Penetration Tester (Principal Consultant)
Penetration Tester (Principal Consultant)

Penetration Tester (Principal Consultant)

Leeds Full-Time 48000 - 64000 £ / year (est.) No home office possible
C

At a Glance

  • Tasks: Lead offensive security projects and manage high-performing teams in cybersecurity.
  • Company: Cognisys is a leading cybersecurity firm specializing in Penetration Testing and Managed Security services.
  • Benefits: Enjoy hybrid work options, professional development budgets, and wellness resources.
  • Why this job: Join a collaborative team making a real impact in cybersecurity with innovative projects.
  • Qualifications: 7+ years in cybersecurity with expertise in penetration testing and cloud security required.
  • Other info: We celebrate innovation and value contributions, fostering a supportive work environment.

The predicted salary is between 48000 - 64000 £ per year.

Location: Leeds (hybrid) / UK (remote)

Salary: up to £80K (DOE)

Are you ready to make an impact in the fast-paced world of cybersecurity? Cognisys is growing rapidly, and we’re looking for a Penetration Tester (Principal Consultant) to join our team during this exciting period of innovation and expansion.

Cognisys is a leading cybersecurity company specializing in Penetration Testing, GRC Consulting, and Managed Security services. We pride ourselves on our customer service, forward-thinking approach, and commitment to excellence. Our small but mighty team works with some of the best-known companies in the world and covers over 30 countries worldwide!

About The Role

As a Penetration Tester (Principal Consultant), you will be key in driving commercial success, managing high-performing teams, and delivering cutting-edge offensive security projects. This role is ideal for a technical leader with deep expertise in red teaming and cloud security, coupled with a passion for business growth and client engagement.

If you are a seasoned cybersecurity professional with a passion for offensive security, team leadership, and business growth, we want to hear from you!

Key Responsibilities

Commercial & Client Engagement:

  • Act as a primary technical contact for key accounts, ensuring strong client relationships and project success.
  • Lead pre-sales engagements, scope projects, and develop Statements of Work (SOWs) that align with client needs.
  • Effectively communicate complex security risks and mitigation strategies to technical and non-technical stakeholders.
  • Represent Cognisys Group at industry events and conferences, demonstrating thought leadership and engaging with the cybersecurity community.

Technical Leadership & Delivery

  • Plan, execute, and oversee advanced Red Team Assessments, cloud security assessments, and penetration testing engagements.
  • Simulate real-world attack scenarios to identify vulnerabilities across networks, cloud environments, applications, and infrastructure.
  • Lead the development and execution of multi-stage attack simulations, leveraging advanced offensive security techniques.
  • Evaluate security controls, incident response processes, and overall security posture, providing actionable remediation guidance.
  • Research and stay ahead of evolving threats, techniques, and security tools to improve methodologies continuously.

Team Management & Development

  • Manage, mentor, and develop a team of security consultants, fostering technical excellence and career growth.
  • Conduct performance evaluations, set professional development goals, and provide guidance on technical engagements.
  • Oversee the quality of penetration testing and red teaming reports, ensuring clarity, accuracy, and actionable insights.
  • Drive knowledge-sharing initiatives within the team, promoting collaboration and continuous learning.

Innovation & Research (optional)

  • Contribute to the development of offensive security tools, methodologies, and frameworks to enhance testing capabilities.
  • Publish security advisories, blogs, and research papers on emerging threats, vulnerabilities, and attack techniques.
  • Participate in the creation and/or oversee the delivery of security training courses for internal teams and external audiences.

Essential Qualifications & Experience

  • 7+ years of experience in cybersecurity, with a strong focus on penetration testing, red teaming, and cloud security.
  • 4+ years of experience in client-facing consulting roles, demonstrating strong business acumen and stakeholder management.
  • Expertise in red teaming methodologies, including social engineering, network exploitation, and lateral movement techniques.
  • Deep understanding of cloud security, including AWS, Azure, and GCP, with hands-on experience in assessing cloud environments.
  • Proficiency in offensive security tools such as Cobalt Strike, Metasploit, PowerShell Empire, and custom exploit development.
  • Strong programming and scripting skills in Python, PowerShell, or Bash to develop and automate attack techniques. Personal GitHub repo would be required to be shared before the Interview showcasing your development skills.
  • Knowledge of MITRE ATT&CK framework, adversary simulation techniques, and threat hunting strategies.
  • Ability to articulate security findings effectively to both technical teams and executive leadership.

Preferred Qualifications & Skills

  • Certifications such as OSCP, OSCE, CCT, CRTO, or Cloud Security Specialty. CCT is a must.
  • Experience leading APT-style engagements and simulating sophisticated cyber threats.
  • Public speaking experience at cybersecurity conferences and events.

