We are seeking a Cyber Security Consultant (Penetration Tester) to assess the security of applications, infrastructure, networks and... Read more
We are seeking a Cyber Security Consultant (Penetration Tester) to assess the security of applications, infrastructure, networks and cloud environments. You will plan and deliver penetration tests, vulnerability assessments and security reviews, identifying weaknesses that could be exploited by malicious actors. The role involves defining test scopes, selecting appropriate methodologies, conducting technical assessments, and producing clear, evidence-based reports for both technical and non-technical audiences.
You will be responsible for performing infrastructure, web application, mobile application, API, wireless and cloud penetration testing, as well as red team or assumed-breach activities where required. Duties will include reconnaissance, vulnerability analysis, exploitation, privilege escalation, post-exploitation testing and risk validation, while ensuring all activity is conducted safely and within agreed rules of engagement. You will collaborate with clients and internal stakeholders to explain findings, prioritise remediation and provide practical recommendations. You may also support security architecture reviews, threat modelling, remediation verification and the development of testing methodologies, tools and reusable scripts.
The successful candidate will have demonstrable experience in penetration testing or a closely related cyber security role, with a strong understanding of common attack techniques, security controls and industry frameworks such as OWASP, PTES, NIST and MITRE ATT&CK. Practical knowledge of operating systems, networking, Active Directory, cloud platforms, scripting and tools such as Burp Suite, Nmap, Metasploit and relevant vulnerability scanners is expected. Professional certifications such as CREST, OSCP, OSWE, GPEN or equivalent are desirable. Strong written and verbal communication skills, sound judgement, attention to detail and the ability to manage multiple engagements are essential. A commitment to ethical conduct, continuous learning and maintaining current knowledge of emerging threats is required.
Read lessLondon, England, United KingdomPermanent
We are seeking an Associate Cyber Security Tester to support the delivery of high-quality security assessments across applications,... Read more
We are seeking an Associate Cyber Security Tester to support the delivery of high-quality security assessments across applications, infrastructure, networks and cloud environments. This is an excellent opportunity for someone developing their career in cyber security who is keen to apply technical knowledge, build practical testing experience and contribute to the identification and remediation of security weaknesses. You will work as part of a collaborative testing team, following established methodologies while developing your skills across a varied range of assignments.
Your responsibilities will include assisting with penetration tests and vulnerability assessments, reviewing technical and functional requirements, preparing test plans and documenting findings clearly and accurately. You will help identify vulnerabilities through manual testing and the use of appropriate security tools, validate remediation activities and support the production of client-ready reports. You may also contribute to security reviews, threat modelling, configuration assessments and internal knowledge-sharing activities. The role requires careful handling of sensitive information, strong attention to detail and the ability to communicate technical issues to both technical and non-technical audiences.
Applicants should have a foundation in cyber security, information technology or a related discipline, together with an understanding of common vulnerabilities, security principles and testing techniques. Familiarity with frameworks such as OWASP, NIST or PTES, and experience with tools used for web application, network or vulnerability testing, would be advantageous. Relevant qualifications or certifications, such as Security+, eJPT, CRT or equivalent practical experience, are welcome but not essential. You should be curious, methodical and committed to continuous learning, with the ability to work independently while contributing positively to a team. A professional approach, good written communication skills and a willingness to develop within a fast-paced technical environment are essential.
Read lessLondon, England, United KingdomPermanent
We are seeking a Senior Cybersecurity Tester/Researcher to lead advanced security assessments, identify emerging threats, and strengthen the... Read more
We are seeking a Senior Cybersecurity Tester/Researcher to lead advanced security assessments, identify emerging threats, and strengthen the resilience of complex technology environments. In this role, you will plan and execute penetration tests, red team exercises, vulnerability assessments, and adversary simulations across networks, applications, cloud platforms, APIs, endpoints, and infrastructure. You will assess security controls, investigate weaknesses, validate exploitability, and clearly communicate technical findings to both specialist and non-specialist audiences.
Key responsibilities include developing testing methodologies and rules of engagement, conducting manual and automated security testing, researching new attack techniques, and creating proof-of-concept exploits where appropriate. You will analyse attack paths, document evidence, rate risks, and provide practical remediation guidance. The role will also involve maintaining and improving testing tools, scripts, and laboratory environments; contributing to threat intelligence activities; supporting incident investigations; and collaborating with engineering, architecture, and risk teams to embed security throughout the development and operational lifecycle. You may also mentor junior testers and contribute to security standards, procedures, and knowledge-sharing initiatives.
