At a Glance
- Tasks: Conduct penetration testing and security assessments to identify vulnerabilities and enhance security measures.
- Company: Prestigious professional services organisation known for its cutting-edge workplace culture.
- Benefits: Competitive salary of £100k, remote work options, and opportunities for professional growth.
- Why this job: Join a dynamic team and make a real impact on information security in a rapidly evolving landscape.
- Qualifications: Experience in security testing and red teaming; relevant certifications are a plus.
- Other info: Collaborative environment with a focus on continuous improvement and career development.
The predicted salary is between 43200 - 72000 £ per year.
Based in London, my client is a prestigious professional services organisation boasting a workplace with cutting-edge people that is moving with the modern ways of working. Named as one of the leading professional services organisations places to work for three times in a row, the work environment attracts a seasoned professional who wants to be part of the best of breed.
Job Overview
This role reports to the Head of Information Security and requires a fast-learning and self-motivated individual to add capability and capacity to our small but highly effective team. Information Security is evolving to dynamic business needs, a rapidly changing threat environment. This role will help play a key part in implementing and improving the underlying processes required to provide a structured, systematic, and audited approach to Information Security. The role will have clear areas of focus combined with periodic involvement in a broad spectrum of information security activities. This is a pivotal role within the Information Security Team.
Key Responsibilities
- Conduct thorough Red Team offensive penetration testing on our IT (on-prem and cloud) infrastructure to identify vulnerabilities and provide recommendations for remediation.
- Perform security assessments on cloud-based applications, ensuring they adhere to industry standards and best practices.
- Execute red team exercises to simulate real-world attack scenarios, testing the firm's detection and response capabilities both internal and external.
- Assess and test the security of internally deployed infrastructure IoT devices and sensors, identifying potential vulnerabilities and ensuring they are secure.
- Assess and test our SmartBuilding digital landscape and data lake.
- Assess and test identified web-based APIs and applications for vulnerabilities and recommend where required actions to resolve the vulnerabilities.
- Provide guidance to internal teams on API security testing and secure practices, as well as carrying out API security assessments.
- Work with wider stakeholders on developing testing models for Generative A.I security.
- Collaborate with cross-functional teams to implement security measures and enhance the firm's overall security posture.
- Prepare detailed reports and presentations on findings, offering actionable insights to both technical and non-technical stakeholders.
- Stay informed about the latest security trends, threats, and technologies to proactively address potential risks.
- Assist in developing and maintaining security policies, procedures, and guidelines.
- Serve as the key point of contact for all matters related to security testing engagement.
- Collaborate with stakeholders to continually enhance efficiencies and maintain compliance with client and external audit requirements.
- Utilise data and stakeholder feedback to drive continuous improvements in security testing.
- Support the security team by focusing on key knowledge and behaviours, empowering colleagues to become informed security contacts within their teams and helping peers resolve security issues.
- Research and analyse existing security policies, standards, and resources to identify areas where additional training or guidance is needed.
- Participate in the evaluation, selection, and implementation of security testing technologies.
- Stay informed about emerging threats and trends, integrating this knowledge into the security testing processes.
- Support the firm's certification activities, such as ISO27001, SOC2, and Cyber Essentials Plus, by assisting with audits, documentation, and continuous improvement efforts.
- Engage with security industry groups and collaborate with external industry partners to stay aligned with best practices and industry standards.
Your Experience
The ideal candidate should possess comprehensive experience and knowledge in security testing and red teaming, with the ability to effectively communicate these concepts within the firm. The candidate should have a background in information security and be capable of conducting a wide range of security testing and red teaming activities, as well as providing advice and guidance to the business. This role will also involve coordinating external security requirements, identifying areas for continuous improvement in security services, and ensuring the effective execution of security testing and red team exercises. The candidate will address the evolving security needs of the business and should have a strong background in delivering actionable results.
The candidate must be able to quickly assimilate information to assess and document risks, engage with individuals at various levels of seniority, and balance the need to gather information. They should consistently demonstrate how Information Security aligns with the firm's business objectives and our clients' need for information assurance. An organised approach to managing and prioritising multiple concurrent assignments is essential.
A degree-level education is likely but not essential, as CREST/CHECK/OSCP/OSWE/OSWA status, and having various qualifications or full membership status with the IISP would be highly advantageous. This role may in the future expand to require security clearance.
Pen Tester - £100k in London employer: Hybrid Global Soultions
Contact Detail:
Hybrid Global Soultions Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Pen Tester - £100k in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can open doors that a CV just can't.
✨Tip Number 2
Show off your skills! Create a portfolio of your best penetration testing projects. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by practising common questions and scenarios related to red teaming. The more you rehearse, the more confident you'll feel when it’s showtime!
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities waiting for talented individuals like you. Plus, it’s the best way to ensure your application gets noticed.
We think you need these skills to ace Pen Tester - £100k in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Pen Tester role. Highlight your relevant experience in security testing and red teaming, and don’t forget to mention any certifications you have that align with the job description.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your skills can contribute to our team. Keep it concise but impactful!
Showcase Your Technical Skills: In your application, be sure to showcase your technical skills related to penetration testing and security assessments. Mention specific tools or methodologies you’ve used, as this will resonate well with us.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at Hybrid Global Soultions
✨Know Your Stuff
Make sure you brush up on your technical skills related to penetration testing and red teaming. Familiarise yourself with the latest tools and techniques in the industry, as well as any specific technologies mentioned in the job description, like cloud security and API testing.
✨Showcase Your Experience
Prepare to discuss your previous experiences in security testing and red teaming. Be ready to share specific examples of how you've identified vulnerabilities and provided actionable recommendations. This will demonstrate your ability to deliver results and align with the firm's objectives.
✨Communicate Clearly
Since you'll be working with both technical and non-technical stakeholders, practice explaining complex security concepts in simple terms. This will help you convey your findings effectively and show that you can bridge the gap between different teams.
✨Stay Current
Keep yourself updated on the latest trends and threats in information security. Being knowledgeable about emerging risks and best practices will not only impress your interviewers but also show your commitment to continuous improvement in the field.