Job Title: Cyber Security Penetration Tester
Locations: UK wide (hybrid work- 1x a month in office)
Salary: Competitive salary and package (Depending on level of experience)
Please Note: Any offer of employment is subject to satisfactory BPSS and SC security clearance which requires 5 years continuous UK address history (typically including no periods of 30 consecutive days or more spent outside of the UK) at the point of application.
Role Overview
As a Penetration Tester, you will deliver hands-on security testing of client web applications, APIs and infrastructure. Working within a collaborative testing team, and supported by senior testers and CHECK Team Leaders on complex engagements, you will find and validate vulnerabilities, demonstrate their real-world impact and give clients clear, practical remediation advice. This role suits an early-career tester who wants to broaden their technical skills and progress through recognised industry certifications.
Key Responsibilities
- Perform manual and tool-assisted testing of web applications, APIs and internal and external infrastructure.
- Identify, validate and safely exploit vulnerabilities within agreed rules of engagement, including authentication, authorisation, injection, business logic and misconfiguration issues.
- Help identify attack paths, including privilege escalation, and explain their business impact.
- Follow recognised methodologies, including OWASP (WSTG, API Security Top 10), PTES and CHECK/CREST standards.
- Help prepare for engagements by confirming scope, access and prerequisites with the engagement lead.
- Write clear, accurate reports with reproducible evidence, risk ratings and prioritised remediation advice.
- Support client remediation and carry out retests to confirm fixes are effective.
- Escalate critical findings promptly to the engagement lead and help explain their impact to stakeholders.
- Share knowledge with the team through peer review, tooling improvements and technical write-ups.
Essential Skills And Experience
- Typically 1–2 years' commercial penetration testing experience across web applications, APIs and infrastructure.
- Good working knowledge of common web and API vulnerabilities, including the OWASP Top 10 and API Security Top 10.
- Practical experience with industry-standard tools such as Burp Suite, Nmap and Metasploit.
- Ability to validate findings, rule out false positives and capture reproducible evidence.
- Clear technical writing that explains risk and remediation in plain language.
Desirable Skills And Experience
- Awareness of cloud security and configuration review in AWS, Azure or GCP.
- Some mobile application testing experience (iOS and/or Android).
- Basic scripting (e.g. Python, Bash, PowerShell) to automate tasks or adapt tools.
- Understanding of cryptography and build/hardening standards.
- Sound understanding of networking, common protocols, and Windows and Linux security.
- Holds, or is working towards, a practitioner-level certification such as CREST CRT, Cyber Scheme CSTM, OSCP or PNPT.
Development and support
- Mentoring and technical guidance from experienced testers and CHECK Team Leaders.
- A funded certification pathway, for example from CRT or CSTM through to CCT or CSTL.
- A broad mix of engagements to build experience across testing types.
- Dedicated time for training, research and lab work.
- Opportunities to contribute to internal tooling, methodology and innovation projects.