The successful candidate will have substantial experience in penetration testing, offensive security, vulnerability research, or a closely related discipline, together with strong knowledge of network, web application, cloud, operating system, and identity security. Proficiency with scripting or programming languages such as Python, PowerShell, Bash, or JavaScript is expected, along with practical experience using industry-standard security testing and analysis tools. Relevant professional certifications are desirable, such as OSCP, CREST, GXPN, OSEP, or equivalent qualifications. You should demonstrate sound judgement, curiosity, attention to detail, and the ability to work independently on sensitive assignments. Strong written and verbal communication skills are essential, as is a commitment to ethical testing, responsible disclosure, confidentiality, and continuous professional development.
Read lessTeddington, England, United KingdomPermanent
We are seeking an AI Security Tester to assess the security, reliability, and resilience of artificial intelligence systems... Read more
We are seeking an AI Security Tester to assess the security, reliability, and resilience of artificial intelligence systems across their full development lifecycle. You will design and execute adversarial tests against machine learning models, generative AI applications, data pipelines, APIs, and supporting infrastructure. Your work will help identify vulnerabilities such as prompt injection, data leakage, insecure model configurations, adversarial manipulation, poisoning, excessive permissions, unsafe outputs, and weaknesses in authentication or access controls.
In this role, you will create realistic threat scenarios, develop test cases, automate security assessments, and analyse results to determine business and technical impact. You will collaborate with software engineers, data scientists, security specialists, and product teams to validate mitigations and ensure issues are resolved effectively. Responsibilities will include reviewing system architectures and code, conducting penetration tests, evaluating third-party AI components, documenting findings, and producing clear reports for both technical and non-technical stakeholders. You may also contribute to security standards, testing methodologies, risk assessments, incident investigations, and continuous monitoring of AI-enabled services.
The successful candidate will have experience in application security, penetration testing, red teaming, or security research, together with a strong understanding of AI and machine learning concepts. Practical knowledge of Python and common security testing tools is expected, along with familiarity with web applications, APIs, cloud environments, identity and access management, and secure software development practices. Experience testing large language models, retrieval-augmented generation systems, model endpoints, or AI agents would be advantageous. You should be analytical, curious, and comfortable working independently while communicating complex findings clearly. Relevant professional certifications or demonstrable contributions to security research, vulnerability disclosure, or open-source testing tools are desirable.
Read lessReading, England, United KingdomPermanent
We are seeking a Cybersecurity Tester/Researcher to assess the security of applications, infrastructure, networks and emerging technologies. The... Read more
We are seeking a Cybersecurity Tester/Researcher to assess the security of applications, infrastructure, networks and emerging technologies. The successful candidate will plan and execute authorised security assessments, identify vulnerabilities, validate their impact and communicate practical recommendations to improve resilience. This role will involve a combination of hands-on testing, technical research and collaboration with engineering, operations and risk teams.
Responsibilities include conducting penetration tests, vulnerability assessments, security reviews and targeted research across web applications, APIs, mobile platforms, cloud environments, operating systems and networks. You will develop test plans and tooling, perform reconnaissance and exploitation within approved boundaries, analyse findings, and produce clear reports for both technical and non-technical audiences. You will also support remediation activities by explaining root causes, recommending appropriate controls and verifying that issues have been effectively resolved. Staying current with threat intelligence, attack techniques, security tools and relevant standards will be an important part of the role, as will contributing to improvements in testing methodologies and internal security practices.
Applicants should have professional experience in penetration testing, cybersecurity research, vulnerability analysis or a closely related discipline. Strong knowledge of common web and network vulnerabilities, authentication mechanisms, secure coding principles, cloud security and recognised frameworks such as OWASP is expected. Experience with tools such as Burp Suite, Nmap, Metasploit, Wireshark or comparable platforms is desirable, along with the ability to script in Python, PowerShell, Bash or another relevant language. Industry certifications such as OSCP, CREST, GPEN or equivalent are beneficial but not essential. You should demonstrate sound judgement, investigative thinking, attention to detail and a responsible approach to handling sensitive information. Excellent written and verbal communication skills are required, together with the ability to work independently and collaboratively in a changing technical environment.
