Security Penetration Tester

Reference: SPT_1781529747

As a Security Penetration Tester, you will be responsible for supporting the design, implementation, and maintenance of TVM (Threat & Vulnerability Management) solutions, controls and processes across the organisation. You will be liaising with Digital teams to ensure appropriate mitigation and remediation of vulnerabilities detected across our IT estate.

This role requires an understanding of TVM concepts, technologies, and best practices, as well as the ability to collaborate effectively with cross-functional teams. The ideal candidate will possess strong communication and will be committed to ensuring the highest level of security, compliance, and user experience.

Security Clearance: CTC (Counter Terrorist Check) clearance is essential. You must currently hold or be able to attain CTC clearance for this role.

What you'll be doing as a Security Penetration Tester

  • Help support and develop an internal penetration testing function.
  • Conduct network, application penetration testing, code and security reviews.
  • Identify and exploit vulnerabilities through proof-of-concept testing.
  • Support vulnerability management across the enterprise, ensuring that a framework for identification, categorisation and mitigation exists and is implemented and maintained.
  • Responsible for supporting the creation of the operating model for vulnerability management, that it is shared, agreed and operates effectively across the business.
  • Develop and maintain penetration testing documentation, policies, and procedures.
  • Integrate cyber security solutions (e.g. vulnerability scanning tools) with existing systems, applications, and infrastructure.
  • Evaluate and recommend technologies, tools, and vendors to meet business needs.
  • Investigate newly identified cyber security vulnerabilities and provide appropriate mitigation actions.
  • Liaise and coordinate with technology and business stakeholders in relation to cyber security patching and vulnerability management issues/actions.
  • Maintain a cyber threat assessment methodology, align to evolving industry standards and integrate into BAU and project-based business processes.
  • Support with proactive threat hunting for new and emerging cyber threats.
  • Develop and maintain dashboards with cyber security threat and vulnerability metrics.
  • Support compliance with relevant industry standards, regulations, and best practices, such as GDPR, NIS and ISO 27001.

What you should bring to the role

  • Strong knowledge of manual penetration testing techniques and confident with operating systems and tools such as Tenable, Burp Suite, Kalli Linux.
  • Exposure to remediating vulnerabilities and patch management in a complex business environment.
  • Experience in remediating cyber risks in the ever-changing digital estate.
  • Experience in a penetration testing enterprise environment.
  • Prepare detailed reports and the ability to present findings to key stakeholders.
  • Cyber security industry certification(s) such as CSTM/ CRT/ OSCP/CTL.
  • Understanding of different patching management techniques and approaches for different technology stacks (e.g. SaaS, IaaS, End-User Computing, Server Estate, etc.).
  • Knowledge of TVM concepts, technologies, and best practices, including OSINT tools, vulnerability assessment, threat modelling, etc

GCS is acting as an Employment Agency in relation to this vacancy.

£65,000.00 - £70,000.00
Per annum
GBP65000 - GBP70000 per annum

Berkshire

Permanent

Added 15/06/2026
Reference: SPT_1781529747

Security Penetration Tester

Berkshire
Permanent

Other similar jobs

Identity & Access Management (IAM) Test Analyst/Tester

Added 28/07/2026

Role OverviewWe are seeking an experienced Test Analyst/QA Tester with a background in Identity & Access Management (IAM) to test identity processing and user provisioning solutions across the identity lifecycle (Joiner, Mover, Leaver - JML).The successful candidate will be responsible for validating that user accounts, access rights, and entitlements are correctly provisioned, updated, and removed across multiple integrated systems, including HR systems, Active Directory (AD/LDAP), IAM platforms, and business applications.The role involves executing functional, integration, end-to-end, regression, and negative testing, validating identity data and business rules, performing SQL data validation, API testing using Postman, managing defects in Jira/ALM, and supporting...

Learn more

Automation Tester

Added 24/07/2026

Automation Tester Drive quality through automation.Are you passionate about software quality, automation, and delivering exceptional user experiences? We're seeking an Automation Tester / Software Development Engineer in Test (SDET) to help build robust testing frameworks and ensure the reliability of modern applications.This role offers the opportunity to work closely with developers, product teams, and engineering leaders to champion quality across the entire software development lifecycle.What You'll Be DoingDesigning, developing, and maintaining automated test frameworksCreating automated test suites for web, API, and backend servicesSupporting CI/CD pipelines and shift-left testing practicesPerforming regression, integration, and end-to-end testingIdentifying issues early and improving overall product...

