part of a truly team driven environment. As a First Responder, you must display excellent outside-the-box thinking and communication skills. DESIRABLE EXPERIENCE. Vulnerability Assessment experience. Knowledge of Penetrationtesting tools and techniques. Network and firewall alert management. Active Directory and group policy management experience. Experience in deploying, managing, and supporting of endpoint security platforms Information security … in line with business requirements. PowerShell scripting. Experience with server infrastructure deployment, configuration and support. Ability to produce high-quality technical reports. Experience with Cyber Essentials and Essentials Plus. Penetrationtesting experience. Security related certifications (BTL1, BTL2, SC200, CySA+, Sec+, etc). Shift Allowance: additional 5k salary uplift for being on shift Performance-related, discretionary end-of-year More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Stripe Olt
part of a truly team driven environment. As a First Responder, you must display excellent outside-the-box thinking and communication skills. DESIRABLE EXPERIENCE. Vulnerability Assessment experience. Knowledge of Penetrationtesting tools and techniques. Network and firewall alert management. Active Directory and group policy management experience. Experience in deploying, managing, and supporting of endpoint security platforms Information security … in line with business requirements. PowerShell scripting. Experience with server infrastructure deployment, configuration and support. Ability to produce high-quality technical reports. Experience with Cyber Essentials and Essentials Plus. Penetrationtesting experience. Security related certifications (BTL1, BTL2, SC200, CySA+, Sec+, etc). Shift Allowance: additional 5k salary uplift for being on shift Performance-related, discretionary end-of-year More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Stripe Olt
part of a truly team driven environment. As a First Responder, you must display excellent outside-the-box thinking and communication skills. DESIRABLE EXPERIENCE. Vulnerability Assessment experience. Knowledge of Penetrationtesting tools and techniques. Network and firewall alert management. Active Directory and group policy management experience. Experience in deploying, managing, and supporting of endpoint security platforms Information security … in line with business requirements. PowerShell scripting. Experience with server infrastructure deployment, configuration and support. Ability to produce high-quality technical reports. Experience with Cyber Essentials and Essentials Plus. Penetrationtesting experience. Security related certifications (BTL1, BTL2, SC200, CySA+, Sec+, etc). Shift Allowance: additional 5k salary uplift for being on shift Performance-related, discretionary end-of-year More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Marlin Selection
Security Engineer, you will implement and maintain robust security systems and protocols across the our IT infrastructure. You will conduct risk assessments and vulnerability scans, mitigate vulnerabilities identified in penetrationtesting, and implement preventative measures to protect against cyber threats. You will monitor the security infrastructure and detect and respond to potential threats. You will help mentor and … Manage MDM\MAM and Conditional Access Manage security certificates and keys. Manage IDS and IPS. Manage PAM systems Deliver Cyber Security Awareness Training Remediate vulnerabilities and weaknesses identified during penetration testing. Ad-hoc IT security projects Experience Essential The successful candidate will have a good working knowledge and experience in managing the majority of the following technology stack CrowdStrike … Microsoft Certificate Services Ivanti or Automox patching AppCheck or Tenable WAS Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Desired Education: CISM, MS SC100, 200 and 900, OSCP or other penetrationtesting qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and verbal communication skills The ability to handle multiple priorities, tasks and projects More ❯
Conditional Access systems Maintain security certificates, encryption keys, and IDS/IPS systems Deliver cybersecurity awareness training and lead ad-hoc security projects Support and resolve issues identified during penetrationtesting Ideal Experience We're looking for someone with strong hands-on experience in most of the following technologies: Essential: CrowdStrike EDR Mimecast Duo, Okta Rapid7 IVM, Tenable … patching Kali Linux, Metasploit, NMAP, BurpSuite Candidate Profile Professional certifications such as CISM, MS SC100/200/900, OSCP are advantageous Background in financial services, SOC environments, or penetrationtesting preferred Strong interpersonal and communication skills, with the ability to engage across teams and deliver training effectively Able to manage multiple priorities and collaborate cross-functionally What More ❯
Conditional Access systems Maintain security certificates, encryption keys, and IDS/IPS systems Deliver cybersecurity awareness training and lead ad-hoc security projects Support and resolve issues identified during penetrationtesting Ideal Experience We're looking for someone with strong hands-on experience in most of the following technologies: Essential: CrowdStrike EDR Mimecast Duo, Okta Rapid7 IVM, Tenable … patching Kali Linux, Metasploit, NMAP, BurpSuite Candidate Profile Professional certifications such as CISM, MS SC100/200/900, OSCP are advantageous Background in financial services, SOC environments, or penetrationtesting preferred Strong interpersonal and communication skills, with the ability to engage across teams and deliver training effectively Able to manage multiple priorities and collaborate cross-functionally What More ❯
