At a Glance
- Tasks: Conduct penetration tests and produce detailed reports to enhance security.
- Company: Join Bulletproof, a leader in innovative cyber security solutions.
- Benefits: Enjoy 25 days holiday, bonuses, gym membership, and flexible working.
- Why this job: Make a real impact in cyber security while developing your skills.
- Qualifications: Experience in penetration testing and knowledge of security frameworks required.
- Other info: Collaborative team environment with opportunities for growth and learning.
The predicted salary is between 36000 - 60000 £ per year.
As a Penetration Tester, you will perform formal and comprehensive penetration testing assessments, including producing full written reports to appropriate standards and within agreed deadlines. In addition, you will support with client pre-engagement activities, including scoping and proposal drafting, as well as researching new vulnerabilities and technologies, following responsible disclosure, and sharing such findings within the team.
RESPONSIBILITIES
- Perform formal and comprehensive application and other penetration testing assessments where appropriate and required;
- Provide well-written, concise, technical and non-technical reports in English;
- Perform vulnerability/attack surface assessments and provide findings with remediation actions;
- Support with various client pre-engagement interactions, including scoping activities and proposal drafting;
- Manage and deliver penetration testing project activities within strict deadlines;
- Research new technologies, security topics and vulnerabilities within the wider team to identify new vulnerabilities and follow responsible disclosure;
- Coach and mentor Graduate and Junior penetration testers where appropriate;
- Support the Marketing team with the development of content (including, but not limited to: Blogs, Social Media Posts, and Articles) to help raise the profile of Bulletproof's Penetration Testing and other services;
- Support the QA process to ensure high quality client reports are delivered in accordance with applicable Service Level Agreement (SLA);
- Any other appropriate job duties in line with the associated skill and experience of the post holder.
SKILLS AND EXPERIENCE REQUIRED
- Proven industry experience in web/API/mobile/thick client application penetration testing;
- Deep knowledge of various Operating Systems and network principles;
- Strong understanding of OWASP, PTES and MITRE ATT&CK framework;
- Knowledge of how modern solutions are designed and deployed across different platforms;
- Ability to program or script in your preferred language;
- Relevant security qualifications (such as OSCP, CREST CRT, OSWE, CCT APP);
- Experience leading penetration testing projects and acting as a lead technical point of contact.
NICE TO HAVE
- Knowledge of assessing cloud and/or hybrid environments (AWS and Azure);
- Knowledge of performing source code reviews in a language of your preference and expertise;
- Knowledge in preparing and launching social engineering campaigns;
- Involvement in previous research projects, tool development and training delivery.
PERSONAL ATTRIBUTES
- Excellent spoken and written communication skills with strong attention-to-detail and accuracy;
- A passion for security and networks;
- Analytical and problem-solving skills with a can-do attitude and the ability to think laterally;
- Self-motivation with a commitment to continued development;
- Ability to work independently and as part of a team;
- Influencing and negotiation skills with the ability to build relationships at all levels;
- Willingness to learn.
BENEFITS
- 25 days annual holiday;
- An additional day’s annual holiday for your birthday;
- Company Pension contribution;
- Generous uncapped bonus scheme;
- Subsidized gym membership;
- Perkbox employee benefits platform;
- Frequent team events;
- Private Healthcare (individual cover only);
- Financial support to study for and achieve additional penetration testing qualifications;
- Additional Learning Allowance Benefit;
- Flexible working policy.
Bulletproof is a trusted provider of innovative cyber security and people-powered solutions. Our cyber security services are the best way to stay ahead of the hackers, take control of infrastructure and protect business-critical data. With our own in-house UK Security Operations Centre (SOC) and years of industry experience, we help to protect our customers from current and emerging security threats. We provide a full spectrum of cyber security services including CREST-certified penetration testing, 24/7 threat monitoring, compliance support and security training to help organisations protect against today’s evolving threat landscape.
Please note that as part of the recruitment process a criminal records check will be carried out by an authorised third party.
Penetration Tester (Web App) employer: Bulletproof incorporated
Contact Detail:
Bulletproof incorporated Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Penetration Tester (Web App)
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can refer you directly to hiring managers.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects, reports, and any cool tools you've developed. This not only demonstrates your expertise but also gives potential employers a taste of what you can bring to the table.
✨Tip Number 3
Don’t just apply anywhere—apply smart! Use our website to find roles that match your skills and interests. Tailor your approach for each application, highlighting how your experience aligns with the specific needs of the role.
✨Tip Number 4
Follow up after interviews! A quick thank-you email can go a long way. It shows your enthusiasm for the role and keeps you fresh in the interviewer's mind. Plus, it’s a great chance to reiterate why you’re the perfect fit!
We think you need these skills to ace Penetration Tester (Web App)
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Penetration Tester role. Highlight your relevant experience in web/API/mobile penetration testing and any specific projects that showcase your skills. We want to see how you fit into our team!
Show Off Your Writing Skills: Since you'll be producing reports, it's crucial to demonstrate your ability to write clearly and concisely. Include examples of technical and non-technical writing in your application. This will help us gauge your communication skills right from the start.
Research and Reflect: Take some time to research Bulletproof and our approach to penetration testing. Reflect this knowledge in your application by mentioning how your values align with ours. It shows us you're genuinely interested in being part of our team!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets to the right people. Plus, it makes the process smoother for both you and us!
How to prepare for a job interview at Bulletproof incorporated
✨Know Your Stuff
Make sure you brush up on your penetration testing knowledge, especially around web applications, APIs, and the OWASP framework. Be ready to discuss specific vulnerabilities and how you would approach testing them.
✨Showcase Your Reports
Since you'll need to produce both technical and non-technical reports, bring examples of your previous work. This will demonstrate your ability to communicate findings clearly and effectively, which is crucial for the role.
✨Engage in Scoping Discussions
Prepare to talk about how you would handle client pre-engagement activities. Think about how you would scope a project and draft proposals, as this shows your understanding of the entire penetration testing process.
✨Be a Team Player
Highlight your experience in mentoring or coaching others, as well as your ability to work collaboratively. This is important since you'll be part of a team that shares findings and supports each other in research and development.