | Payments – Banking London/Glasgow | £750/day (Inside IR35) | Financial Services We're seeking a seasoned Security Engineer with a proven track record in banking environments to join a high-impact team driving resilience and security across mission-critical systems. You’ll … bring deep expertise across Identity & Access Management (IAM) , penetrationtesting , and 3rd party risk , with strong familiarity with DORA compliance and payments/settlement systems . What You’ll Do: Lead and execute advanced penetrationtesting and vulnerability assessments Own IAM strategy and operations , ensuring airtight … in fast-paced, regulated environments with a laser focus on resilience What You’ll Bring: Hands-on banking experience – essential Expertise in IAM, pen testing, third-party risk , and regulatory frameworks (DORA) In-depth knowledge of financial systems, especially payments & settlement platforms Strong communicator, highly analytical, and security-obsessed More ❯
engage, and close new business opportunities within the SOC Service offering and assist with GRC (PCI DSS, ISO 27001, NIST, Cyber Maturity Assessments) and penetrationtesting services. With strong SDR and marketing support, you'll have the tools and backing to succeed in a high-growth cybersecurity environment. … Doing: Hunt, Develop, and Manage Accounts: Your primary focus will be selling cyber professional services covering a wide spectrum from SOC, GRC, MDR, and Penetrationtesting Managing a sales pipeline with deal sizes ranging from £25k - £100k Meet or exceed quarterly sales quota Working closely with SDRs to More ❯
Conducting comprehensive security assessments: This involves evaluating an organization's IT infrastructure, networks, systems, and applications to identify potential weaknesses and vulnerabilities. Performing vulnerability testing and penetrationtesting: Using various tools and techniques (like Nessus, Burp Suite, Metasploit), you'll simulate attacks to uncover exploitable flaws. Developing More ❯
security breaches, intrusions, and abnormal system behavior Investigate security incidents, perform root cause analysis, and provide incident response support Conduct regular vulnerability assessments and penetrationtesting; assist in remediation efforts Maintain and manage SIEM (Security Information and Event Management) tools and log analysis Develop and enforce security policies More ❯
to proactively mitigate risks Perform proactive threat hunting, research, and analysis, delivering actionable intelligence to IT and security teams Perform security assessments, audits, and penetrationtesting using industry-standard methodologies and tools. Deliver security awareness training and phishing simulations to internal stakeholders. Ensure compliance with company policies and More ❯
and supporting Entra (Azure AD), Azure IaaS/PaaS Management of backup/recovery solutions Experience with operating system hardening, vulnerability assessments, security audits, penetrationtesting, intrusion prevention systems and other security control systems for example PAM, SIEM etc. Experience with endpoint security, content filtering, vulnerability scanning and More ❯
solutions. With a proven track record and strong client relationships, we are trusted by our clients to meet their goals. The role: As a Penetration Tester on Risk Crew, you'll be part of an elite team of security experts who are dedicated to identifying and mitigating security vulnerabilities … wireless, and mobile applications. You will act as a trusted advisor, conducting comprehensive security assessments of our clients' most critical assets. Apart from security testing you will support the team to ensure on-time, on-budget delivery of their assigned tasks, quality of their deliverables and overall customer satisfaction. … This role will require mid-level expertise in multiple domains of security testing, and we expect you to be versatile yet methodical in your testing approach. The location: The duties of this position will be performed mainly at the Risk Crew office, in London SE1 with occasional travelling More ❯
Cyber Vulnerability Management Analyst Fixed Term Contract (Maternity Cover) 18 months Must have experience working on Tenable.IO, analysed vulnerabilities form penetrationtesting reports, work with vendors to remediate vulnerabilities, has patch management experience, has patched/worked on windows, Linux and Azure cloud systems, analyse and remediate SOC … term goals. The role of Cyber Vulnerability Management Analyst is to deal with all remediation work in relation to identified vulnerabilities inclusive of patch testing and implementation within SLA. The job holder will work very closely with all third-party vendors involved in the remediation process. The job holder More ❯
detect potential threats or breaches. Respond to security incidents, conduct root cause analysis, and implement corrective actions. Vulnerability Management: Perform regular security assessments, including penetrationtesting and vulnerability scanning. Collaborate with development teams to address vulnerabilities and enforce remediation timelines. Compliance and Governance: Ensure compliance with industry standards More ❯
5+ years of hands-on experience in InfoSec Strong grasp of security principles, best practices, and system hardening techniques. Solid experience with threat modeling, penetrationtesting, and automated security validation. Deep knowledge of cloud, network, and systems security. Scripting skills in Python or PowerShell (or both). Familiarity More ❯
with NIST, ISO 27001, ITIL Azure - 5 years experience Info Sec (Azure AD, Defender, Sentinel) Audits and report writing Assessments Vulnerability Management and Pen Testing Zero Trust Architecture Automation (eg powershell, python More ❯
