Principal AppSec Penetration Testing Consultant
We are seeking a highly experienced Principal AppSec Penetration Testing Consultant to lead and deliver complex security assessments across a wide range of environments. This role suits a hands‑on expert who enjoys deep technical work while also owning delivery quality, mentoring others, and acting as a trusted security advisor to clients.
Key Responsibilities
- Lead and perform advanced application penetration tests across modern web technologies, frameworks, APIs, and microservice‑based architectures.
- Design and execute manual and automated testing approaches, incorporating SAST and DAST methodologies to complement hands‑on exploitation and maximise coverage.
- Deliver high‑quality Pentesting beyond web applications, including network, cloud security, mobile app, red team engagements, and social engineering where appropriate.
- Own engagements end to end, from scoping and threat modelling through execution, reporting, and final client presentations.
- Produce clear, professional penetration test reports with actionable remediation guidance, suitable for engineers, security teams, and senior stakeholders.
- Present findings to both technical and non‑technical audiences, translating vulnerabilities into business‑relevant risk and prioritised recommendations.
- Act as a senior technical authority, contributing to methodology development, quality assurance, and mentoring of junior consultants.
- Stay current with emerging vulnerabilities, attack techniques, and tooling, including developments in secure SDLC, SAST, and DAST practices.
Required Skills & Experience
- 5+ years of experience performing complex application penetration tests across common web technologies and application stacks.
- Strong understanding of SAST and DAST tools and workflows, including how to interpret results, reduce false positives, and integrate findings into manual testing.
- Broad technical skillset enabling delivery of high‑quality security assessments across multiple domains, not limited to AppSec.
- Solid knowledge of secure development practices, common vulnerability classes (e.g. OWASP Top 10), and real‑world exploitation techniques.
- Experience leading penetration tests from scoping to final delivery in a consulting environment.
- Excellent written and verbal communication skills, with the ability to communicate effectively with both technical and non‑technical stakeholders.
Nice to Have
- Industry‑recognised certifications such as OSCP, OSCE, OSWA, OSWE, CRTO, BSCP, or equivalent.
- Published security research, CVEs, blog posts, conference talks, or open‑source security tools.
- Active involvement in CTFs, bug bounty programmes, security research, or the wider hacking community.
- Completion of relevant security‑related MOOCs, training programmes, or recognised books.
Seniority level
Mid‑Senior level
Employment type
Full‑time
Job function
Consulting
Industries
Computer and Network Security and IT Services and IT Consulting