At a Glance
- Tasks: Conduct exciting penetration tests and lead client engagements to identify security vulnerabilities.
- Company: Join a leading offensive security consultancy with a dynamic team of experts.
- Benefits: Enjoy a competitive salary, remote work, travel expenses, and bonus for site visits.
- Other info: Flexible roles available with excellent career growth and mentorship opportunities.
- Why this job: Make a real impact in cybersecurity while working on diverse and challenging projects.
- Qualifications: Must have CHECK/CREST qualifications and hands-on experience in penetration testing.
The predicted salary is between 55000 - 90000 £ per year.
Location: Fully Remote, UK (with client site visits as required)
Salary: £55,000 - £90,000 DOE + expenses + overnight bonus for site work
Type: Permanent, Full-Time
Summary: We are looking for experienced Penetration Testers to join one of the UK's larger dedicated offensive security practices. With a team of around 70 testers split across CHECK and CREST work, this is a well-established consultancy delivering high-quality assessments across a broad client base, with genuine variety in engagement type, sector, and technical depth. The team is structured across two streams, more commercially-driven engagements through CREST, and deeper, security-led work through CHECK, so there’s a clear path whichever direction you want to lean. Multiple roles are available across mid and senior levels, and the company is flexible on starting clearance level.
This role is fully remote with client site visits as required. No two weeks look the same.
Key Responsibilities:
- Deliver web application, API, and infrastructure penetration tests, taking ownership of engagements end-to-end from scoping through to final report delivery.
- Lead client-facing engagements, communicating high-risk findings as they are identified to support swift remediation.
- Produce clear, professional reports tailored to client-specific context and business risk.
- Support broader offensive security activities including red and purple team engagements, phishing simulations, and assumed-breach style assessments where relevant.
- Contribute to internal QA, mentor more junior consultants, and support report quality across the team.
- Stay up to date with the evolving threat landscape and contribute to internal R&D, tooling, and knowledge sharing.
Requirements:
- CHECK Team Member (CTM), CHECK Team Leader (CTL), CREST Registered Tester (CRT), or CREST Certified Tester (CCT) qualified, or actively progressing along either pathway at a senior level.
- Hands-on experience delivering web application, API, and/or infrastructure penetration tests in a professional consultancy setting.
- Strong understanding of common vulnerability classes (e.g. OWASP Top 10), exploitation techniques, and remediation guidance.
- Confident client-facing communication skills, with the ability to explain technical findings to both technical and non-technical audiences.
- Strong written reporting skills, with the ability to produce clear, well-structured deliverables.
- A genuine passion for offensive security, demonstrated through CTFs, labs (e.g. Hack The Box, TryHackMe), research, certifications, or community involvement.
Clearance:
Clearance requirements vary by role, some do not require any clearance, others are looking for SC or DV. The company will put successful candidates through the relevant clearance process where required, so existing clearance is welcomed but not essential across the board.
Benefits:
- Salary: £55,000 - £90,000, depending on experience, certifications and clearance level
- Fully remote working
- Overnight bonus for client site visits
- Travel and expenses covered for client work
- Clearance sponsorship (SC / DV) where required for the role
- Company pension scheme
Locations
Penetration Tester (CHECK / CREST) in Glasgow, North East employer: Oscar Associates (UK) Limited
Contact Detail:
Oscar Associates (UK) Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Penetration Tester (CHECK / CREST) in Glasgow, North East
✨Tip Number 1
Network like a pro! Reach out to fellow penetration testers and industry professionals on LinkedIn or at local meetups. Building connections can lead to job opportunities that aren't even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects, CTF achievements, or any relevant research. This gives potential employers a taste of what you can do beyond just a CV.
✨Tip Number 3
Prepare for interviews by brushing up on your client-facing communication skills. Practice explaining complex technical concepts in simple terms, as you'll need to convey findings to both tech-savvy and non-tech audiences.
✨Tip Number 4
Don't forget to apply through our website! We have multiple roles available, and applying directly can give you an edge. Plus, it shows you're genuinely interested in joining our awesome team!
We think you need these skills to ace Penetration Tester (CHECK / CREST) in Glasgow, North East
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Penetration Tester role. Highlight your relevant experience with web applications, APIs, and infrastructure tests, and don’t forget to mention any certifications like CHECK or CREST!
Show Off Your Skills: We want to see your passion for offensive security! Include any personal projects, CTFs, or labs you've participated in. This is your chance to showcase your hands-on experience and technical know-how.
Be Clear and Concise: When writing your application, keep it professional but straightforward. We appreciate clear communication, so make sure your reports and descriptions are well-structured and easy to understand, just like you would for a client.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and get the ball rolling on your journey to joining our awesome team.
How to prepare for a job interview at Oscar Associates (UK) Limited
✨Know Your Stuff
Make sure you brush up on your technical skills, especially around web application, API, and infrastructure penetration testing. Be ready to discuss specific vulnerabilities like those in the OWASP Top 10 and how you've tackled them in past projects.
✨Showcase Your Communication Skills
Since this role involves client-facing engagements, practice explaining complex technical findings in simple terms. Think of examples where you've had to communicate risks to non-technical stakeholders and how you made it clear and actionable.
✨Prepare for Scenario Questions
Expect scenario-based questions that test your problem-solving skills. Prepare to walk through how you would approach a penetration test from scoping to reporting, highlighting your thought process and decision-making at each stage.
✨Demonstrate Your Passion
Let your enthusiasm for offensive security shine through! Share your experiences with CTFs, labs, or any community involvement. This shows you're not just qualified but genuinely interested in the field, which can set you apart from other candidates.