delivery team, you'll contribute to the coordination and execution of security testing across the software development lifecycle. This will involve running vulnerability scans using tools such as Burp, coordinating with relevant teams, testing security related issues. Support the wider test team by sharing knowledge and guidance on security testing approaches and tooling. Attend meetings and provide stakeholders … CSTA or GIAC Penetration testing, OR currently working towards this OR have proven working experience. Working knowledge of at least 5 of the following security tools and technologies: BurpSuite (including Burp Scanner) - for web app vulnerability scanning and manual security testing. OWASP ZAP - for DAST and automated security regression testing. Postman or SOAP … for secure code handling and integration with security scanners. Static Application Security Testing (SAST) tools - e.g. SonarQube, Checkmarx, Semgrep. Dynamic Application Security Testing (DAST) tools - e.g. OWASP ZAP, BurpSuite Pro. Infrastructure-as-Code (IaC) scanning tools - e.g. tfsec, Checkov. Secrets detection tools - e.g. GitLeaks, truffleHog, detect-secrets. Threat modelling approaches - e.g. STRIDE, or creating risk More ❯
an organization's IT infrastructure, networks, systems, and applications to identify potential weaknesses and vulnerabilities. Performing vulnerability testing and penetration testing: Using various tools and techniques (like Nessus, BurpSuite, Metasploit), you'll simulate attacks to uncover exploitable flaws. Developing threat analysis schedules and staying updated on emerging threats: Keeping abreast of the latest attack vectors More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Global TechForce
an organization's IT infrastructure, networks, systems, and applications to identify potential weaknesses and vulnerabilities. Performing vulnerability testing and penetration testing: Using various tools and techniques (like Nessus, BurpSuite, Metasploit), you'll simulate attacks to uncover exploitable flaws. Developing threat analysis schedules and staying updated on emerging threats: Keeping abreast of the latest attack vectors More ❯
London, England, United Kingdom Hybrid / WFH Options
Global TechForce
an organization's IT infrastructure, networks, systems, and applications to identify potential weaknesses and vulnerabilities. Performing vulnerability testing and penetration testing: Using various tools and techniques (like Nessus, BurpSuite, Metasploit), you'll simulate attacks to uncover exploitable flaws. Developing threat analysis schedules and staying updated on emerging threats: Keeping abreast of the latest attack vectors More ❯
Gateway Menlo CASB Cisco Secure Access Cisco Umbrella Cisco ASA KnowBe4 Digicert Certificates and Microsoft Certificate Services Ivanti or Automox patching AppCheck or Tenable WAS Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Desired Education: CISM, MS SC100, 200 and 900, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Marlin Selection Recruitment
Gateway Menlo CASB Cisco Secure Access Cisco Umbrella Cisco ASA KnowBe4 Digicert Certificates and Microsoft Certificate Services Ivanti or Automox patching AppCheck or Tenable WAS Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Desired Education: CISM, MS SC100, 200 and 900, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and More ❯
Remote working (anywhere in the UK) Hybrid / WFH Options
Government Digital & Data
Lead Test Engineer focusing on security, you will: Take ownership of security testing within the software development lifecycle. This will involve running vulnerability scans using tools such as Burp, coordinating with relevant teams, and testing security-related issues. As a manager, you will provide advice, coaching and mentoring to testers on non-functional testing subjects such as security … working experience. Experience of non-functional testing practices with a strong focus on Security Testing. Working knowledge of at least 5 of the following security tools and technologies: BurpSuite (including Burp Scanner) - for web application vulnerability scanning and manual security testing. OWASP ZAP - for DAST and automated security regression testing. Postman or SOAP … for secure code handling and integration with secrets scanners. Static Application Security Testing (SAST) tools - e.g. SonarQube, Checkmarx, Semgrep. Dynamic Application Security Testing (DAST) tools - e.g. OWASP ZAP, BurpSuite Pro. Infrastructure-as-Code (IaC) scanning tools - e.g. tfsec, Checkov. Secrets detection tools - e.g. GitLeaks, truffleHog, detect-secrets. Threat modelling methodologies - e.g. STRIDE, PASTA, or creating More ❯
Lead Test Engineer focusing on security, you will: Take ownership of security testing within the software development lifecycle. This will involve running vulnerability scans using tools such as Burp, coordinating with relevant teams, and testing security-related issues. As a manager, you will provide advice, coaching and mentoring to testers on non-functional testing subjects such as security … working experience. Experience of non-functional testing practices with a strong focus on Security Testing. Working knowledge of at least 5 of the following security tools and technologies: BurpSuite (including Burp Scanner) - for web application vulnerability scanning and manual security testing. OWASP ZAP - for DAST and automated security regression testing. Postman or SOAP … for secure code handling and integration with secrets scanners. Static Application Security Testing (SAST) tools - e.g. SonarQube, Checkmarx, Semgrep. Dynamic Application Security Testing (DAST) tools - e.g. OWASP ZAP, BurpSuite Pro. Infrastructure-as-Code (IaC) scanning tools - e.g. tfsec, Checkov. Secrets detection tools - e.g. GitLeaks, truffleHog, detect-secrets. Threat modelling methodologies - e.g. STRIDE, PASTA, or creating More ❯
