Security Testing Analyst

Security Testing Analyst

Full-Time 30000 - 35000 £ / year (est.) No working from home possible
Oscar

At a Glance

  • Tasks: Conduct vulnerability assessments and penetration testing with hands-on experience.
  • Company: Established cyber security consultancy focused on growth and development.
  • Benefits: Competitive salary, funded certifications, mentoring, and hybrid working options.
  • Other info: Join a supportive team with a clear development path and excellent career opportunities.
  • Why this job: Gain real client exposure and progress based on your performance, not tenure.
  • Qualifications: 1-2 years in security testing or vulnerability assessment; familiarity with relevant tools.

The predicted salary is between 30000 - 35000 £ per year.

We are working with a well-established cyber security consultancy that is looking for a Security Testing Analyst to join their growing security testing team. This is a hands-on role with a clear development path - ideal for someone with around one to two years of experience in vulnerability assessment or junior penetration testing who wants structured progression toward deeper VAPT capability in a real client environment.

The consultancy works with clients across regulated industries and PE-backed businesses, delivering penetration testing, VAPT, GRC advisory, and AI security services. You'll be joining a team that invests in its people: mentoring, funded certifications, and a performance-based progression model, not a time-served one.

About the Role

The primary focus of the role is vulnerability assessment, external attack surface management, scan management, finding validation, and remediation follow-up. Alongside that, you'll be carrying out practical penetration testing activity - particularly across external infrastructure and internet-facing services - with direct mentoring from senior testers as you build out your capability. This isn't a role where you run a scan, export the report, and move on. You'll be expected to investigate findings properly, understand exploitability, reduce false positives, and produce technical summaries that hold up to scrutiny. The testing team operates to CREST methodology throughout. Early on the role will be office weighted so you can get comfortable with the team. Hybrid working will then be available once you are settled in.

What You’ll be Doing

  • Deliver VAPT, vulnerability assessment, and attack surface management services across a range of clients
  • Conduct security testing of external infrastructure and internet-facing services, including reconnaissance, enumeration, and vulnerability validation
  • Configure, schedule, and monitor vulnerability scans, maintaining accurate asset inventories and scope records
  • Triage and prioritise vulnerability findings, focusing on critical and high-severity issues
  • Validate findings using approved methods, assessing exploitability and business impact
  • Perform basic penetration testing activities under guidance, including reconnaissance and controlled validation
  • Support external attack surface reviews, identifying exposed assets and prioritising remediation
  • Produce clear summaries and documentation for internal teams, clients, and formal reports
  • Assist senior penetration testers with research, evidence collection, and report writing
  • Adhere to internal methodologies and industry frameworks, including NIST, OWASP, and CREST best practices

What They’re Looking For

  • 1–2 years’ experience in vulnerability assessment, security testing, or junior penetration testing
  • Good understanding of networking, operating systems, and web technologies (TCP/IP, DNS, HTTP/S, Linux, Windows)
  • Hands-on experience with vulnerability scanning tools such as Nessus, OpenVAS, AppCheck, or Qualys
  • Familiarity with penetration testing tools including Kali Linux, Nmap, Burp Suite, Metasploit, Nikto, and Gobuster
  • Understanding of CVEs, CVSS scoring, vulnerability prioritisation, and the OWASP Top 10
  • Ability to perform reconnaissance, enumeration, service analysis, and controlled validation of findings
  • Strong written communication skills with the ability to produce clear technical reports
  • Able to work methodically within defined scope and rules of engagement
  • Certs like CPSA, PenTest+, eJPT or PNPT are a nice bonus, as is lab time on HTB or TryHackMe.

Why This Role?

Funded certs, direct mentoring from experienced testers, real client exposure from day one, and progression that's based on what you deliver - not how long you've been there.

Security Testing Analyst employer: Oscar

Join a leading cyber security consultancy in London that prioritises employee development and offers a dynamic work culture. With a strong focus on mentoring, funded certifications, and a performance-based progression model, this role provides an excellent opportunity for growth in the field of security testing. Enjoy the benefits of hybrid working after settling in, while engaging in meaningful projects that directly impact clients across regulated industries.

Oscar

Contact Details:

Oscar Recruitment Team

We think you need these skills to ace Security Testing Analyst

Vulnerability Assessment
Penetration Testing
External Attack Surface Management
Vulnerability Scanning Tools (Nessus, OpenVAS, AppCheck, Qualys)
Penetration Testing Tools (Kali Linux, Nmap, Burp Suite, Metasploit, Nikto, Gobuster)
Networking Knowledge (TCP/IP, DNS, HTTP/S)
Operating Systems Knowledge (Linux, Windows)