Learn more

Software Tester

Added 02/07/2026

Software Tester (SC Cleared)Drive quality. Accelerate delivery. Own automation. We're looking for a Software Tester who can build robust automated test solutions that boost efficiency, reduce manual effort, and ensure high‑quality software releases. What You'll DoBuild Automation Strategy - Identify what to automate, prioritise test cases, and shape a scalable automation approach.Develop Test Frameworks - Create and maintain automation frameworks using Selenium, Appium, TestNG, JUnit, or similar tools.Write & Execute Scripts - Build reliable, maintainable automated tests across platforms, devices, and environments.Integrate with CI/CD - Embed automated tests into pipelines using Jenkins, GitLab CI, Azure DevOps, etc.Manage Test Data -...

Learn more

Cyber Controls Tester

Added 07/05/2026

As a Control Tester, you will play a key role within the Information Security team supporting the Control Testing & Assurance Manager in delivering cybersecurity control testing activities across multiple security domains. Working closely with cybersecurity leadership, service owners, and control owners, you will help ensure security controls are effectively designed, implemented, and operating as intended across the organisation.This role contributes to the Cybersecurity Control Testing & Assurance programme by assessing control effectiveness, gathering evidence, and supporting the organisation's wider security and compliance objectives. You will collaborate with stakeholders across the business to ensure testing activities are executed efficiently while...

Learn more

Cyber Security Architect - OutsideIR35

Added 31/07/2026

Security Architect - Consultant Advisory12-Month Contract | Outside IR35 | Hybrid (2 days per week on-site)Location: West London / Greater LondonWe are supporting a major UK transport infrastructure organisation undergoing a significant programme of cyber security improvement and technology transformation.We are seeking an experienced Security Architect Consultant to provide advisory support across a complex digital estate, reviewing security architectures, assessing risks, and supporting the delivery of security improvements across critical technology platforms.This role will involve working with technical teams, architects, and senior stakeholders to review existing security controls, improve security design practices, and support the implementation of secure technology solutions...

Learn more

Cloud Security Solution Architect

Added 20/07/2026

Job Title: Solution ArchitectJob Type: Contract Job Location: SheffieldMandatory Skills: IAM, GCPOverviewA leading global financial services organisation is undertaking a major multi-year Identity & Access Management (IAM) transformation programme to modernise and enhance identity services across a complex international technology landscape.The programme will redefine how identities are managed across the enterprise, spanning workforce, privileged, machine, agent, and workload identities. As part of this transformation, a number of next-generation identity capabilities and platforms will be designed and implemented using modern cloud-native technologies and security principles.We are seeking an experienced Solution Architect / Design Engineer to provide technical leadership across the programme,...

Learn more

AWS Security Architect - Contract

Added 17/07/2026

WS Security Architect - ContractWe are seeking an experienced AWS Security Architect to lead the design and implementation of security controls across our AWS estate. This role will be responsible for establishing secure architecture standards, driving security best practices, and ensuring AWS services are deployed in a scalable, compliant, and resilient manner.Working closely with Cloud Engineering, Platform, DevOps, and Cyber Security teams, you will provide both strategic direction and hands-on technical guidance to ensure security is embedded throughout the lifecycle of our AWS platforms and applications.This is a delivery-focused role that combines architecture, engineering, and governance, enabling teams to adopt...

Learn more

Cyber Security Director

Added 16/07/2026

Associate Director - Cyber Security Location: OxfordshireContract Type: Day Rate ContractOverviewWe are seeking an experienced Associate Director of Cyber Security to lead and enhance cyber security operations for my client. This is a hands on leadership role responsible for driving cyber strategy, managing security operations, and improving security across a hybrid Azure, AWS, and on-premise environment.Key ResponsibilitiesLead cyber security strategy and day-to-day security operationsDesign and implement security architecture across Azure, AWS and on-prem environmentsOwn SIEM, SOAR, EDR and vulnerability management platformsManage external SOC providers and oversee incident responseDrive cyber governance, risk management and compliance initiativesDevelop security policies, standards and awareness...

Learn more

Cyber Security Director

Added 15/07/2026

Associate Director - Cyber Security Location: OxfordshireContract Type: Day Rate ContractOverviewWe are seeking an experienced Associate Director of Cyber Security to lead and enhance cyber security operations for my client. This is a hands on leadership role responsible for driving cyber strategy, managing security operations, and improving security across a hybrid Azure, AWS, and on-premise environment.Key ResponsibilitiesLead cyber security strategy and day-to-day security operationsDesign and implement security architecture across Azure, AWS and on-prem environmentsOwn SIEM, SOAR, EDR and vulnerability management platformsManage external SOC providers and oversee incident responseDrive cyber governance, risk management and compliance initiativesDevelop security policies, standards and awareness...

