At a Glance
- Tasks: Conduct penetration tests and produce detailed reports while mentoring junior testers.
- Company: Join a leading cyber security firm dedicated to protecting businesses from hackers.
- Benefits: Enjoy 25 days holiday, flexible work, bonuses, and support for further qualifications.
- Why this job: Be part of a dynamic team tackling real-world security challenges with a focus on innovation.
- Qualifications: Experience in web/API testing and relevant security certifications are essential.
- Other info: This role is remote but requires UK residency and the right to work.
The predicted salary is between 30000 - 70000 £ per year.
Penetration Tester (Web/API) Increase your chances of reaching the interview stage by reading the complete job description and applying promptly. Please note: this role requires you to be UK-based already with full right to work and live in the UK Salary up to £50k base + benefits Overview As a Penetration Tester, you will perform formal and comprehensive penetration testing assessments, including producing full written reports to appropriate standards and within agreed deadlines. In addition, you will support with client pre-engagement activities, including scoping and proposal drafting, as well as researching new vulnerabilities and technologies, following responsible disclosure, and sharing such findings within the team. Responsibilities Perform formal and comprehensive application and other penetration testing assessments where appropriate and required; Provide well-written, concise, technical and non-technical reports in English; Perform vulnerability/attack surface assessments and provide findings with remediation actions; Support with various client pre-engagement interactions, including scoping activities and proposal drafting; Manage and deliver penetration testing project activities within strict deadlines; Research new technologies, security topics and vulnerabilities within the wider team to identify new vulnerabilities and follow responsible disclosure; Coach and mentor Graduate and Junior penetration testers where appropriate; Support the Marketing team with the development of content (including, but not limited to: Blogs, Social Media Posts, and Articles) to help raise the profile of Penetration Testing and other services; Support the QA process to ensure high quality client reports are delivered in accordance with applicable Service Level Agreement (SLA); Any other appropriate job duties in line with the associated skill and experience of the post holder. Skills and experience required Proven industry experience in web/API/mobile/thick client application penetration testing; Deep knowledge of various Operating Systems and network principles. Strong understanding of OWASP, PTES and MITRE ATT&CK framework; Knowledge of how modern solutions are designed and deployed across different platforms; Ability to program or script in your preferred language. Relevant security qualifications (such as OSCP, CREST CRT, OSWE, CCT APP); Experience leading penetration testing projects and acting as a lead technical point of contact. Nice To Have Knowledge of assessing cloud and/or hybrid environments (AWS and Azure); Knowledge of performing source code reviews in a language of your preference and expertise; Knowledge in preparing and launching social engineering campaigns; Involvement in previous research projects, tool development and training delivery. Personal Attributes Excellent spoken and written communication skills with strong attention-to-detail and accuracy; A passion for security and networks; Analytical and problem-solving skills with a can-do attitude and the ability to think laterally; Self-motivation with a commitment to continued development; Ability to work independently and as part of a team; Influencing and negotiation skills with the ability to build relationships at all levels; Willingness to learn. Benefits 25 days annual holiday; An additional day’s annual holiday for your birthday; Company Pension contribution; Generous uncapped bonus scheme; Subsidized gym membership; Perkbox employee benefits platform; Frequent team events; Private Healthcare (individual cover only); Financial support to study for and achieve additional penetration testing qualifications; Additional Learning Allowance Benefit; Flexible working policy. Company Overview A trusted provider of innovative cyber security and people-powered solutions. Our cyber security services are the best way to stay ahead of the hackers, take control of infrastructure and protect business-critical data. With our own in-house UK Security Operations Centre (SOC) and years of industry experience, we help to protect our customers from current and emerging security threats. We provide a full spectrum of cyber security services including CREST-certified penetration testing, 24/7 threat monitoring, compliance support and security training to help organisations protect against today’s evolving threat landscape. Remote working/work at home options are available for this role.
PenTester (Remote) - WebApp employer: Cyber Search Partners
Contact Detail:
Cyber Search Partners Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land PenTester (Remote) - WebApp
✨Tip Number 1
Make sure to showcase your hands-on experience with web/API penetration testing. Highlight specific projects or assessments you've conducted, as this will demonstrate your practical skills and understanding of the role.
✨Tip Number 2
Familiarize yourself with the OWASP, PTES, and MITRE ATT&CK frameworks. Being able to discuss these frameworks in detail during your interview will show that you are well-versed in industry standards and best practices.
✨Tip Number 3
Prepare to discuss your experience with client interactions, especially in scoping and proposal drafting. This is a key part of the role, and demonstrating your ability to communicate effectively with clients will set you apart.
✨Tip Number 4
Stay updated on the latest vulnerabilities and security technologies. Being knowledgeable about current trends will not only help you in the role but also impress the interviewers with your commitment to continuous learning.
We think you need these skills to ace PenTester (Remote) - WebApp
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in web/API penetration testing. Include specific projects you've worked on, tools you've used, and any security qualifications you hold.
Craft a Strong Cover Letter: Write a cover letter that showcases your passion for security and your understanding of the role. Mention your familiarity with OWASP, PTES, and MITRE ATT&CK frameworks, and how you can contribute to the team.
Showcase Your Communication Skills: Since the role requires producing well-written reports, emphasize your written communication skills. Provide examples of past reports or documentation you've created that demonstrate clarity and technical accuracy.
Highlight Continuous Learning: Mention any ongoing education or training you're pursuing in the field of penetration testing. This shows your commitment to professional development and staying updated with the latest security trends.
How to prepare for a job interview at Cyber Search Partners
✨Showcase Your Technical Skills
Be prepared to discuss your experience with web/API penetration testing in detail. Highlight specific projects you've worked on, the tools you used, and the methodologies you followed. This will demonstrate your hands-on expertise and understanding of the field.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving abilities in real-world scenarios. Practice articulating how you would approach a penetration test, including scoping, execution, and reporting. This will show your analytical skills and ability to think critically under pressure.
✨Communicate Clearly and Concisely
Since you'll need to produce both technical and non-technical reports, practice explaining complex concepts in simple terms. During the interview, focus on clear communication to convey your ideas effectively, showcasing your written and verbal skills.
✨Demonstrate Your Passion for Security
Share your enthusiasm for cybersecurity and any personal projects or research you've undertaken. Discussing your commitment to continuous learning and staying updated on the latest vulnerabilities and technologies will resonate well with the interviewers.