Pen Tester - £100k - Remote

Pen Tester - £100k - Remote

Full-Time 43200 - 72000 £ / year (est.) No home office possible
H

At a Glance

  • Tasks: Conduct penetration testing and enhance security measures across IT infrastructure.
  • Company: Prestigious professional services organisation with a modern work culture.
  • Benefits: Competitive salary of £100k, remote work flexibility, and career growth opportunities.
  • Why this job: Join a top-rated team and make a real impact in the evolving field of information security.
  • Qualifications: Experience in security testing and red teaming; strong communication skills required.
  • Other info: Dynamic role with opportunities to collaborate on innovative security projects.

The predicted salary is between 43200 - 72000 £ per year.

Senior Pen Tester / Red Team Security Specialist

Remote or London Based (50%)

The Client

Based in London, my client is a prestigious professional services organisation boasting a workplace with cutting-edge people that is moving with the modern ways of working. Named as one of the leading professional services organisations places to work for three times in a row, the work environment attracts a seasoned professional who wants to be part of the best of breed.

Job Overview

This role reports to the Head of Information Security and requires a fast-learning and self-motivated individual to add capability and capacity to our small but highly effective team. Information Security is evolving to dynamic business needs, a rapidly changing threat environment, and the firm's own ambitious IT Strategy. This role will help play a key part in implementing and improving the underlying processes required to provide a structured, systematic, and audited approach to Information Security across the firm. The role will have clear areas of focus combined with periodic involvement in a broad spectrum of information security activities. This is a pivotal role within the Information Security Team.

The key tasks and responsibilities include, but are not limited to, the following:

  • Conduct thorough Red Team offensive penetration testing on our IT (on-prem and cloud) infrastructure to identify vulnerabilities and provide recommendations for remediation.
  • Perform security assessments on cloud-based applications, ensuring they adhere to industry standards and best practices.
  • Execute red team exercises to simulate real-world attack scenarios, testing the firm's detection and response capabilities both internal and external.
  • Assess and test the security of internally deployed infrastructure IoT devices and sensors, identifying potential vulnerabilities and ensuring they are secure.
  • Assess and test our SmartBuilding digital landscape and data lake.
  • Assess and test identified web-based APIs and applications for vulnerabilities and recommend where required actions to resolve the vulnerabilities.
  • Provide guidance to internal teams on API security testing and secure practices, as well as carrying out API security assessments.
  • Work with wider stakeholders on developing testing models for Generative A.I security.
  • Collaborate with cross-functional teams to implement security measures and enhance the firm's overall security posture.
  • Prepare detailed reports and presentations on findings, offering actionable insights to both technical and non-technical stakeholders.
  • Stay informed about the latest security trends, threats, and technologies to proactively address potential risks.
  • Assist in developing and maintaining security policies, procedures, and guidelines.
  • Serve as the key point of contact for all matters related to security testing engagement.
  • Collaborate with stakeholders to continually enhance efficiencies and maintain compliance with client and external audit requirements.
  • Utilise data and stakeholder feedback to drive continuous improvements in security testing.
  • Support the security team by focusing on key knowledge and behaviours, empowering colleagues to become informed security contacts within their teams and helping peers resolve security issues.
  • Research and analyse existing security policies, standards, and resources to identify areas where additional training or guidance is needed.
  • Participate in the evaluation, selection, and implementation of security testing technologies.
  • Stay informed about emerging threats and trends, integrating this knowledge into the security testing processes.
  • Support the firm's certification activities, such as ISO27001, SOC2, and Cyber Essentials Plus, by assisting with audits, documentation, and continuous improvement efforts.
  • Engage with security industry groups and collaborate with external industry partners to stay aligned with best practices and industry standards.

