Enable job alerts via email!

Penetration tester

LA International

City Of London

Hybrid

GBP 80,000 - 100,000

Full time

Today
Be an early applicant

Job summary

A technology consulting firm is seeking an experienced Pen tester to conduct internal penetration testing and support security initiatives. The role involves collaboration with development teams and compliance with security standards. Applicants should possess relevant certifications and hands-on experience with testing tools. This position requires SC clearance and is located onsite in Croydon for part of the week.

Qualifications

  • Experience with cloud security and containerised environments.
  • Ability to interpret and apply security NFRs across diverse environments.
  • Experience testing EUDs under operational constraints.

Responsibilities

  • Conduct internal penetration testing across applications, infrastructure, and end user devices.
  • Perform scenario-based testing aligned with security principles.
  • Collaborate with development teams for rapid remediation.

Skills

Hands-on experience with penetration testing tools
Strong understanding of OWASP
Familiarity with Secure-by-Design principles
Proficiency in JIRA

Education

Certifications: OSCP, CREST CRT, CTL Web/Inf, CEH

Tools

AWS
Azure
JIRA
SharePoint
Job description

Role: Pen tester. Rate: Outside IR35. Location: 1-2 days a week onsite in Croydon. Duration: 6 months initially. SC clearance required.

This role supports the strategic shift towards internal assurance, reducing reliance on external ITHC suppliers, and aligning with Secure-by-Design (SbD) principles.

Key Responsibilities
  • Conduct internal penetration testing across applications, infrastructure, and end user devices (EUDs), including POISE and MacBook platforms.
  • Perform scenario-based testing aligned with SbD principles and DSA security non-functional requirements.
  • Collaborate with development teams to integrate findings into JIRA workflows for rapid remediation.
  • Support the testing pipeline, including planning, execution, and reporting of penetration tests.
  • Maintain compliance with NCSC guidance and Home Office security standards.
Desirable Qualifications
  • Certifications: OSCP, CREST CRT, CTL Web/Inf, CEH.
  • Experience with cloud security (AWS, Azure) and containerised environments.
Essential Skills & Experience
  • Hands‑on experience with penetration testing tools.
  • Strong understanding of OWASP, NIST SP 800‑53, ISO 27001, and CIS Benchmarks.
  • Familiarity with Secure‑by‑Design principles and CI/CD pipeline integration.
  • Experience testing EUDs under operational constraints (e.g. no destructive tools, CSOC coordination).
  • Ability to interpret and apply security NFRs across diverse environments.
  • Proficiency in JIRA, SharePoint, and vulnerability management platforms.
Attributes
  • Strong stakeholder engagement and communication skills.
  • Ability to work independently and as part of cross‑functional teams.
  • Commitment to continuous improvement and knowledge sharing.

Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Successful applicants will be required to be security cleared prior to appointment, which can take up to a minimum 10 weeks.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.