troubleshoot issues with A/V systems in meeting rooms. Assist in the development of IT policies and procedures Contribute to the implementation and monitoring of security measures and penetrationtesting Perform other duties as assigned by the IT Manager or Director of Digital Transformation Nature and Scope At the Energy Institute, technology isn't just a tool … abilities and the capacity to diagnose and resolve complex technical issues efficiently. Excellent customer service skills, with a user-focused approach. Solid cybersecurity awareness and a foundational understanding of penetrationtesting methodologies or security auditing principles. Demonstrable experience in incident response, particularly in identifying, containing, and escalating cyber incidents. Experience in Microsoft Windows systems administration, particularly Windows Server More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Energy Institute
troubleshoot issues with A/V systems in meeting rooms. Assist in the development of IT policies and procedures Contribute to the implementation and monitoring of security measures and penetrationtesting Perform other duties as assigned by the IT Manager or Director of Digital Transformation Nature and Scope At the Energy Institute, technology isn't just a tool … abilities and the capacity to diagnose and resolve complex technical issues efficiently. Excellent customer service skills, with a user-focused approach. Solid cybersecurity awareness and a foundational understanding of penetrationtesting methodologies or security auditing principles. Demonstrable experience in incident response, particularly in identifying, containing, and escalating cyber incidents. Experience in Microsoft Windows systems administration, particularly Windows Server More ❯
cyber security career in a dynamic and supportive setting? Apply now to make an impact across diverse sectors. Key Responsibilities: Lead or support the delivery of vulnerability assessments and penetrationtesting projects Provide technical security consultancy and basic to intermediate-level training to clients across the UK and internationally Occasionally deputise for the Head of Cyber Operations Work … directly with clients to define and deliver tailored security solutions Contribute to business development through proposal writing and client engagement Skills/Must have: Strong understanding of penetrationtesting, vulnerability assessments, EDR, and endpoint protection Experience working in or with government or defence clients Previous consultancy experience with client-facing responsibilities SC clearance (or willingness to undergo clearance More ❯
Simulate the Threats. Strengthen the Defenses. Are you passionate about uncovering vulnerabilities before they become headlines? Join a global veterinary business where your expertise in cyber security testing will help protect the digital infrastructure that supports animal health worldwide. As our Cyber Security Testing Lead, you'll lead proactive testing efforts to expose weaknesses, validate controls, and … leadership role within our Cyber Defence Red Team, focused on simulating real-world attack techniques to identify and close security gaps before they're exploited. Key responsibilities include: Security Testing Strategy: Design and execute end-to-end testing-from basic port scans to advanced adversarial simulations. Vulnerability Identification: Perform External Attack Surface Management (EASM) and threat hunting to … the Blue Team and Compliance, driving remediation efforts. Collaboration & Mentorship: Work closely with IT and development teams to resolve issues and mentor internal testers. Third-Party Oversight: Manage external testing providers and ensure alignment with internal standards. Continuous Improvement: Help close the gap between theoretical controls and real-world threats. What You Bring Significant hands-on experience in cyber More ❯
SECFORCE is an independent offensive cyber security consultancy specialised in PenetrationTesting and Adversary Simulation. Founded in 2008 out of love and passion for the hacking craft, we have grown into a well-respected company based in London, Malta and Greece, with teams across Europe working for top-tier organisations all over the world. What started as a … to align on partner strategy Requirements 3+ years of experience in channel sales partner management Good understanding of the cyber threat landscape Understanding of the cyber services markets e.g. PenetrationTesting, Red Team/Purple Team, Adversary Simulation) Excellent communication, negotiation, and interpersonal skills Self-starter with a results-oriented mindset and the ability to work independently Experience More ❯
retain, and develop talent and expertise, including application security specialists. Set and maintain the team's culture and tone. Business Continuity and Disaster Recovery : Contribute to the development and testing of business continuity and disaster recovery plans from an information security perspective, including considerations for application security. Security Monitoring and Incident Response : Establish and maintain processes for continuous security … and controls, including but not limited to, firewalls, intrusion detection/prevention systems, security information and event management (SIEM), data loss prevention (DLP), vulnerability management tools, and application security testing tools. Secure Software Development Lifecycle (SSDLC) : Integrate security best practices into the software development lifecycle. Work closely with development teams to ensure secure coding practices, conduct comprehensive security testing (e.g., penetrationtesting, vulnerability scanning, application security reviews), and promote a security-aware development culture with a strong application security focus. Third-Party Risk Management : Develop and implement a program for assessing and managing the information security risks, including application security risks, associated with third-party vendors and service providers. Security Awareness and Training : Develop and deliver More ❯
