At a Glance
- Tasks: Conduct diverse penetration tests and deliver findings to clients.
- Company: Join a dynamic security consultancy in London with a collaborative culture.
- Benefits: Enjoy hybrid work flexibility, competitive salary, and ongoing professional development.
- Why this job: Be part of a positively charged environment that values autonomy and mentorship.
- Qualifications: Strong knowledge of OWASP, offensive testing, and proficiency in key security tools required.
- Other info: Opportunity to mentor juniors and contribute to marketing materials.
The predicted salary is between 36000 - 60000 Β£ per year.
Job Title:
Penetration Tester
Role:
An exciting opportunity for a mid-level Penetration Tester to join a dynamic and collaborative security consultancy based in London. This role is ideal for a proactive individual with a hackerβs mindset and broad security testing experience across applications, networks, cloud platforms, and more.
You\’ll be a key player in delivering high-quality penetration tests while also supporting client advisory, team development, and process improvement.
Whatβs in it for you?
Autonomy and ownership in conducting diverse penetration testing engagements.
Ongoing professional development with access to industry events and training.
A positively charged work environment with flexibility for hybrid working post-probation.
Responsibilities:
Conduct web, mobile, API, infrastructure, cloud, and wireless penetration testing.
Create detailed technical reports and deliver test findings directly to clients.
Provide remediation advice and post-assessment consultancy.
Contribute to internal testing methodologies and Red Team/social engineering activities.
Mentor junior team members and support collaborative delivery of projects.
Occasionally support the creation of marketing materials such as research papers and articles.
Skills / Must have:
Strong knowledge of OWASP methodologies and offensive testing across black/grey/white-box approaches.
Proficiency in tools like Burp Suite, Kali, Nmap, Nessus, Qualys, Metasploit.
Familiarity with cloud platform security testing (AWS, Azure, GCP).
Understanding of mobile security (Android & iOS), networking protocols, and the OSI model.
Excellent verbal and written communication skills, especially for client-facing engagements.
Highly organised, analytical, and able to manage multiple projects independently.
Ability to explain technical risks to non-technical stakeholders and C-level executives.
SC Clearable
Desirable (βnice to haveβ) Skills:
Experience with programming, databases, and IoT security.
Exposure to CI/CD security, Docker/container security, and AI/LLM testing.
Hands-on experience with Red Teaming tools (e.g., Cobalt Strike) and social engineering.
Familiarity with bug bounty platforms and vulnerability disclosure best practices.
Benefits:
Competitive salary with regular performance reviews
Annual training and personal development plan
Access to conferences and professional events
Supportive and knowledgeable team culture
Hybrid work flexibility after probation
Salary:
Competitive (dependent on experience)
Mid-Level Penetration tester employer: Hamilton Barnes π³
Contact Detail:
Hamilton Barnes π³ Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Mid-Level Penetration tester
β¨Tip Number 1
Familiarise yourself with the latest OWASP methodologies and ensure you can discuss them confidently. Being able to articulate your understanding of these frameworks during interviews will demonstrate your expertise and proactive approach.
β¨Tip Number 2
Get hands-on experience with the tools mentioned in the job description, such as Burp Suite and Metasploit. Consider setting up a home lab or participating in Capture The Flag (CTF) challenges to showcase your practical skills.
β¨Tip Number 3
Network with professionals in the cybersecurity field by attending industry events or joining online forums. Building connections can lead to valuable insights and potential referrals for the role you're interested in.
β¨Tip Number 4
Prepare to discuss your previous penetration testing experiences in detail, focusing on specific projects where you provided remediation advice. Highlighting your ability to communicate technical risks to non-technical stakeholders will set you apart.
We think you need these skills to ace Mid-Level Penetration tester
Some tips for your application π«‘
Tailor Your CV: Make sure your CV highlights relevant experience in penetration testing, especially with tools like Burp Suite and Kali. Emphasise your knowledge of OWASP methodologies and any specific projects that showcase your skills.
Craft a Strong Cover Letter: In your cover letter, express your passion for cybersecurity and detail how your proactive approach aligns with the company's values. Mention specific experiences where you've successfully conducted penetration tests or mentored others.
Showcase Communication Skills: Since excellent verbal and written communication skills are crucial for this role, consider including examples of how you've effectively communicated technical risks to non-technical stakeholders in past roles.
Highlight Continuous Learning: Mention any ongoing professional development activities, such as attending industry events or training sessions. This shows your commitment to staying updated in the fast-evolving field of cybersecurity.
How to prepare for a job interview at Hamilton Barnes π³
β¨Showcase Your Technical Skills
Be prepared to discuss your experience with penetration testing tools like Burp Suite, Kali, and Nmap. Highlight specific projects where you've successfully applied these tools, as this will demonstrate your hands-on expertise.
β¨Understand the OWASP Methodologies
Familiarise yourself with OWASP methodologies and be ready to explain how youβve implemented them in past roles. This knowledge is crucial for a penetration tester and will show that youβre aligned with industry standards.
β¨Communicate Clearly
Since you'll be delivering findings to clients, practice explaining technical concepts in simple terms. Being able to convey complex information to non-technical stakeholders is a key skill that employers value.
β¨Demonstrate a Proactive Mindset
Share examples of how you've taken initiative in previous roles, whether itβs mentoring junior team members or contributing to process improvements. This will reflect your proactive attitude and fit with the company culture.