Enable job alerts via email!

Senior Penetration Tester (Social Engineering) Penetration Testing · Remote - UK ·

Bulletproof incorporated

United Kingdom

Remote

GBP 50,000 - 80,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Senior Penetration Tester to lead innovative security assessments focused on social engineering and physical penetration testing. This role involves conducting thorough evaluations, producing detailed reports, and mentoring junior team members. You will also engage with clients directly, enhancing their security posture through tailored training and insights. Join a dynamic team that values creativity and expertise, where your contributions will significantly impact the cybersecurity landscape. If you are passionate about security and thrive in a collaborative environment, this opportunity is perfect for you.

Benefits

25 days annual holiday
Birthday holiday
Company Pension contribution
Generous uncapped bonus scheme
Subsidized gym membership
Perkbox employee benefits platform
Frequent team events
Relaxed working environment
Private Healthcare
Financial support for qualifications

Qualifications

  • Proven experience in Social Engineering and Physical Penetration Testing.
  • Strong knowledge of OWASP, PTES, and MITRE ATT&CK framework.
  • Ability to program or script in preferred language.

Responsibilities

  • Conduct comprehensive penetration testing assessments.
  • Deliver well-written technical and non-technical reports.
  • Manage and deliver testing projects within deadlines.

Skills

Social Engineering
Physical Penetration Testing
Open Source Intelligence
Vulnerability Assessment
Report Writing
Analytical Skills
Problem-Solving

Education

Relevant Security Qualifications (OSCP, CREST CRT, etc.)

Job description

Overview

As a Senior Penetration Tester, with a focus on social engineering & physical penetration testing (black team), you will perform formal and comprehensive penetration testing assessments, including producing full written reports to appropriate standards and within agreed deadlines. In addition, you will support with training, client pre-engagement activities (including scoping and proposal drafting), researching vulnerabilities and maintaining process documentation.


Responsibilities

  • Perform formal and comprehensive Social Engineering and other penetration testing assessments (i.e Application and/or Infrastructure based assessments) where appropriate and required;
  • Attend customer sites to deliver engagements where required (such as Physical Penetration Testing/Black Team engagements);
  • Provide well-written, concise, technical and non-technical reports in English;
  • Perform vulnerability assessments and provide findings with remediation actions;
  • Support with various client pre-engagement interactions, including scoping activities and proposal drafting;
  • Manage and deliver penetration testing project activities within strict deadlines;
  • Research Social Engineering trends, new attack vectors and technologies that may improve efficiencies when delivering these engagements;
  • Develop and deliver in house training to the penetration testing team;
  • Coach and mentor Graduate and Junior penetration testers;
  • Act as lead tester on large or onsite penetration testing projects (including Physical Penetration Tests);
  • Support the Marketing team with the development of content (including, but not limited to: Blogs, Social Media Posts, and Articles) to help raise the profile of Bulletproof's Penetration Testing and other services;
  • Support the QA process to ensure high quality client reports are delivered in accordance with applicable Service Level Agreement (SLA);
  • Any other appropriate job duties in line with the associated skill and experience of the post holder.

Skills and experience required

  • Proven industry experience in Social Engineering and Physical Penetration Testing (Black Team);
  • Deep knowledge of Social Engineering attack vectors relating to:
  • Phishing (email)
  • Vishing (Phone calls)
  • Physical Social engineering (in person during a Physical Penetration Test/Black Team)
  • Strong knowledge of Social Engineering and Physical Penetration attack techniques such as:
  • Lock picking
  • Card cloning
  • Elicitation
  • Disguise and Social Engineering scenario creation
  • Strong skills in Open Source Intelligence gathering – specifically targeting organisations and physical locations
  • Knowledge of the additional legal boundaries that are involved for Social Engineering attacks and Physical Site Engagements
  • Proven industry experience in infrastructure and/or application penetration testing;
  • Deep knowledge of various Operating Systems and network principles.
  • Strong understanding of OWASP, PTES and MITRE ATT&CK framework;
  • Knowledge of how modern solutions are designed and deployed across different platforms;
  • Ability to program or script in your preferred language;
  • Relevant security qualifications (such as OSCP, CREST CRT, OSEP, CCT or relevant Social Engineering exams/training);

Nice to have

  • Deep knowledge of access card cloning techniques and involved technologies
  • Experience operating as part of or in conjunction with a Red Team
  • Strong knowledge of Wireless (WiFi) testing techniques and other Signals Intelligence
  • Good knowledge of SMShing attacks and supporting infrastructure

Personal Attributes

  • Excellent spoken and written communication skills with strong attention-to-detail and accuracy;
  • A passion for security and networks;
  • Analytical and problem-solving skills with a can-do attitude and the ability to think laterally;
  • Self-motivation with a commitment to continued development;
  • Ability to work independently and as part of a team;
  • Influencing and negotiation skills with the ability to build relationships at all levels;
  • Willingness to learn.

Benefits

  • 25 days annual holiday;
  • An additional day’s annual holiday for your birthday;
  • Company Pension contribution;
  • Generous uncapped bonus scheme;
  • Subsidized gym membership;
  • Perkbox employee benefits platform;
  • Frequent team events;
  • Relaxed working environment;
  • Private Healthcare (individual cover only);
  • Financial support to study for and achieve additional penetration testing qualifications;
  • Additional Learning Allowance Benefit – a reimbursable benefit of £100 per annum (or equivalent) for you to spend towards your personal career development;
  • Flexible working policy.

Company Overview

Bulletproof is a trusted provider of innovative cyber security and people-powered solutions. Our cyber security services are the best way to stay ahead of the hackers, take control of infrastructure and protect business-critical data.

Please note that as part of the recruitment process a criminal records check will be carried out by an authorised third party.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Network Security Engineer

Corecom Consulting

Remote

GBP 60,000 - 100,000

3 days ago
Be an early applicant

Security Services Delivery Consultant

Maxwell Bond

Remote

GBP 60,000 - 80,000

10 days ago

Information Security Analyst

Push Gaming

Remote

GBP 40,000 - 80,000

10 days ago

Senior Consultant, Penetration Tester - Red Team | Remote UK

TN United Kingdom

Remote

GBP 67,000 - 88,000

3 days ago
Be an early applicant

Security Vulnerability & Penetration Testing (VAPT) Engineer - Remote (UK)

JR United Kingdom

Greater Manchester

Remote

GBP 50,000 - 80,000

Today
Be an early applicant

Security Vulnerability & Penetration Testing (VAPT) Engineer - Remote (UK)

JR United Kingdom

London

Remote

GBP 50,000 - 90,000

Yesterday
Be an early applicant

Consultant, Penetration Tester - Red Team | Remote UK

TN United Kingdom

Remote

GBP 50,000 - 66,000

3 days ago
Be an early applicant

Lead Information Security Architect

Deel

Remote

GBP 70,000 - 110,000

7 days ago
Be an early applicant

Security Vulnerability & Penetration Testing (VAPT) Engineer - Remote (UK)

JR United Kingdom

West Midlands Combined Authority

Remote

GBP 50,000 - 90,000

3 days ago
Be an early applicant