Senior Penetration Tester
Job description
Senior Penetration Tester at Bamboohr.
About the role
Bamboohr is seeking an experienced Senior Penetration Tester to join our dynamic team in either Glasgow or Reading, Berkshire. This full-time position is ideal for professionals who are passionate about cybersecurity and have a strong background in identifying vulnerabilities in various systems. As a Senior Penetration Tester, you will play a crucial role in enhancing our clients' security posture by conducting thorough assessments and providing actionable insights. Your expertise will help shape our security strategies and ensure that we remain at the forefront of the industry.
Key facts
What you'll do
- Conduct comprehensive penetration tests on web applications, networks, and mobile applications to identify security weaknesses and vulnerabilities.
- Develop and execute detailed testing plans and methodologies tailored to specific client requirements and industry standards.
- Collaborate with cross-functional teams, including developers and system administrators, to communicate findings and recommend effective remediation strategies.
- Prepare detailed reports that outline vulnerabilities, potential impacts, and prioritized recommendations for risk mitigation.
- Stay updated on the latest security threats, vulnerabilities, and penetration testing tools to ensure the use of best practices in assessments.
- Mentor and guide junior penetration testers, providing training and support to enhance their skills and knowledge in the field.
- Participate in security assessments for compliance with industry regulations and standards, such as PCI-DSS, ISO 27001, and GDPR.
- Engage with clients to understand their security needs and provide expert advice on improving their overall security posture.
- Conduct red teaming exercises to simulate real-world attack scenarios and assess the effectiveness of existing security measures.
- Collaborate with the incident response team to investigate security breaches and provide recommendations for future prevention.
- Contribute to the development of internal security tools and frameworks to streamline the penetration testing process.
- Present findings and recommendations to stakeholders in a clear and concise manner, ensuring that technical details are accessible to non-technical audiences.
Requirements
- A minimum of 5 years of experience in penetration testing or a related field, with a proven track record of successful assessments.
- Strong knowledge of various penetration testing methodologies, including OWASP, NIST, and PTES.
- Proficiency in using penetration testing tools such as Burp Suite, Metasploit, Nmap, and Wireshark.
- Experience with programming and scripting languages such as Python, Bash, or PowerShell to automate testing processes.
- Familiarity with network protocols, web application architectures, and security controls.
- Relevant certifications such as OSCP, CEH, or GPEN are highly desirable.
- Excellent analytical and problem-solving skills, with the ability to think critically and creatively to overcome challenges.
- Strong communication skills, both written and verbal, with the ability to convey complex technical information to diverse audiences.
- A proactive attitude towards learning and staying current with industry trends and emerging threats.
Nice to have
- Experience with cloud security assessments, particularly in AWS, Azure, or Google Cloud environments.
- Knowledge of secure coding practices and application security principles.
- Familiarity with threat modeling and risk assessment methodologies.
- Previous experience in a consulting role, working directly with clients to address their security concerns.
- Understanding of incident response processes and experience in handling security incidents.
Skills & tools
- Proficient in penetration testing frameworks and methodologies.
- Familiar with security assessment tools and software.
- Strong understanding of network security principles and practices.
- Experience with vulnerability management and remediation processes.
- Knowledge of compliance frameworks and regulations relevant to cybersecurity.
Practical notes
- This position is based in either Glasgow or Reading, Berkshire, and may require occasional travel to client sites.
- The salary for this role is competitive and commensurate with experience.
- Candidates must be eligible to work in the UK and may require sponsorship for a work visa, depending on their situation.
- The ideal candidate will demonstrate a commitment to continuous professional development and a passion for cybersecurity.
META
Company: Bamboohr
Title: Senior Penetration Tester
Listed
location: Glasgow or Reading, Berkshire
Job type: Full-time
Apply URL: https://fsp.bamboohr.com/careers/276