Job Search and Career Advice Platform

Enable job alerts via email!

Penetration Tester – Offensive Security

MastarRec

Greater London

Hybrid

GBP 70,000 - 95,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A cybersecurity firm in the UK is seeking a certified Penetration Tester to join their team. The role involves planning and executing penetration tests, conducting red team engagements, and identifying vulnerabilities across various platforms. The ideal candidate should possess strong skills in penetration testing tools like Kali Linux and Burp Suite, hold an industry certification, and have a solid understanding of cybersecurity principles. The position offers a competitive salary and hybrid working options.

Benefits

Competitive salary
Performance bonus
Paid training and certification reimbursement
25 days holiday plus bank holidays
Private healthcare
Mental health support
Company-funded attendance at security conferences

Qualifications

  • Strong proficiency in penetration testing tools like Kali Linux, Burp Suite, and Metasploit.
  • Experience with OWASP Top 10 and exploit development.
  • Solid knowledge of TCP/IP firewalls, DNS, HTTP/HTTPS protocols.
  • At least one industry certification such as OSCP or CEH.

Responsibilities

  • Plan and execute penetration tests across various environments.
  • Conduct simulated phishing, social engineering, and physical security assessments.
  • Produce detailed technical reports and manage vulnerabilities.

Skills

Penetration testing tools
Kali Linux
Burp Suite
Metasploit
Nmap
Wireshark
Scripting skills in Python
Scripting skills in PowerShell
Scripting skills in Bash

Education

OSCP certificate
CEH
CREST CRT
CISM
CRISC

Tools

GRC platforms (RSA Archer, ServiceNow)
ISO 27001
NIST CSF
Job description
Job Description

We are looking for a certified Penetration Tester to join our client’s cybersecurity team and help safeguard critical systems through simulated attacks and red team assessments. You’ll be responsible for identifying vulnerabilities across networks, applications, and cloud infrastructure, and providing actionable insights to reduce risk exposure.

Ideal candidates have deep experience in offensive security, a strong understanding of exploits and security protocols, and a drive to continuously evolve with today’s fast-moving threat landscape.

Job Responsibilities
  • Plan, execute, and report on penetration tests across networks, web applications, APIs, mobile, and cloud environments.
  • Conduct red team engagements including simulated phishing, social engineering, and physical security assessments.
  • Identify, document, and prioritize vulnerabilities and misconfigurations.
  • Use both manual techniques and automated tools (e.g. Burp Suite, Metasploit, Nmap).
  • Collaborate with blue team and remediation teams to harden systems.
  • Produce detailed technical reports and executive summaries for stakeholders.
  • Stay up to date with the latest exploits, vulnerabilities (CVEs), and threat actor tactics.
Required Skills
  • Strong proficiency in penetration testing tools (e.g. Kali Linux, Burp Suite, Metasploit, Nmap, Wireshark).
  • Experience with OWASP Top 10 vulnerability scanning and exploit development.
  • Familiarity with MITRE ATT&CK framework and red team methodology.
  • Solid knowledge of TCP/IP firewalls, DNS, HTTP/HTTPS, and encryption protocols.
  • Strong reporting and communication skills.
  • At least one industry certification (OSCP, CEH, CREST CRT, or similar).

Required Skills: In-depth knowledge of ISO 27001, NIST CSF, GDPR, and risk management frameworks; experience performing security risk assessments, internal audits, and compliance reviews; strong understanding of cybersecurity controls, regulatory mandates, and business risk alignment; excellent client communication, stakeholder management and reporting skills; familiarity with GRC platforms (e.g. RSA Archer, ServiceNow, GRC LogicGate); Desired Skills: Certifications such as CISM, CRISC, ISO 27001 Lead Auditor or similar; experience working with financial services, healthcare, or SaaS industries; understanding of emerging regulations (e.g. DORA, NIS2, AI Act); cloud compliance knowledge (e.g. CSA CCM, AWS / Azure / GCP compliance); familiarity with SOC 2, PCI DSS, HIPAA frameworks.

Desired Skills
  • Scripting skills in Python, PowerShell, or Bash.
  • Experience with cloud security testing (AWS, Azure, GCP).
  • Familiarity with CI/CD environments and DevSecOps.
  • Exposure to purple teaming or adversary emulation.
  • Knowledge of physical security and social engineering tactics.
Job Benefits
  • Competitive salary, performance bonus.
  • Paid training and certification reimbursement (OSCP, CREST, etc.).
  • 25 days holiday, bank holidays.
  • Private healthcare, mental health support.
  • Fully remote or hybrid working options.
  • Company-funded attendance at security conferences (DEF CON, Black Hat, etc.).
Position Details

Employment Type: Full Time

Experience: years

Vacancy: 1

Yearly Salary: 70000 - 95000

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.