in everything we deliver. As a Senior Security Engineer focused on Application & Product Security , you will own our AppSec strategy - driving threat modeling, secure architecture design, and offensive security testing . You will lead manual and automated penetrationtesting, manage AppSec tooling (SAST, DAST, SCA), and build developer enablement programs. You'll also be responsible for vulnerability … Responsibilities: Threat Modeling & Architecture Reviews Mature and scale a modern threat modeling program across products and services. Enable secure by design architectures in collaboration with Engineering teams. Offensive Security Testing Conduct penetration tests (white-box and black-box) for web applications and APIs. Perform dynamic (DAST), static (SAST), and software composition (SCA) analysis. Simulate adversary attack scenarios to … incident analysis. Compliance Enablement Support audits, technical evidence collection, and control design for SOC 2, ISO 27001, and privacy-by-design requirements. Customer Trust Contribute to customer security assessments, penetration test reports, and security documentation. Requirements: 7+ years of experience in a security engineer or related role, including 4+ years specializing in web application, API, and product security. Deep More ❯
security architecture and assurance to OFFICIAL and above classifications. Provide specialist advice and knowledge of Public Cloud (Azure, AWS, GCP) cloud-based security architectures. Define and lead external security testing (e.g ITHC) of solutions on the public cloud (Azure, AWS, GCP), cloud native platforms (Docker, Kubernetes, etc.), and Software as a Service (SaaS) solutions. Formulate HMG Information Assurance Risk … across IaaS, PaaS, SaaS and Serverless architectures Implementing Information Security and Privacy Standards and Frameworks (e.g. ISO 27k, NIST800-53, CIS, GDPR) Leading security working groups and external security testing (ITHC, PenetrationTesting, etc) of cloud solutions at high HMG classification levels (OFFICIAL required, SECRET desirable) or equivalent in other industries Designing & delivering secure systems & tooling: Working … and principles Working within environments utilising DevOps, DevSecOps, SRE, CI/CD, Infrastructure & Security as Code (Docker, Git, Terraform) Managing technical assessments of security related technologies, vulnerability assessments and penetration tools and techniques Enabling & informing risk-based decisions: Working with higher impact or more complex risks, advising on the impact and whether this is within risk tolerance Understanding and More ❯
is. SIEM, IDS/IPS, ASM, WAF) to safeguard against security breaches, cyber threats and unauthorized access Report on and assist with all security events and incidents. Oversee Security testing, including penetrationtesting and vulnerability scanning Ensure products compliance with security standards and regulations Ensure NAVBLUE Security strategy deployment within technical operations Ensure effective synchronization and alignment … Excellent management, analytical and problem-resolution skills Working knowledge of the SDLC and AWS network architecture Knowledge of the SAFe Agile method would be an asset Understanding of security testing in the software pipeline (SAST, DAST, SCA, RASP) Knowledge of STRIDE, DICE and other threat and risk frameworks Knowledge of AWS tools Proven experience managing multiple projects simultaneously Practical More ❯
Penetration Tester - Manchester Hybrid - £50,000 - £60,000 (DOE) FryerMiles are delighted to be partnered with a leading cyber security consultancy that work with a diverse range of clients on exciting projects and engagements who are looking to hire an experienced penetration tester. This is hybrid position that requires office presence twice a week in the clients Manchester … a British Citizen and be eligible for SC Clearance, so unfortunately sponsorship cannot be offered for this position. Experience & Requirements: 2+ years of hands on experience working as a penetration tester in a consultative capacity Demonstratable experience in delivering Web Application and Infrastructure/cloud tests Relevant penetrationtesting certifications (OSCP, CRT, CCT) Experience of relevant toolings … such as Nessus, Qualys, Kali etc.. Experience mentoring or assisting junior/graduate testers Eligibility to be SC Cleared This client do pen testing differently & are not your typical offensive security consultancy & there are many perks and bonuses that are on offer. If you think this position could be a good fit for you, then please apply directly or More ❯
Manchester, North West, United Kingdom Hybrid / WFH Options
FryerMiles Recruitment
Penetration Tester - Manchester Hybrid - £50,000 - £60,000 (DOE) FryerMiles are delighted to be partnered with a leading cyber security consultancy that work with a diverse range of clients on exciting projects and engagements who are looking to hire an experienced penetration tester. This is hybrid position that requires office presence twice a week in the clients Manchester … a British Citizen and be eligible for SC Clearance, so unfortunately sponsorship cannot be offered for this position. Experience & Requirements: 2+ years of hands on experience working as a penetration tester in a consultative capacity Demonstratable experience in delivering Web Application and Infrastructure/cloud tests Relevant penetrationtesting certifications (OSCP, CRT, CCT) Experience of relevant toolings … such as Nessus, Qualys, Kali etc.. Experience mentoring or assisting junior/graduate testers Eligibility to be SC Cleared This client do pen testing differently & are not your typical offensive security consultancy & there are many perks and bonuses that are on offer. If you think this position could be a good fit for you, then please apply directly or More ❯