Qualifications

Your experience

The ideal candidate should possess comprehensive experience and knowledge in security testing and red teaming, with the ability to effectively communicate these concepts within the firm. The candidate should have a background in information security and be capable of conducting a wide range of security testing and red teaming activities, as well as providing advice and guidance to the business. This role will also involve coordinating external security requirements, identifying areas for continuous improvement in security services, and ensuring the effective execution of security testing and red team exercises. The candidate will address the evolving security needs of the business and should have a strong background in delivering actionable results.

The candidate must be able to quickly assimilate information to assess and document risks, engage with individuals at various levels of seniority, and balance the need to gather information. They should consistently demonstrate how Information Security aligns with the firm's business objectives and our clients' need for information assurance. An organised approach to managing and prioritising multiple concurrent assignments is essential.

A degree-level education is likely but not essential, as CREST/CHECK/OSCP/OSWE/OSWA status, and having various qualifications or full membership status with the IISP would be highly advantageous. This role may in the future expand to require security clearance. This role may expose the candidate to our external clients, so it is important that this candidate be able to maintain good working relations and strive to build bridges even in challenging circumstances.

Experience in developing and using structured documentation process, format, logical content, version control etc. is also important.

Pen Tester - £100k - Remote employer: Hybrid Global Solutions Limited

Join a prestigious professional services organisation that has been recognised as one of the best places to work for three consecutive years. With a commitment to cutting-edge technology and a dynamic work culture, this remote or London-based role offers exceptional opportunities for professional growth, collaboration with top-tier talent, and the chance to make a significant impact in the evolving field of Information Security. Enjoy a supportive environment that values innovation and continuous improvement, ensuring you thrive in your career while contributing to the firm's ambitious IT strategy.
H

Contact Detail:

Hybrid Global Solutions Limited Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Pen Tester - £100k - Remote

Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can sometimes lead to job opportunities that aren't even advertised.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your pen testing projects. This gives potential employers a taste of what you can do and sets you apart from the crowd.

Tip Number 3

Prepare for interviews by practising common questions and scenarios related to red teaming. We recommend doing mock interviews with friends or using online platforms to boost your confidence.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Pen Tester - £100k - Remote

Penetration Testing
Red Teaming
Cloud Security Assessments
API Security Testing
Vulnerability Assessment
Security Policy Development
Risk Assessment
Communication Skills
Collaboration
Continuous Improvement
ISO 27001
SOC2
Cyber Essentials Plus
Technical Documentation
Stakeholder Engagement

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Pen Tester role. Highlight your relevant experience in security testing and red teaming, and don’t forget to mention any specific tools or methodologies you’ve used that align with what we’re looking for.

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about information security and how your skills can help us tackle the evolving security landscape. Keep it concise but impactful!

Showcase Your Achievements: When detailing your experience, focus on your achievements rather than just responsibilities. Use metrics where possible to demonstrate the impact of your work, like how you reduced vulnerabilities or improved security measures.

Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you’re considered for the role without any hiccups!

How to prepare for a job interview at Hybrid Global Solutions Limited

Know Your Stuff

Make sure you brush up on your knowledge of penetration testing and red teaming. Familiarise yourself with the latest tools and techniques, especially those relevant to cloud security and IoT devices. Being able to discuss recent trends or vulnerabilities will show that you're not just knowledgeable but also passionate about the field.

Showcase Your Experience

Prepare to share specific examples from your past work that demonstrate your skills in conducting security assessments and red team exercises. Use the STAR method (Situation, Task, Action, Result) to structure your responses, making it easy for the interviewer to see how you've tackled challenges and delivered results.

Communicate Clearly

Since you'll be working with both technical and non-technical stakeholders, practice explaining complex security concepts in simple terms. This will help you convey your findings effectively and show that you can bridge the gap between different teams within the organisation.

Ask Insightful Questions

Prepare thoughtful questions about the company's security posture, their approach to emerging threats, and how they measure success in their security initiatives. This not only shows your interest in the role but also helps you gauge if the company aligns with your career goals and values.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

H
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>