At a Glance
- Tasks: Conduct penetration tests and security assessments to protect clients from cyber threats.
- Company: Join Goaco, a forward-thinking tech company focused on innovative software solutions.
- Benefits: Competitive salary, performance incentives, and ongoing training for career growth.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: 4+ years in cybersecurity, with hands-on experience in penetration testing and incident response.
- Other info: Collaborative culture that values work-life balance and supports your professional development.
The predicted salary is between 36000 - 60000 £ per year.
Get AI-powered advice on this job and more exclusive features.
Goaco is looking to build a team to continue solving problems using software and technology for our clients. We are developers at heart – and by the mind too. We thrive on challenges and live for logical thinking. Formed over a decade ago, we have built on our successes, all of whom have benefitted from their level-headed software solutions. The team is all like-minded individuals, with a drive to succeed in their own fields.
Overview
ROLE OBJECTIVE
We are seeking a highly skilled Penetration Tester with a strong background in penetration testing and network security. This role is ideal for a cybersecurity professional with experience in identifying, assessing, and mitigating security risks across various platforms. The candidate will play a critical role in evaluating and strengthening our clients’ cybersecurity postures by conducting in-depth security assessments, vulnerability analysis, and developing comprehensive security strategies. The successful candidate will work closely with the Global Director of Cyber Security to grow and develop the Penetration Testing capability here at Goaco, fostering a culture of technical excellence and high calibre outcomes.
Responsibilities
- Conduct comprehensive penetration tests, vulnerability assessments, and security audits to identify risks and ensure compliance with industry best practices.
- Provide expert recommendations and solutions to mitigate identified vulnerabilities, enhancing client systems’ security postures.
- Investigate alerts and suspicious activity to determine if an incident has occurred.
- Contain affected systems and networks to prevent the incident from spreading.
- Implement temporary measures to mitigate the impact of the incident.
- Work with other teams, such as IT and security operations, to develop and implement a containment strategy.
- Analyse incident data to determine the root cause of the incident and identify recommendations for improvement.
- Document and report incidents to the incident response team and other relevant stakeholders.
- Develop and implement security plans, policies, and training to prepare the organization to respond efficiently and effectively to cyber threats.
- Travel to various client locations when required (potential international travel) and deliver high quality solutions (e.g. OT testing or other IT services).
- Collaborate with client teams to develop, document, and implement security policies, standards, and guidelines aligned with industry standards (e.g., ISO 27001, NIST).
- Assist in the deployment, configuration, and management of security infrastructure and technologies, including firewalls, intrusion detection/prevention systems, and secure network architectures.
- Provide guidance and support on Azure security practices, leveraging expertise in Microsoft Azure security frameworks and best practices.
- Stay updated with the latest cybersecurity threats, trends, and regulatory changes, proactively advising clients on necessary adjustments to their security strategies.
- Produce detailed and accurate reports on penetration testing findings, including risk levels, remediation steps, and strategic recommendations.
Experience
- Minimum of 4+ years of experience in cybersecurity, specifically in penetration testing and incident response, vulnerability management, and risk assessment.
- Public Sector experience, ideally MOD, MOJ.
- Must be SC clearable.
- Proven hands-on experience with tools such as Metasploit, Burp Suite, Nessus, and Wireshark.
- Strong understanding of network protocols, firewall configurations, and secure network design.
- Proficiency in scripting languages (e.g., Python, Bash, PowerShell) to automate tasks and streamline processes.
- Hands-on experience of vulnerability assessments, incident response, penetration testing, threat hunting and compromise assessment.
- Experience collaborating with Sales teams as a pre-sales cyber security consultant.
- Experience working in Energy or Construction industry projects is a plus.
- Experience in writing technical proposals along with other teams to deliver robust statement of works for client sign off.
Certifications
- CCNP/CCNA is nice to have.
- CREST/OSCP is nice to have.
- Microsoft and/or other cloud providers.
Skills
- Working knowledge of cloud security architecture, specifically within Azure (or other Cloud platforms).
- Familiarity with security frameworks and compliance standards such as NIST, GDPR, PCI-DSS, DESC ISR.
- Strong problem-solving skills, with the ability to think creatively to solve complex security challenges.
Benefits
- Competitive Salary: Base salary commensurate with experience, plus performance-based incentives.
- Career Progression: Clear pathways for career development and progression within the company.
- Training & Development: Ongoing training and development opportunities to help you grow in your role.
- Supportive Culture: Join a collaborative, friendly, and ambitious team that values work-life balance.
#J-18808-Ljbffr
Penetration Testing (CREST / CHECK) employer: Goaco
Contact Detail:
Goaco Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Penetration Testing (CREST / CHECK)
✨Network Like a Pro
Get out there and connect with people in the cybersecurity field! Attend meetups, conferences, or even online webinars. Building relationships can lead to job opportunities that aren’t even advertised yet.
✨Show Off Your Skills
Create a portfolio showcasing your penetration testing projects. Whether it’s a blog, GitHub repo, or a personal website, let your work speak for itself. This is a great way to demonstrate your expertise to potential employers.
✨Ace the Interview
Prepare for technical interviews by brushing up on common penetration testing scenarios and tools like Metasploit and Burp Suite. Practice explaining your thought process clearly, as communication is key in this field.
✨Apply Through Us!
Don’t forget to check out our website for openings at Goaco. Applying directly through us not only shows your interest but also gives you a chance to stand out in the application process!
We think you need these skills to ace Penetration Testing (CREST / CHECK)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Penetration Testing role. Highlight your relevant experience, especially in cybersecurity and penetration testing. We want to see how your skills align with what we’re looking for!
Showcase Your Skills: Don’t just list your skills; demonstrate them! Use specific examples of tools like Metasploit or Burp Suite that you’ve used in past roles. This helps us understand your hands-on experience and technical prowess.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Explain why you’re passionate about cybersecurity and how you can contribute to our team at Goaco. Keep it engaging and relevant to the role.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!
How to prepare for a job interview at Goaco
✨Know Your Tools
Familiarise yourself with the tools mentioned in the job description, like Metasploit and Burp Suite. Be ready to discuss your hands-on experience with these tools and how you've used them in past projects.
✨Showcase Your Problem-Solving Skills
Prepare examples of complex security challenges you've faced and how you creatively solved them. This role thrives on logical thinking, so demonstrating your analytical skills will impress the interviewers.
✨Understand the Company’s Needs
Research Goaco and their approach to cybersecurity. Tailor your responses to show how your skills can specifically help them strengthen their clients' security postures. Mention any relevant experience in sectors like Energy or Construction.
✨Prepare for Scenario-Based Questions
Expect questions that assess your incident response capabilities. Think through potential scenarios where you had to contain a security incident and be ready to explain your thought process and actions taken.