Penetration Tester
3 days ago
£42000–£48000 yearly
Full-time
London
Cyber Armed Security are seeking a skilled Penetration Tester to join their Cyber Security team. In this role, you will be responsible for simulating real-world attacks against our clients’ systems, applications, and infrastructure to identify vulnerabilities and provide actionable remediation advice. You will play a critical role in strengthening security postures, protecting sensitive data, and helping organisations meet compliance and regulatory requirements, the candidate must be highly self-motivated and confident to work efficiently alone. Key Responsibilities · Conduct penetration testing across networks, web applications, APIs, mobile applications, and cloud environments. · Perform vulnerability assessments and exploit weaknesses in a controlled, ethical manner. · Develop and deliver detailed technical reports and clear executive summaries for clients. · Provide expert advice on remediation strategies and security best practices. · Stay up to date with the latest exploits, attack vectors, tools, and methodologies. · Support Red Team and Purple Team engagements where required. · Collaborate with internal security teams, developers, and client stakeholders to improve overall security posture. Essential Skills & Experience · Minimum of 2 years of proven experience as a Penetration Tester, Ethical Hacker, or in a similar cyber security role. · Manual testing ability · Strong knowledge of penetration testing methodologies (e.g. OWASP, NIST). · Proficiency with common testing tools (e.g. Burp Suite, Metasploit, Nmap, Nessus, Kali Linux). · Solid understanding of networks, operating systems, web technologies, and cloud platforms (AWS, Azure, GCP). · Ability to write and deliver clear, professional reports. · Relevant industry certifications (e.g. OSCP, CREST CRT, CEH, GIAC GPEN) highly desirable. Desirable Skills · Experience with scripting/programming languages (Python, PowerShell, Bash, etc.). · Exposure to Red Team operations and threat emulation. · Familiarity with security compliance standards (ISO 27001, PCI-DSS, Cyber Essentials Plus). · Strong client-facing skills and ability to explain technical findings in non-technical terms.