Testing Focus on ensuring different modules/components interact correctly. Test APIs, databases, and service flows. Security Testing & Penetration Testing (Ethical Hacking) Simulate attacks to find vulnerabilities. Tools: BurpSuite , OWASP ZAP , Metasploit . CEH , OSCP , CISSP certifications an advantage Vulnerability Testing Scan systems for known vulnerabilities. Collaborate with SecOps and DevSecOps teams. Security QA/ More ❯
Reading, England, United Kingdom Hybrid / WFH Options
THAMES WATER UTILITIES LIMITED
hours, Monday to Friday. What you should bring to the role Strong knowledge of manual penetration testing techniques and confident with operating systems and tools such as Tenable, BurpSuite, Kalli Linux. Exposure to remediating vulnerabilities and patch management in a complex business environment. Experience in remediating cyber risks in the ever-changing digital estate. More ❯
London, England, United Kingdom Hybrid / WFH Options
S-RM
S-RM is a global intelligence and cyber security consultancy. Since 2005, we've helped some of the most sophisticated clients in the world solve some of their toughest challenges. We've been able to do this because of our More ❯
role Excellent knowledge of Vulnerability and Penetrating Testing concepts and best practices, including the requirements for WhiteHat/Ethical Hacking. Experience with automated tools such as Nessus, Appscan, BurpSuite, Nipper, and Trustwave. Expert understanding of the difference between a vulnerability assessment and a penetration test in the context of assessment scope, objectives, and deliverables. Working More ❯
London, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
a penetration testing role. Deep knowledge of Vulnerability and Penetration Testing concepts and best practices, including WhiteHat/Ethical Hacking. Experience with automated tools such as Nessus, Appscan, BurpSuite, Nipper, and Trustwave. Understanding of the differences between vulnerability assessments and penetration tests regarding scope, objectives, and deliverables. Working knowledge of information security frameworks like ISO27001 More ❯
Hounslow, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
pen test role. Excellent knowledge of Vulnerability and Penetration Testing concepts and best practices, including WhiteHat/Ethical Hacking requirements. Experience with automated tools such as Nessus, Appscan, BurpSuite, Nipper, and Trustwave. Understanding of the difference between vulnerability assessment and penetration testing regarding scope, objectives, and deliverables. Working knowledge of information security frameworks such as More ❯
or above Eligible to attain SC (Security Check) clearance Demonstrated track record of effective customer engagement on previous CHECK engagements Hands-on expertise with common testing tools (e.g. BurpSuite, Nmap, Metasploit, Cobalt Strike) Strong written and verbal communication skills What We Offer Flexible engagement options: Permanent or Contract Competitive day rate or salary package Hybrid More ❯
CCT, OSCP, OSWE, OSCE, or equivalent level. • Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. • Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. • Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. • Independence: Ability to work solo or as part of a team More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Nomios
CCT, OSCP, OSWE, OSCE, or equivalent level. • Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. • Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. • Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. • Independence: Ability to work solo or as part of a team More ❯
London, England, United Kingdom Hybrid / WFH Options
Nomios Netherlands
CCT, OSCP, OSWE, OSCE, or equivalent level. Experience: At least two years in penetration testing, covering network, web, and internal tests and customer engagements. Tools: Proficiency with tools like Burpsuite Pro, Nessus, and other industry standards. Communication: Strong verbal and written skills for stakeholder management, collaboration and report writing. Independence: Ability to work solo or as part of a team More ❯
London, England, United Kingdom Hybrid / WFH Options
Oliver Bernard
internal security processes and documentation in the process. Required: Strong experience as an App Sec Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as BurpSuite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely More ❯
London, England, United Kingdom Hybrid / WFH Options
Oliver Bernard
internal security processes and documentation in the process. Required: Strong experience as an App Sec Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as BurpSuite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely More ❯
facilitating penetration testing, security risk assessments, driving the remediation of cyber vulnerabilities and remediating or mitigating cyber risks. Experience of security testing services e.g., penetration testing, ZAP testing, BurpSuite, Attack & Breach simulation, or similar. Knowledge of emerging threats e.g. Quantum, AI and Digital Ledger Financial Services Regulation and Payments Scheme compliance experience. Any creative experience More ❯
security processes and documentation in the process. Required: Strong experience as an Application Security (AppSec) Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as BurpSuite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Oliver Bernard
security processes and documentation in the process. Required: Strong experience as an Application Security (AppSec) Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as BurpSuite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Oliver Bernard
internal security processes and documentation in the process. Required: Strong experience as an App Sec Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as BurpSuite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Oliver Bernard
internal security processes and documentation in the process. Required: Strong experience as an App Sec Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as BurpSuite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely More ❯