Learn more

Cyber Security Engineer (OUTSIDE IR35)

Added 14/07/2026

Cyber Security Engineer - Microsoft 365 & Azure6-Month Contract | Outside IR35 | £350-400 per day | Remote (UK) | 1-2 Days per Month On-Site (South West London)A leading public sector organisation is looking for a Cyber Security Engineer to support a major cyber security improvement programme.Working alongside the Cyber Security, Infrastructure and Platform teams, you'll help deliver a range of security enhancements across Microsoft 365, Azure and AWS, strengthening the organisation's overall security posture while improving identity, endpoint, cloud and data protection capabilities.This is a fantastic opportunity for someone who enjoys hands-on engineering and wants to be involved in...

Learn more

AWS Security Architect - Contract

Added 08/07/2026

AWS Security Architect - ContractWe are seeking an experienced AWS Security Architect to lead the design and implementation of security controls across our AWS estate. This role will be responsible for establishing secure architecture standards, driving security best practices, and ensuring AWS services are deployed in a scalable, compliant, and resilient manner.Working closely with Cloud Engineering, Platform, DevOps, and Cyber Security teams, you will provide both strategic direction and hands-on technical guidance to ensure security is embedded throughout the lifecycle of our AWS platforms and applications.This is a delivery-focused role that combines architecture, engineering, and governance, enabling teams to adopt...

Learn more

AWS Security Architect

Added 08/07/2026

AWS Security ArchitectWe are seeking an experienced AWS Security Architect to lead the design and implementation of security controls across our AWS estate. This role will be responsible for establishing secure architecture standards, driving security best practices, and ensuring AWS services are deployed in a scalable, compliant, and resilient manner.Working closely with Cloud Engineering, Platform, DevOps, and Cyber Security teams, you will provide both strategic direction and hands-on technical guidance to ensure security is embedded throughout the lifecycle of our AWS platforms and applications.This is a delivery-focused role that combines architecture, engineering, and governance, enabling teams to adopt AWS services...

Learn more

Technical Project Manager Security

Added 07/07/2026

Technical Program Manager II - Security & Audit Remediation📍 Los Angeles, CA (Hybrid) We are hiring a Technical Program Manager II to lead enterprise security, compliance, and audit remediation initiatives. This role will partner with Security, Engineering, Infrastructure, Risk, and Compliance teams to drive audit readiness, remediation efforts, risk management, and executive reporting.Responsibilities:Lead security and compliance programs across cross-functional teams.Drive audit remediation activities and track deliverables to completion.Manage risks, dependencies, and program status reporting.Coordinate audit documentation, evidence collection, and technical artifacts.Track vulnerability remediation and provide leadership updates.Requirements:7+ years of Technical Program Management or Project Management experience.Experience leading security, compliance, infrastructure,...

Learn more

Technical Project Manager Security

Added 07/07/2026

Technical Program Manager II - Security & Audit Remediation📍 Irvine, CA (Hybrid)We are seeking an experienced Technical Program Manager II to lead security, compliance, and audit remediation initiatives across enterprise technology environments. This role will partner with Security, Engineering, Infrastructure, Risk, and Compliance teams to drive audit readiness, remediation efforts, risk management, and executive reporting.Key Responsibilities:Lead cross-functional security and compliance programs.Drive audit remediation activities and track deliverables to completion.Manage program plans, risks, dependencies, and executive communications.Coordinate audit evidence, documentation, and technical artifacts.Track vulnerability remediation and report program health metrics.Facilitate stakeholder meetings and leadership updates.Required Qualifications:7+ years of Technical Program Management...

Learn more

Cloud & Security Engineer

Added 06/07/2026

Cloud & Security Engineer (12-Month Contract)Location: Dublin (Hybrid - 3 days onsite)Contract: 12 Months | Daily RateAn Irish organisation is looking for an experienced Cloud & Security Engineer to support and enhance its Microsoft cloud and security environment.You'll play a key role across cloud infrastructure, identity, endpoint security and incident response while helping to strengthen security posture and modernise IT operations.Key ResponsibilitiesManage Microsoft Entra ID, Conditional Access, MFA and Privileged Identity Management (PIM)Administer Microsoft Intune and Microsoft Defender XDRMonitor and investigate security events using Microsoft SentinelSecure Azure environments using Zero Trust principlesProvide Level 3 support and technical leadershipSupport ITIL processes...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.