Nessus Palo Alto Firewalls, InTune, Entra ID, Active Directory Desirable: Imperva WAF, Menlo Security, Cisco Secure Access/Umbrella, KnowBe4, AppCheck Ivanti or Automox patching Kali Linux, Metasploit, NMAP, BurpSuite Candidate Profile Professional certifications such as CISM, MS SC100/200/900, OSCP are advantageous Background in financial services, SOC environments, or penetration testing preferred Strong interpersonal and communication More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Marlin Selection Recruitment
Gateway Menlo CASB Cisco Secure Access Cisco Umbrella Cisco ASA KnowBe4 Digicert Certificates and Microsoft Certificate Services Ivanti or Automox patching AppCheck or Tenable WAS Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Desired Education: CISM, MS SC100, 200 and 900, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and More ❯
Gateway Menlo CASB Cisco Secure Access Cisco Umbrella Cisco ASA KnowBe4 Digicert Certificates and Microsoft Certificate Services Ivanti or Automox patching AppCheck or Tenable WAS Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Desired Education: CISM, MS SC100, 200 and 900, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and More ❯
Remote working (anywhere in the UK) Hybrid / WFH Options
Government Digital & Data
Lead Test Engineer focusing on security, you will: Take ownership of security testing within the software development lifecycle. This will involve running vulnerability scans using tools such as Burp, coordinating with relevant teams, and testing security-related issues. As a manager, you will provide advice, coaching and mentoring to testers on non-functional testing subjects such as security … working experience. Experience of non-functional testing practices with a strong focus on Security Testing. Working knowledge of at least 5 of the following security tools and technologies: BurpSuite (including Burp Scanner) - for web application vulnerability scanning and manual security testing. OWASP ZAP - for DAST and automated security regression testing. Postman or SOAP … for secure code handling and integration with secrets scanners. Static Application Security Testing (SAST) tools - e.g. SonarQube, Checkmarx, Semgrep. Dynamic Application Security Testing (DAST) tools - e.g. OWASP ZAP, BurpSuite Pro. Infrastructure-as-Code (IaC) scanning tools - e.g. tfsec, Checkov. Secrets detection tools - e.g. GitLeaks, truffleHog, detect-secrets. Threat modelling methodologies - e.g. STRIDE, PASTA, or creating More ❯
Lead Test Engineer focusing on security, you will: Take ownership of security testing within the software development lifecycle. This will involve running vulnerability scans using tools such as Burp, coordinating with relevant teams, and testing security-related issues. As a manager, you will provide advice, coaching and mentoring to testers on non-functional testing subjects such as security … working experience. Experience of non-functional testing practices with a strong focus on Security Testing. Working knowledge of at least 5 of the following security tools and technologies: BurpSuite (including Burp Scanner) - for web application vulnerability scanning and manual security testing. OWASP ZAP - for DAST and automated security regression testing. Postman or SOAP … for secure code handling and integration with secrets scanners. Static Application Security Testing (SAST) tools - e.g. SonarQube, Checkmarx, Semgrep. Dynamic Application Security Testing (DAST) tools - e.g. OWASP ZAP, BurpSuite Pro. Infrastructure-as-Code (IaC) scanning tools - e.g. tfsec, Checkov. Secrets detection tools - e.g. GitLeaks, truffleHog, detect-secrets. Threat modelling methodologies - e.g. STRIDE, PASTA, or creating More ❯
remediation support and vulnerability management expertise. Hands-on experience with threat modelling and secure code reviews. Experience with Mobile Application Security and API Security. Familiarity with security tools (BurpSuite, Fortify, Checkmarx, Veracode, ZAP, etc.). Experience with cloud security (AWS, Azure, GCP) and container security (Docker, Kubernetes). Ability to conduct maturity assessments and gap More ❯
Testing Focus on ensuring different modules/components interact correctly. Test APIs, databases, and service flows. Security Testing & Penetration Testing (Ethical Hacking) Simulate attacks to find vulnerabilities. Tools: BurpSuite , OWASP ZAP , Metasploit . CEH , OSCP , CISSP certifications an advantage Vulnerability Testing Scan systems for known vulnerabilities. Collaborate with SecOps and DevSecOps teams. Security QA/ More ❯
understanding of the external threat environment and attacker tactics, techniques, and procedures Your skills and experiences: Demonstrable experience in penetration testing Proficient in penetration testing tools such as BurpSuite, Nmap, Metasploit etc CREST Registered Penetration Tester (CRT) The ability to clearly communication both verbally and written Practical Penetration Certifications such as PNPT/eCPPT Offensive More ❯
London, England, United Kingdom Hybrid / WFH Options
RSM
offensive security and penetration testing Demonstrable experience in infrastructure and web application testing, experience in API testing is desirable. Demonstrable experience using common pen testing tools including Kali Linux, Burpsuite, Nessus and other industry standard tools. Hold or working towards an industry recognised certification including CompTIA PenTest+; CHECK, CREST; Offensive Security Certified Professional (OSCP) etc. Relevant experience within a cyber … weekly. 25 Days Holiday. Lifestyle, Health, and Wellbeing including financial wellbeing benefits such as financial tools, electric car scheme and access to a virtual GP. Access to a suite of 300+ courses on demand developed by our inhouse Talent Development team. #LI-AK1 Diversity and Inclusion at RSM At RSM, we want to create a strong sense of More ❯
