Posted 04 August, 2026
Penetration Tester
Big Red Recruitment
London, ENG, GB
Full Time
Job Description
We are seeking a Penetration Tester to join a growing Offensive Security team within a specialist cyber security consultancy. This is an exciting opportunity to join at a time of significant investment and growth, helping to strengthen existing testing services while contributing to the development of new capabilities across areas such as Red Teaming, Operational Technology (OT), Threat-Led Security Testing and emerging technologies. The successful candidate will play a key role in delivering penetration testing engagements, supporting process improvement initiatives, and helping to build a scalable and mature testing function. This position offers excellent opportunities for professional development, certification support and future progression into senior or leadership positions.JOB ROLE - PENETRATION TESTERLOCATION - LONDON (OCCASIONAL ON-SITE WORK)SALARY - £40,000-£45,000 + BENEFITSKey Responsibilities\n
- \n
- Conduct vulnerability assessments and penetration testing engagements across: \n
- \n
- Internal infrastructure \n
- External infrastructure \n
- Web applications \n
- Networks and systems \n
\n - Perform configuration and build reviews using recognised security frameworks and benchmarks. \n
- Produce clear, concise and actionable technical reports detailing findings, risk ratings and remediation recommendations. \n
- Utilise industry-standard security testing tools including Burp Suite, Nessus, Metasploit, Nmap, Wireshark and related technologies. \n
- Work directly with clients and stakeholders, presenting findings and providing remediation guidance where required. \n
- Support the continuous improvement of testing methodologies, processes and documentation. \n
- Assist in creating and maintaining standard operating procedures, testing guides and knowledge-sharing materials. \n
- Collaborate with wider cyber security teams to support service development and research initiatives. \n
- Contribute to research and development activities across new security testing disciplines and technologies. \n
- Participate in occasional out-of-hours and on-site engagements where client requirements dictate. \n
- \n
- Minimum 2 years' experience in penetration testing, vulnerability assessment or offensive security. \n
- Experience conducting: \n
- \n
- Internal and external infrastructure testing \n
- Web application security testing \n
- Security assessments and audits \n
- Vulnerability identification and validation \n
\n - Strong understanding of networking concepts, protocols, routing and firewall technologies. \n
- Experience working with Windows, Linux and macOS environments. \n
- Familiarity with security assessment tools such as: \n
- \n
- Burp Suite \n
- Nessus \n
- Metasploit \n
- Nmap \n
- Wireshark \n
\n - Experience producing high-quality technical reports and client-facing documentation. \n
- Excellent communication and stakeholder management skills. \n
- Strong organisational skills and ability to manage workload independently. \n
- Comfortable working in a consultancy or client-facing environment. \n
- Eligible to obtain UK Security Clearance. \n
- \n
- CREST CRT, CPSA, CCT or equivalent certification. \n
- OSCP or similar offensive security qualification. \n
- Cyber Scheme accreditation. \n
- CHECK Team Member status. \n