Code principles Establish and maintain security controls and monitoring systems aligned with ISO27001 requirements Build and maintain CI/CD pipelines with integrated security testing and compliance checks Implement automated security scanning and vulnerability management processes Develop and maintain disaster recovery and backup solutions for critical systems Configure and … best practices and implementing Zero Trust architecture Experience with healthcare compliance requirements (ISO27001, ISO13485, HIPAA) and security controls Proven track record implementing automated security testing and vulnerability management Strong knowledge of monitoring and observability tools (Azure Monitor, Application Insights) Experience implementing secure networking and identity management solutions in Azure … teams Track record of building secure and compliant DevOps practices Desired Skills Experience with quality management systems in medical device software development Experience of penetrationtesting Background in implementing Agile methodologies Experience of startup environments More ❯
place to protect critical systems and data. Responsibilities Develop and implement Vulnerability Management Strategy. Lead Threat Intelligence and Threat Modelling. Oversee Vulnerability Assessments and Penetration Testing. Collaborate on Security Incident Response. Ensure Compliance with Security Standards. Stakeholder Communication and Reporting. Leadership and Team Accountability. Skills & Experience Mininum of … Defender. In-depth knowledge of security frameworks and compliance standards, such as ISO 27001, NIST, GDPR, and PCI-DSS. Experience in coordinating or conducting penetrationtesting, red teaming, and handling security incidents. Experience with managing security projects and teams. Interview Process Recruiter Call Hiring Manager Intro Final Interview More ❯
Sentinel ▪ Configure and maintain end user compute policies with Microsoft Intune ▪ Maintain and contribute to the security and compliance plan, including regular involvement in penetrationtesting, escrow deposits, backup verification and BCP testing ▪ Work across development and production environments, independently, with colleagues and with third-party suppliers More ❯
or risks. Collaborate with engineering teams to embed secure coding practices and tackle vulnerabilities. Manage security assessments, audit responses, and incident investigations. Run regular penetrationtesting, disaster recovery simulations, and security awareness training. Streamline access controls, onboarding/offboarding processes, and device compliance using SSO/SCIM and More ❯
identify vulnerabilities using CWE or OWASP •Knowledge of operating systems and their hardening techniques •Understanding of development concepts such as CICD, Pipelines, and SDLC •Penetrationtesting knowledge is also super useful •Familiarity with Cloud Development Kit (CDK) and GitOps •Experience operating in a DevOps/agile team environment More ❯
of legacy systems while maintaining operational continuity Leading the retirement of Active Directory, guiding the shift to modern, cloud-native identity infrastructure Remediation of penetrationtesting findings Transition to a zero-trust network architecture Network segmentation and decommissioning of MPLS infrastructure Optimization of Okta implementation—streamlining access, enforcing More ❯
Our client, are looking for a Digital Project Manager with proven experience managing website delivery through testing, launch, and post-go-live support to join their team on a contract basis. This role is ideal for someone who thrives at the intersection of strategy and execution—comfortable managing stakeholders … sleeves to get things done. What you'll be doing: Leading the delivery of complex website launches across global teams Managing end-to-end testing and go-live processes including Tech Assessments, Cutovers, and Hypercare Acting as the central point of coordination across technical, QA, SEO, and brand teams … Ensuring all pre-launch readiness activities are completed, documented, and approved Driving issue resolution across workstreams during development, testing, and hypercare Supporting SEO audits, penetrationtesting, and DNS cutovers Partnering with external vendors and internal teams to keep delivery on track Experienced required: Strong experience delivering websites More ❯
to implement security controls across cloud infrastructure (ideally AWS), including access control, encryption, and logging. Leading the incident response process and managing third-party penetrationtesting and vulnerability management activities. The ideal Information Security Lead will have experience with the following: 3-5 years of hands-on experience More ❯
or AWS Write clean, maintainable code following best practices and team standards Participate in code reviews and contribute to improving development processes Implement robust testing strategies and maintain high code quality Collaborate with Data Science and Delivery teams to understand and deliver business requirements Apply security-first development practices … with healthcare technology and regulatory requirements (ISO13485, ISO27001) Desired Skills: Experience in building mobile apps Experience working in a healthcare technology company Experience of penetrationtestingMore ❯
Purpose: The individual will be looking to deliver robust control testing, aligned with regulatory and internal standards, to ensure control design adequacy and effectiveness. The role supports RCSA processes and leads evidence-based evaluations. Key Responsibilities: Evaluate and test security controls against NIST 800-53 requirements Execute scheduled control … testing, document results, and analyse weaknesses Review and capture control evidence for audit and compliance purposes Collaborate with control owners and remediation teams to resolve findings Use Archer to record outcomes and align with risk control inventory Skills & Experience: Expertise in control design, encryption, and testing (incl. vulnerability … pen testing) Familiarity with Archer and RCSA frameworks Understanding of both technical and non-technical control types (HR, systems, assets) Strong audit mindset and regulator-facing assurance experience More ❯