with database testing and SQL query language. Experience testing AWS services like Lambda, API Gateway, DynamoDB, and S3. Understanding of security testing concepts and tools (e.g., OWASP ZAP, BurpSuite). Knowledge of usability testing and user experience (UX) principles. Start-up experience About You Effective collaboration skills, able to work with cross-functional teams and More ❯
with database testing and SQL query language. Experience testing AWS services like Lambda, API Gateway, DynamoDB, and S3. Understanding of security testing concepts and tools (e.g., OWASP ZAP, BurpSuite). Knowledge of usability testing and user experience (UX) principles. Start-up experience About You Effective collaboration skills, able to work with cross-functional teams and More ❯
Reading, England, United Kingdom Hybrid / WFH Options
THAMES WATER UTILITIES LIMITED
hours, Monday to Friday. What you should bring to the role Strong knowledge of manual penetration testing techniques and confident with operating systems and tools such as Tenable, BurpSuite, Kalli Linux. Exposure to remediating vulnerabilities and patch management in a complex business environment. Experience in remediating cyber risks in the ever-changing digital estate. More ❯
London, England, United Kingdom Hybrid / WFH Options
S-RM
S-RM is a global intelligence and cyber security consultancy. Since 2005, we've helped some of the most sophisticated clients in the world solve some of their toughest challenges. We've been able to do this because of our More ❯
as Bitsight, Security Scorecard or Panorays. Experience using attack surface management (ASM) and attack surface discovery (ASD) solutions. Experience using web application testing tools and commercial scanners (e.g; BurpSuite, Edgescan, InsightAppsec). Experience using Application Programming Interfaces. Understanding of virtualization and public cloud tech stacks. Ability to learn and implement technologies quickly. A bachelor's More ❯
role Excellent knowledge of Vulnerability and Penetrating Testing concepts and best practices, including the requirements for WhiteHat/Ethical Hacking. Experience with automated tools such as Nessus, Appscan, BurpSuite, Nipper, and Trustwave. Expert understanding of the difference between a vulnerability assessment and a penetration test in the context of assessment scope, objectives, and deliverables. Working More ❯
London, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
a penetration testing role. Deep knowledge of Vulnerability and Penetration Testing concepts and best practices, including WhiteHat/Ethical Hacking. Experience with automated tools such as Nessus, Appscan, BurpSuite, Nipper, and Trustwave. Understanding of the differences between vulnerability assessments and penetration tests regarding scope, objectives, and deliverables. Working knowledge of information security frameworks like ISO27001 More ❯
Hounslow, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
pen test role. Excellent knowledge of Vulnerability and Penetration Testing concepts and best practices, including WhiteHat/Ethical Hacking requirements. Experience with automated tools such as Nessus, Appscan, BurpSuite, Nipper, and Trustwave. Understanding of the difference between vulnerability assessment and penetration testing regarding scope, objectives, and deliverables. Working knowledge of information security frameworks such as More ❯
or above Eligible to attain SC (Security Check) clearance Demonstrated track record of effective customer engagement on previous CHECK engagements Hands-on expertise with common testing tools (e.g. BurpSuite, Nmap, Metasploit, Cobalt Strike) Strong written and verbal communication skills What We Offer Flexible engagement options: Permanent or Contract Competitive day rate or salary package Hybrid More ❯
in an IT or CyberSecurity related field Passion for penetratioin testing, shown through either work experience, extra curricular activities or personal projects. Strong Technical understanding of toolings such as Burpsuite or Nessus Strong understanding of OWASP top 10 Sole british citizen This position is a fantastic chance for someone who wants to progress their career as a penetration tester, opportunities More ❯
project teams Collaborate with the wider Security Operations teams to enable better utilisation of results. Technical Requirements: Advanced with offensive tools such as: Metaspoit, Kali Linux, Cobalt Strike, Mimikatz, Burpsuite or similar tools Good knowledge of creating scripts in preferred scripting language Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP More ❯
project teams Collaborate with the wider Security Operations teams to enable better utilisation of results. Technical Requirements: Advanced with offensive tools such as: Metaspoit, Kali Linux, Cobalt Strike, Mimikatz, Burpsuite or similar tools Good knowledge of creating scripts in preferred scripting language Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP More ❯
CCT, OSCP, OSWE, OSCE, or equivalent level. • Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. • Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. • Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. • Independence: Ability to work solo or as part of a team More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Nomios
CCT, OSCP, OSWE, OSCE, or equivalent level. • Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. • Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. • Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. • Independence: Ability to work solo or as part of a team More ❯
London, England, United Kingdom Hybrid / WFH Options
Nomios Netherlands
CCT, OSCP, OSWE, OSCE, or equivalent level. Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. Independence: Ability to work solo or as part of a team More ❯
coding best practices. Familiarity with threat modeling methodologies such as STRIDE and architectural risk analysis. Hands-on experience with tools like SAST/DAST/IAST, Snyk, SonarQube, BurpSuite, Veracode, or similar. Strong understanding of cloud platforms and modern development architectures. Relevant certifications such as CSSLP, OSWE, GWAPT, CISSP, or equivalent are advantageous. Additional notes More ❯