Read lessTeddington, England, United KingdomPermanent
We are seeking a Cybersecurity Tester/Researcher to assess the security of applications, infrastructure, networks, and emerging technologies. The... Read more
We are seeking a Cybersecurity Tester/Researcher to assess the security of applications, infrastructure, networks, and emerging technologies. The successful candidate will plan and conduct penetration tests, vulnerability assessments, security reviews, and controlled attack simulations across web, mobile, cloud, API, and enterprise environments. You will identify weaknesses, validate their impact, and provide clear, evidence-based recommendations that help strengthen security controls and reduce operational risk.
Responsibilities include defining test scope and methodologies, performing manual and automated security testing, researching new vulnerabilities and attack techniques, developing proof-of-concept exploits where appropriate, and analysing security events or suspected compromises. You will document findings in detailed technical reports, prioritise issues according to likelihood and business impact, and present results to both technical and non-technical stakeholders. The role also involves maintaining testing tools and scripts, contributing to threat modelling and security standards, supporting remediation activities, and staying informed about developments in offensive security, vulnerability research, cloud technologies, and regulatory expectations.
Applicants should have practical experience in penetration testing, vulnerability research, application security, or a closely related cybersecurity discipline. Strong knowledge of common attack methods, network protocols, operating systems, authentication mechanisms, secure coding principles, and security testing frameworks is required. Experience with tools such as Burp Suite, Nmap, Metasploit, Wireshark, or equivalent technologies is desirable, as is proficiency in scripting or programming languages such as Python, PowerShell, Bash, or JavaScript. Professional certifications including OSCP, CREST, GPEN, GWAPT, or comparable qualifications are advantageous. You should demonstrate sound analytical judgement, careful attention to detail, strong written and verbal communication skills, and the ability to work independently while collaborating effectively with wider technical teams. All testing must be conducted responsibly, ethically, and in accordance with agreed authorisation and data-handling requirements.
Read lessSolihull, England, United KingdomPermanent
We are seeking a Manager, Senior Red Team Operator, Global to lead sophisticated offensive security activities across a... Read more
We are seeking a Manager, Senior Red Team Operator, Global to lead sophisticated offensive security activities across a complex, international environment. This role will manage and participate in authorised red team operations designed to identify weaknesses in people, processes, applications, infrastructure, cloud services and physical security controls. You will develop realistic, intelligence-led attack scenarios, define objectives and rules of engagement, coordinate activity across regions, and ensure operations are conducted safely, discreetly and in accordance with legal, regulatory and ethical requirements.
You will lead engagements from initial planning through execution, evidence collection, impact assessment and remediation validation. Responsibilities include translating threat intelligence into adversary emulation plans; conducting network, cloud, application, identity and social engineering assessments; directing covert operations; maintaining detailed operational documentation; and presenting clear findings to technical teams, senior leadership and risk stakeholders. You will mentor experienced operators, support capability development, contribute to tooling and tradecraft improvements, and work closely with defensive security teams to strengthen detection, response and resilience. The role may require collaboration across multiple time zones and occasional international travel.
Applicants should have substantial experience in red teaming, penetration testing, adversary emulation or a closely related offensive security discipline, including a strong understanding of modern attack techniques, threat actor behaviours and defensive countermeasures. Proven experience leading complex engagements and handling sensitive information is essential. Strong technical capability across areas such as Active Directory, identity and access management, cloud platforms, scripting, network security, web applications and endpoint environments is highly desirable. Relevant professional certifications are beneficial, but demonstrated expertise and sound judgement are equally important. Excellent written and verbal communication, stakeholder management, discretion, curiosity and the ability to operate independently in ambiguous situations are required. This position is suited to a calm, ethical security professional who can combine hands-on technical leadership with strategic thinking.
Read lessCardiff, Wales, United KingdomPermanent
We are seeking an Alignment Red Team Research Engineer/Research Scientist to investigate how advanced AI systems can fail,... Read more
We are seeking an Alignment Red Team Research Engineer/Research Scientist to investigate how advanced AI systems can fail, be misused, or behave unexpectedly under challenging conditions. You will design and conduct rigorous adversarial evaluations of models, agents, and safety mechanisms, with the goal of identifying vulnerabilities before they create meaningful real-world risks. The role combines scientific research, engineering, critical thinking, and practical experimentation in a highly collaborative environment.
Your responsibilities will include developing threat models and evaluation methodologies; creating adversarial prompts, scenarios, tools, and test environments; probing models for deceptive, unsafe, biased, or otherwise misaligned behaviour; and building automated pipelines to support large-scale red-team exercises. You will analyse results, distinguish genuine failures from artefacts, document reproducible findings, and communicate their significance to technical and non-technical audiences. You may also contribute to mitigations, safety benchmarks, model monitoring approaches, and research publications or internal reports. The work may involve exploring capability elicitation, agentic behaviour, instruction following, reward hacking, situational awareness, scalable oversight, and security or privacy risks.