What We Offer

  • A dynamic and supportive work environment where customer care and innovation drive everything we do.
  • A dedicated budget for your professional development and training in cyber security and sales.
  • EMI Employee Share Schemes, providing the opportunity to share in the success of the company.
  • Access to an Employee Wellness Hub supported by Kara Connect for health and well-being resources.
  • Frequent team social events and celebrations.
  • 22 days holiday rising to 25, plus a birthday holiday.
  • Referral bonus scheme up to £2,000!

Why Join Us?

At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You\’ll have the opportunity to work on challenging projects that make a real impact on our clients. If you are driven by a desire to protect and innovate, we’d love to hear from you!

We\’re not just about the work; we\’re about our people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.

Applications

Please feel free to reach out to Dom, our Head of Talent Acquisition if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format –

We welcome applications from candidates from diverse backgrounds and can make reasonable adjustments to accommodate individual needs.

NO RECRUITMENT AGENCIES, PLEASE

#J-18808-Ljbffr

Penetration Tester (Principal Consultant) employer: Cognisys

Cognisys is an exceptional employer that fosters a dynamic and supportive work environment, where innovation and customer care are at the forefront of everything we do. With a strong emphasis on professional development, employees benefit from dedicated training budgets, employee wellness resources, and a collaborative culture that values input and encourages growth. Join us in Leeds or remotely in the UK to work on impactful projects with a talented team, while enjoying competitive benefits and a commitment to celebrating your contributions.
C

Contact Detail:

Cognisys Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Penetration Tester (Principal Consultant)

✨Tip Number 1

Make sure to showcase your experience in client-facing roles. Highlight any successful projects where you managed client relationships and delivered results, as this is crucial for the role.

✨Tip Number 2

Demonstrate your technical leadership skills by discussing any teams you've managed or mentored. Share specific examples of how you've fostered growth and collaboration within your team.

✨Tip Number 3

Engage with the cybersecurity community by attending industry events or conferences. This not only helps you stay updated on trends but also positions you as a thought leader, which is highly valued in this role.

✨Tip Number 4

Prepare to discuss your personal GitHub repository during the interview. Ensure it showcases your development skills and any offensive security tools or methodologies you've contributed to.

We think you need these skills to ace Penetration Tester (Principal Consultant)

Penetration Testing
Red Teaming Methodologies
Cloud Security (AWS, Azure, GCP)
Client Engagement
Stakeholder Management
Offensive Security Tools (Cobalt Strike, Metasploit, PowerShell Empire)
Programming and Scripting (Python, PowerShell, Bash)
MITRE ATT&CK Framework
Threat Hunting Strategies
Technical Leadership
Team Management and Development
Communication Skills
Performance Evaluation
Research and Innovation in Cybersecurity

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your extensive experience in penetration testing, red teaming, and cloud security. Use specific examples that demonstrate your technical leadership and client engagement skills.

Craft a Compelling Cover Letter: In your cover letter, express your passion for offensive security and business growth. Mention how your background aligns with Cognisys's mission and values, and provide insights into your approach to managing high-performing teams.

Showcase Your Technical Skills: Include a link to your personal GitHub repository in your application. Highlight any relevant projects or tools you have developed that showcase your programming and scripting skills, particularly in Python, PowerShell, or Bash.

Prepare for Interviews: Be ready to discuss your experience with advanced Red Team Assessments and cloud security assessments. Prepare to articulate complex security risks and mitigation strategies clearly to both technical and non-technical stakeholders.

How to prepare for a job interview at Cognisys

✨Showcase Your Technical Expertise

Be prepared to discuss your experience in penetration testing, red teaming, and cloud security in detail. Highlight specific projects where you successfully identified vulnerabilities and implemented solutions, as this will demonstrate your hands-on expertise.

✨Communicate Effectively with Stakeholders

Practice articulating complex security concepts in a way that is understandable to both technical and non-technical audiences. This skill is crucial for the role, as you'll need to engage with clients and explain risks and mitigation strategies clearly.

✨Demonstrate Leadership Skills

Prepare examples of how you've managed teams or mentored junior consultants in the past. Discuss your approach to fostering technical excellence and career growth within your team, as this aligns with the responsibilities of the position.

✨Research Current Threats and Tools

Stay updated on the latest trends in cybersecurity, including emerging threats and new offensive security tools. Being knowledgeable about current events in the field will not only impress your interviewers but also show your commitment to continuous learning and improvement.

Penetration Tester (Principal Consultant)
Cognisys
C
  • Penetration Tester (Principal Consultant)

    Leeds
    Full-Time
    48000 - 64000 £ / year (est.)

    Application deadline: 2027-04-23

  • C

    Cognisys

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>