At a Glance
- Tasks: Lead penetration testing on client applications and assess security best practices.
- Company: Join Coalfire, a leader in cybersecurity solutions with a mission to make the world safer.
- Benefits: Enjoy flexible work options, competitive salary, and comprehensive benefits including mental health support.
- Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
- Qualifications: Experience in application security and strong technical skills in programming or scripting languages.
- Other info: Collaborative culture with opportunities for professional development and community engagement.
The predicted salary is between 54000 - 65000 £ per year.
About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients' hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the everāchanging cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problemāsolvers who are hungry to learn, grow, and make a difference.
The Consultant works closely with Project Managers, Delivery Directors, and other Delivery team members to lead engagements, assessing the security of various types of client applications and supporting infrastructure against security best practices. The Consultant is a technical leader with broad technical skills, meeting the objectives of their engagements, collaborating with clients, mentoring teammates, and providing subjectāmatter expertise across one or more technical domains. The Consultant is a trusted advisor to clients, and through objective testing and results reporting, supports the client in making wellāinformed, riskābased decisions to improve overall security posture.
What You'll Do
- Working independently and collaboratively with a team to both lead and support
- Perform penetration testing on applications with complex technology stacks from both a Blackbox & Whitebox perspective
- Dynamically flex your skills when assessing emerging or custom technologies
- Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors
- Manage priorities and tasks to achieve utilization targets
- Operate with professionalism both internally and with clients
- Ensure quality reports and services are delivered efficiently and on time
- Maintain strong depth of knowledge in the practice area
- Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables
- Up to 10% travel
What You'll Bring
- Application penetration testing and assessment tradecraft and methodologies (including browserābased, API)
- Strong working knowledge of at least two programming or scripting languages
- Strong understanding of security principles and industry best practices
- Minimum of 2 years' experience in a consulting/professional services role
- Minimum of 2 years' experience in Application Security and/or Software Development
- Proficiency in Web Application Penetration Testing
- Strong overall technical skills, with strong expertise in at least one of the following:
- Mobile Application Penetration Testing
- Thick Application Penetration Testing
- Hardware Penetration Testing
- Secure Code Review
- Container Penetration Testing
- Cloud Penetration Testing
- Network Active Directory Penetration Testing
- AI Penetration Testing
- Time management, performing adjacent tasks while ensuring onātime delivery, escalating issues as needed
- Verbal communication, leading client calls for project kickoffs and debrief
- Written communication & Report writing, for both executive audiences and technical staff
Bonus Points
- UK CREST Certification and eligibility to be approved for and maintain UK SC level Clearance
- Strongly preferred CREST Certifications
- CREST Practitioner Security Analyst (CPSA)
- CREST Practitioner Threat Intelligence Analyst (CPTIA)
- AWAE, OSCP, OSCE, OSEE offensive security certifications
- Significant development and engineering backgrounds
- Cloud Service penetration testing tradecraft and methodologies across multiple service providers (e.g. AWS, GCP, etc.)
- Mobile platform and application penetration testing tradecraft and methodologies across both iOS and Android.
- Red/Purple Team tradecraft and methodologies
- Social engineering in all its forms
- AWS Certified Solutions Architect ā Professional, AWS Certified Security, AWS Certified Advanced Networking, AWS Certified SysOps Administrator
- Network, Database, System administration experience and certifications
Ā£63,000 - Ā£72,810 a year. The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on jobārelated education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.
Why You'll Want to Join Us
At Coalfire, you'll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you'll work most effectively ā whether you're at home or an office.
Regardless of location, you'll experience a company that prioritises connection and wellbeing and be part of a team where people care about each other and our communities. You'll have opportunities to join employee resource groups, participate in ināperson and virtual events, and more. And you'll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com.
Consultant, Application Security Penetration Tester in London employer: Coalfire
Contact Detail:
Coalfire Recruiting Team
StudySmarter Expert Advice š¤«
We think this is how you could land Consultant, Application Security Penetration Tester in London
āØTip Number 1
Network like a pro! Reach out to current employees at Coalfire on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the Consultant role. Personal connections can make a huge difference!
āØTip Number 2
Prepare for the interview by brushing up on your technical skills. Since this role involves application security and penetration testing, be ready to discuss your experience with various technologies and methodologies. Show us you know your stuff!
āØTip Number 3
Practice your communication skills! As a Consultant, you'll need to explain complex security concepts to clients. Try explaining your past projects to friends or family to ensure you can break it down simply and effectively.
āØTip Number 4
Donāt forget to apply through our website! Itās the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the Coalfire team!
We think you need these skills to ace Consultant, Application Security Penetration Tester in London
Some tips for your application š«”
Tailor Your Application: Make sure to customise your CV and cover letter for the Consultant role. Highlight your experience in application security and penetration testing, and show us how your skills align with what we're looking for.
Showcase Your Technical Skills: We want to see your technical prowess! Include specific examples of your work with programming languages and penetration testing methodologies. This is your chance to shine, so donāt hold back!
Be Clear and Concise: When writing your application, keep it clear and to the point. Use straightforward language and avoid jargon unless necessary. We appreciate a well-structured application thatās easy to read.
Apply Through Our Website: Donāt forget to submit your application through our website! Itās the best way for us to receive your details and ensures youāre considered for the role. We canāt wait to hear from you!
How to prepare for a job interview at Coalfire
āØKnow Your Stuff
Make sure you brush up on your application security knowledge, especially around penetration testing methodologies. Be ready to discuss specific tools and techniques you've used in past projects, as well as any programming languages you're proficient in.
āØShowcase Your Problem-Solving Skills
Coalfire values passionate problem-solvers, so prepare to share examples of how you've tackled complex security challenges. Think about situations where you had to think outside the box or adapt your approach to meet client needs.
āØCommunicate Clearly
Since you'll be leading client calls and writing reports, practice articulating your thoughts clearly and concisely. Consider doing mock interviews with a friend to refine your verbal communication skills and ensure you can explain technical concepts to non-technical audiences.
āØBe Ready for Real-World Scenarios
Expect to face scenario-based questions during your interview. Prepare by reviewing case studies or past engagements where you assessed vulnerabilities and made recommendations. This will help demonstrate your practical experience and ability to contextualise risks.