At a Glance
- Tasks: Conduct penetration testing and enhance security for digital services.
- Company: Join TLScontact, a leader in secure visa and immigration solutions.
- Benefits: Competitive salary, ongoing learning opportunities, and a collaborative culture.
- Other info: Remote work with excellent career growth potential.
- Why this job: Make a global impact by safeguarding sensitive data in a tech-driven environment.
- Qualifications: Experience in penetration testing and security tools; CREST certification required.
Join TLScontact – Secure the Future of Global Visa & Immigration Services! At TLScontact, we specialise in delivering seamless and secure visa and immigration solutions for governments and travellers worldwide. Security is at the heart of our digital transformation, and we are looking for a Security Testing Engineer (Pentester) to help safeguard our platforms and applications.
If you are passionate about penetration testing, vulnerability analysis, and secure development, this role is perfect for you! You will work closely with our software engineering teams to identify security risks, implement best practices, and enhance the security posture of our digital services.
Your Mission
- Perform offensive security testing (penetration testing) on web applications and services.
- Conduct manual and automated code analysis to detect vulnerabilities and non-trivial security issues.
- Support technical teams in resolving vulnerabilities and strengthening security measures.
- Develop and maintain security testing methodologies aligned with OWASP, NIST, and CIS Controls.
- Integrate security testing into the CI/CD pipeline to detect and fix vulnerabilities early.
- Ensure compliance with industry security regulations (PCI DSS, GDPR, HIPAA, SOC 2).
- Use PTES, MITRE ATT&CK, and CVSS scoring for standardized security assessments.
- Collaborate with developers and QA teams to build comprehensive security test strategies.
- Provide detailed security reports, analyze trends, and propose continuous improvements.
What You Bring to TLScontact
- Experience in penetration testing and security testing.
- Hands-on expertise with security tools (Burp Suite, OWASP ZAP) and scripting languages (Python, Bash, PowerShell, Metasploit, Checkmarx).
- Experience with CI/CD tools (GitLab, Jenkins, GitHub Actions).
- Deep understanding of secure software development lifecycle (SDLC).
- Strong problem-solving skills with high attention to detail.
- Excellent communication skills to collaborate with technical and non-technical teams.
- English fluency (B2 level or higher).
- CREST Registered certification required.
Why TLScontact?
- Global Impact – Work on security solutions that protect sensitive visa and immigration data.
- Innovative Environment – Be part of a tech-driven organization committed to security and excellence.
- Career Growth – Access ongoing learning opportunities, certifications, and professional development.
- Collaborative Culture – Join a diverse and skilled team that values knowledge-sharing and teamwork.
- Competitive Package – Enjoy an attractive salary and benefits package.
Ready to make an impact in global security? Apply now and help TLScontact shape a secure digital future!
At TLScontact, we are proud to foster an inclusive work environment where diversity is celebrated and valued. We are committed to equal employment opportunities and pay parity, regardless of factors like race, religion, gender, or disability.
Please note that all successful applicants will be required to undergo an enhanced level Criminal Record disclosure.
Join us on our mission to redefine global visa and consular services – apply now and embark on a rewarding journey with TLScontact!
Please note TLScontact is unable to sponsor those without permission to work in the UK, therefore any applicant must already have permission to work in the UK. All successful applicants will need to apply for and pass a Criminal Record disclosure - enhanced level. Under The Immigration, Asylum and Nationality Act 2006, you must have the right to work in the United Kingdom to be considered for this role.
Security Testing Engineer - CREST Certified employer: TLScontact
At TLScontact, we pride ourselves on being an exceptional employer, offering a dynamic and inclusive work environment in the heart of Manchester. As a People Operations Specialist, you will have the opportunity to make a significant impact on employee experience while enjoying a hybrid working pattern that promotes work-life balance. Our commitment to professional development, diversity, and a collaborative culture ensures that every team member can thrive and grow within our organisation.
StudySmarter Expert Advice🤫
We think this is how you could land Security Testing Engineer - CREST Certified
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including TLScontact, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through TLScontact
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at TLScontact. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Testing Engineer - CREST Certified
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at TLScontact insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to TLScontact that you’re committed to staying ahead in the game.
How to prepare for a job interview at TLScontact
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at TLScontact to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at TLScontact.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.