Senior Penetration Tester in City of London
Senior Penetration Tester

Senior Penetration Tester in City of London

City of London Full-Time 48000 - 72000 Β£ / year (est.) No home office possible
J

At a Glance

  • Tasks: Conduct hands-on penetration testing to identify risks in critical applications and platforms.
  • Company: Join a leading firm focused on enhancing cybersecurity and resiliency.
  • Benefits: Competitive salary, health benefits, and opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: 3+ years of penetration testing experience and strong communication skills.
  • Other info: Collaborative environment with excellent career advancement opportunities.

The predicted salary is between 48000 - 72000 Β£ per year.

As an Assessments & Exercises Senior Associate in the Penetration Testing team, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. Your primary responsibility will be performing hands-on penetration testing of some of JPMC's most critical applications, platforms, and the perimeter. You will work with application developers to understand root causes and mitigate vulnerabilities, as well as identify where vulnerabilities can be detected earlier in the SDLC.

Successful candidates are expected to demonstrate an eagerness to learn, the drive to excel, excellent technical knowledge of security concepts, and proven expertise in penetration testing.

Job responsibilities:
  • Design and execute testing and simulations - such as penetration tests and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements.
  • Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation.
  • Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement.
  • Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management.
  • Engage with peers and industry groups that share threat intelligence analytics.
Required qualifications, capabilities, and skills:
  • 3+ years of experience in conducting manual penetration tests against a wide variety of applications and technologies including web, mobile and thick clients, internal and external facing infrastructures and cloud.
  • Foundational knowledge of cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies.
  • Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., OWASP Top Ten, NIST Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents.
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels.
Preferred qualifications, capabilities, and skills:
  • Experience in testing Public cloud environments like AWS, Azure and GCP with proficiency in at least one platform.
  • Experience in reverse engineering standalone, thick client and mobile applications.
  • Proficiency in security concepts for both Windows and Unix-like Operating Systems.
  • Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.).
  • Certifications like CREST (CRT, CCT), OSCP, OSCE, GXPN, GRE.

Senior Penetration Tester in City of London employer: JP Morgan

At JPMC, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. Our commitment to employee growth is evident through continuous learning opportunities and access to cutting-edge resources in cybersecurity. Located in a vibrant city, our team enjoys a supportive environment where meaningful contributions are recognised, making it an ideal place for passionate professionals looking to make a significant impact in the field of penetration testing.
J

Contact Detail:

JP Morgan Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land Senior Penetration Tester in City of London

✨Tip Number 1

Network, network, network! Get out there and connect with professionals in the cybersecurity field. Attend meetups, webinars, or conferences where you can chat with others who share your passion for penetration testing. You never know who might have a lead on your next job!

✨Tip Number 2

Show off your skills! Create a portfolio showcasing your penetration testing projects, including any simulations or assessments you've conducted. This will not only demonstrate your expertise but also give potential employers a taste of what you can bring to their team.

✨Tip Number 3

Don’t just apply blindly! Tailor your approach for each application by researching the company and its cybersecurity needs. When you reach out, mention specific projects or values that resonate with you. This shows you're genuinely interested and not just sending out cookie-cutter applications.

✨Tip Number 4

Keep learning and stay updated! The cybersecurity landscape is always changing, so make sure you're on top of the latest trends and tools. Join online forums, follow industry leaders, and consider getting certified. This not only boosts your knowledge but also makes you more attractive to potential employers.

We think you need these skills to ace Senior Penetration Tester in City of London

Penetration Testing
Cybersecurity Knowledge
Risk Management
Vulnerability Assessment
SDLC Understanding
Threat Intelligence
Report Writing
Collaboration Skills
Cloud Security (AWS, Azure, GCP)
Reverse Engineering
Source Code Review
Proficiency in Programming Languages (Python, Java, Rust)
Communication Skills
Offensive Testing Tools
Incident Response Methodologies

Some tips for your application 🫑

Tailor Your CV: Make sure your CV is tailored to the Senior Penetration Tester role. Highlight your experience with manual penetration tests and any relevant certifications. We want to see how your skills align with what we're looking for!

Show Off Your Skills: In your cover letter, don’t just list your qualificationsβ€”show us how you've applied them in real-world scenarios. Share specific examples of your work with penetration testing and how you’ve contributed to improving security postures.

Be Clear and Concise: When writing your application, keep it clear and to the point. Use straightforward language and avoid jargon unless it's necessary. We appreciate a well-structured application that’s easy to read!

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for the role. Don’t miss out on this opportunity!

How to prepare for a job interview at JP Morgan

✨Know Your Stuff

Make sure you brush up on your technical knowledge of penetration testing methodologies and tools. Be ready to discuss specific experiences where you've identified vulnerabilities and how you mitigated them. This shows not only your expertise but also your eagerness to learn and excel.

✨Showcase Your Collaboration Skills

Since the role involves working closely with application developers and cross-functional teams, prepare examples of how you've successfully collaborated in the past. Highlight any reports or assessments you've contributed to, and be ready to discuss how you influenced stakeholders with your findings.

✨Stay Current with Threat Intelligence

Familiarise yourself with the latest trends in cybersecurity threats and vulnerabilities. Bring up recent incidents or emerging threats during the interview to demonstrate your proactive approach to staying informed and how it can enhance the firm's assessment strategy.

✨Prepare for Scenario-Based Questions

Expect scenario-based questions that test your problem-solving skills in real-world situations. Think about how you would approach a penetration test for different environments, like cloud platforms or mobile applications, and be ready to articulate your thought process clearly.

Senior Penetration Tester in City of London
JP Morgan
Location: City of London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

J
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>