levels Security Posture Management: Develop and maintain a comprehensive security posture management program to proactively identify and address vulnerabilities. Continuously assess the organization's security posture through vulnerability assessments, penetrationtesting, and threat modelling. Collaborate with cross-functional teams to implement security best practices and ensure compliance with industry standards and regulations. Cyber Exposure Risk Management: Identify, analyse More ❯
s ability to deliver on its vision and strategy. Main responsibilities: Proactively integrate security throughout the application development lifecycle, reacting to find and fix vulnerabilities. Conduct security assessments, support penetrationtesting, and address vulnerabilities. Transform technical requirements into an effective application development lifecycle within a DevSecOps toolchain. Ensure secure deployment strategies are scalable, repeatable, and highly available. Support … and solutions (Practitioner) Supporting and supporting security support methodologies (Expert) Process analysis and optimization (Practitioner) Risk-based decision making (Working) Modern development standards application (Practitioner) Software engineering: design, coding, testing (Practitioner) Prototyping and testing (Practitioner) Research and innovation in security (Working) Systems design and integration (Practitioner) Understanding security implications of transformation (Working) Experience: Integrating security practices into DevOps … including automated testing and vulnerability management. Experience with CI/CD, IaC, and security automation tools. Implementing Zero Trust models, identity verification, MFA, and adaptive access controls. Knowledge of standards and regulations like GDPR, ISO 27001, NIST, including conducting audits and risk assessments. Leading process optimization investigations. Essential: Analytical, problem-solving, and collaborative skills. Experience as a DevOps professional. More ❯
Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Frontier Resourcing
/53, JSP 440/604, Def Stan 05-series). Lead the creation and maintenance of security documentation (RMADS, Security Assurance Documents, Security Management Plans). Testing & Assurance Design and execute penetration tests and automated vulnerability scans; validate fixes. Oversee third-party security assessments as required. Continuous Improvement Drive security tooling and automation (CI/CD integration … management frameworks (ISO 27001/2/5/31000, NIST 800-series) and Defence Standards (JSPs, Def Stan 05-138/139). Hands-on experience with security testing tools and techniques (SAST, DAST, penetrationtesting). Eligible for UK SC clearance; right to work in the UK. Why Join? You'll Gain exposure to cutting More ❯
Assistant Vice President, Penetration Tester page is loaded Assistant Vice President, Penetration Tester Apply locations London time type Full time posted on Posted 2 Days Ago job requisition id -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. … irrespective of the entity which employs you. Develop and maintain governance structure of red team operations and train, and mentor other members of the Red Team. Develop and execute penetrationtesting plans, including network, web application, and social engineering assessments. Collaborate with SOC team and selected vendor to plan and execute annual purple team testing Identify security … risks and vulnerabilities through simulated attacks, and helping the organization understand the potential impact. Manage Red Team tools and the Security Testing & Validation Platform Implement and maintain governance of any assessments finding remediation progress and create regular reporting for tech and executives Collaborating with other technology teams (i.e. infra, app and etc) to develop and improve defensive strategies and More ❯
and quality Excellent problem-solving techniques and trouble analysis skills Experience in design and publishing Security Standards & Policies Experienced in running global Bug Bounty/VDP programs Experiencedin Pen Testing, from scope, schedule, findings, remediation and risk registration The candidate should have a good knowledge of: Vulnerability Management concepts, controls, and best practices for all Operating systems & asset types More ❯
Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
and compliance with MOD and HMG security standards (JSP, Def Stan 05-138/139). Proficiency in security threat modeling and risk assessments. Knowledge of secure development practices, penetrationtesting, and vulnerability assessments. Ability to communicate security risks and strategies to technical and non-technical stakeholders. Experience in incident response and remediation. Strong analytical and problem-solving More ❯
Bristol, Kendleshire, Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
and compliance with MOD and HMG security standards (JSP, Def Stan 05-138/139). Proficiency in security threat modeling and risk assessments. Knowledge of secure development practices, penetrationtesting, and vulnerability assessments. Ability to communicate security risks and strategies to technical and non-technical stakeholders. Experience in incident response and remediation. Strong analytical and problem-solving More ❯
to monitor, analyse, and respond to evolving cyber threats, lead forensic investigations, and support wider resilience initiatives. Key Responsibilities: Design, implement, and manage secure network architectures Perform vulnerability assessments , penetrationtesting , and remediation strategy delivery Lead and coordinate incident response , forensic analysis, and post-incident reporting Use and optimise security tooling (e.g. firewalls, IDS/IPS , endpoint protection More ❯