We are looking for candidates with experience in machine learning, software engineering, AI safety, cybersecurity, formal methods, or a closely related field. Strong programming skills, particularly in Python, and the ability to work effectively with modern AI models and evaluation tooling are expected. You should be comfortable designing experiments under uncertainty, reasoning about adversarial behaviour, and turning ambiguous questions into clear, testable investigations. Research experience demonstrated through publications, substantial independent projects, or equivalent practical work is valuable, as is familiarity with language models, reinforcement learning, agent systems, or security testing. Curiosity, intellectual honesty, careful documentation, and the ability to collaborate across disciplines are essential. Candidates from non-traditional backgrounds are encouraged to apply if they can demonstrate relevant expertise and a strong commitment to improving the safety and reliability of advanced AI systems.
Read lessLondon, England, United KingdomPermanent
We are seeking an experienced Principal Penetration Tester for a 12-month fixed-term contract. This is a senior technical... Read more
We are seeking an experienced Principal Penetration Tester for a 12-month fixed-term contract. This is a senior technical role responsible for planning and delivering high-quality penetration testing and security assessment engagements across applications, infrastructure, cloud environments, networks, APIs, mobile platforms and emerging technologies. You will work with technical and business stakeholders to understand risk, define appropriate testing approaches and provide practical, evidence-based recommendations that strengthen security resilience.
Your responsibilities will include leading complex penetration tests from scoping and threat modelling through to exploitation, reporting and remediation support. You will identify and validate vulnerabilities, assess their potential business impact, and produce clear reports suitable for both technical and executive audiences. You will also provide mentoring and technical guidance to other testers, contribute to the development of testing methodologies and tooling, support quality assurance activities, and help improve the wider security assessment service. Where appropriate, you may represent the testing function in security reviews, risk discussions and remediation planning sessions.
Applicants should have substantial professional experience in penetration testing, red teaming or an equivalent offensive security role, together with a strong understanding of common attack techniques, security controls and vulnerability management. Demonstrable expertise in areas such as web application, API, network, cloud or Active Directory testing is required, along with the ability to script or automate tasks using languages such as Python, PowerShell or Bash. Industry-recognised certifications such as OSCP, CREST, GXPN, GPEN or equivalent are desirable. You will need excellent written and verbal communication skills, strong report-writing ability, sound judgement and a methodical approach to managing multiple engagements. The successful candidate must be comfortable working independently, handling sensitive information responsibly and collaborating effectively with colleagues and stakeholders at all levels.
Read lessWatford, England, United KingdomPermanent
We are seeking an experienced Penetration Testing Engineer at Vice President level to lead and deliver sophisticated security... Read more
We are seeking an experienced Penetration Testing Engineer at Vice President level to lead and deliver sophisticated security assessments across applications, infrastructure, cloud environments, networks, and emerging technologies. The successful candidate will combine strong technical expertise with strategic leadership, helping to identify and communicate security risks before they can be exploited. This role requires an individual who can operate independently, influence senior stakeholders, and contribute to the continued development of a high-performing offensive security function.
Responsibilities will include planning and executing red team exercises, penetration tests, vulnerability assessments, and adversary simulation engagements. You will assess complex environments, develop attack paths, validate security controls, and produce clear, evidence-based reports with practical remediation guidance. The role will also involve presenting findings to technical and executive audiences, mentoring junior and senior testers, reviewing assessment quality, improving methodologies, and supporting the development of automated tools and repeatable testing processes. You may also contribute to threat modelling, security architecture reviews, incident response investigations, and regulatory or audit-related activities.
Applicants should have significant professional experience in penetration testing, red teaming, or offensive security, together with a strong understanding of networks, operating systems, web applications, APIs, cloud platforms, identity systems, and common security frameworks. Proficiency with scripting or programming languages such as Python, PowerShell, Bash, or similar is expected. Experience with tools including Burp Suite, Metasploit, Nmap, BloodHound, Cobalt Strike, or comparable technologies is highly desirable. Industry certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, CREST, or equivalent practical experience are advantageous. Excellent written and verbal communication, sound judgement, leadership capability, and the ability to manage multiple priorities are essential. A commitment to ethical conduct, continuous learning, and responsible disclosure is required.
Read lessLondon, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria