At a Glance
- Tasks: Conduct penetration testing to identify vulnerabilities and enhance security across web and cloud environments.
- Company: Join a global leader in information and analytics, making a real impact on science and healthcare.
- Benefits: Generous holiday allowance, health benefits, study assistance, and employee discounts.
- Why this job: Leverage your skills to strengthen security and contribute to meaningful advancements in healthcare.
- Qualifications: Experience in security and software development, with relevant offensive-security certification.
- Other info: Enjoy a healthy work/life balance and excellent career growth opportunities.
The predicted salary is between 36000 - 60000 £ per year.
Are you ready to leverage your expertise in security and software development to make a significant impact? We are seeking a Penetration Tester to help strengthen our web and cloud security. In this role, you will perform thorough penetration testing, identify vulnerabilities, and recommend effective solutions. You will collaborate with teams across the organisation to improve our overall security posture.
Responsibilities
- Conduct manual and automated penetration testing across web and cloud environments, including SAST, DAST, configuration reviews, and code analysis.
- Document findings and produce detailed technical security assessment reports.
- Identify, assess, and prioritise vulnerabilities and exploitation risks; recommend mitigation and detection strategies.
- Validate security fixes, ensuring remediation efforts are correctly implemented.
- Analyze recurring security issues to identify root causes and propose permanent solutions.
- Recommend improvements to tools, processes, and applications to strengthen security posture.
- Develop and maintain scripts to automate security testing and cybersecurity processes.
- Support continuous enhancement of security practices, standards, and policies.
- Perform advanced security testing of Identity and Access Management (IAM) solutions.
Requirements
- Good years of security experience and IT experience in software development or DevOps.
- BS in Engineering, Information Technology, Computer Science, or equivalent (advanced degree preferred).
- At least one relevant offensive-security certification (e.g., OSCP, OSWE, OSEP, GPEN, GXPN, CEH, or equivalent penetration testing/red teaming certification).
- Strong understanding of cloud services, networking, web application architecture, content delivery, and operating system security.
- Ability to scope, execute, and report on penetration tests (manual and automated).
- Proficiency with industry security testing tools (open-source and commercial).
- Expert-level knowledge of secure coding principles, SAST, DAST, API security testing, and vulnerability analysis.
- Strong scripting and automation skills (Python, Bash, etc.).
- Ability to assess emerging threats and perform risk evaluations using threat intelligence tools.
- Excellent problem-solving and communication skills, including working effectively with global teams and presenting to senior stakeholders.
Working for you
We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.
Benefits
- Generous holiday allowance with the option to buy additional days.
- Health screening, eye care vouchers and private medical benefits.
- Access to a competitive contributory pension scheme.
- Save As You Earn share option scheme.
- Travel Season ticket loan.
- Electric Vehicle Scheme.
- Maternity, paternity and shared parental leave.
- Employee Assistance Programme.
- Access to emergency care for both the elderly and children.
- RECARES days, giving you time to support the charities and causes that matter to you.
- Access to employee resource groups with dedicated time to volunteer.
- Access to extensive learning and development resources.
- Access to employee discounts scheme via Perks at Work.
About the business
A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. What you do every day will help advance science and healthcare to advance human progress.
Security Assurance Penetration Tester employer: Elsevier
Contact Detail:
Elsevier Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Assurance Penetration Tester
✨Tip Number 1
Network like a pro! Reach out to current employees at Elsevier on LinkedIn or other platforms. A friendly chat can give us insights into the company culture and maybe even a referral!
✨Tip Number 2
Prepare for the technical interview by brushing up on your penetration testing skills. We recommend simulating real-world scenarios and practising with tools you’ll likely use in the role.
✨Tip Number 3
Showcase your problem-solving skills during interviews. Be ready to discuss past experiences where you identified vulnerabilities and how you tackled them. We love seeing candidates who can think on their feet!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows us you’re genuinely interested in joining the team at Elsevier.
We think you need these skills to ace Security Assurance Penetration Tester
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Security Assurance Penetration Tester role. Highlight your relevant experience in security, software development, and any certifications you hold. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how your background makes you a great fit for our team. Don’t forget to mention specific projects or experiences that showcase your expertise.
Showcase Your Technical Skills: In your application, be sure to highlight your proficiency with industry security testing tools and your scripting skills. We love seeing candidates who can demonstrate their technical know-how, especially in areas like SAST, DAST, and cloud security.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us that you’re genuinely interested in joining our team at StudySmarter!
How to prepare for a job interview at Elsevier
✨Know Your Stuff
Make sure you brush up on your security knowledge, especially around penetration testing techniques like SAST and DAST. Familiarise yourself with the tools mentioned in the job description and be ready to discuss how you've used them in past projects.
✨Showcase Your Problem-Solving Skills
Prepare to share specific examples of how you've identified vulnerabilities and proposed solutions in previous roles. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your analytical thinking.
✨Communicate Clearly
Since you'll be collaborating with various teams, practice explaining complex security concepts in simple terms. Be ready to demonstrate your communication skills, especially when discussing technical findings with non-technical stakeholders.
✨Ask Insightful Questions
At the end of the interview, have a few thoughtful questions prepared about the company's security practices or future projects. This shows your genuine interest in the role and helps you assess if the company is the right fit for you.