Cst Associate Penetration Tester
18 hours ago
**About The Role**:
The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack surface for new vulnerabilities, changes in the scope of the attack surface, and proactively inform customers of discovered issues along with recommended remediation; with the overall aim of reducing the lifetime of each vulnerability. Manual testing includes identification of issues which automation alone could not identify, exploitation of all issues, often chaining multiple findings together in order to determine the true impact of vulnerabilities for the customer.
- Manual identification and exploitation of vulnerabilities.
- Manual verification and exploitation of scanner findings.
- Detailed analysis of issues identified and exposure for the customer including proof of concept, reproduction steps, and recommended remediation.
- Communication of findings to the customer in a detailed, accurate and manageable manner both orally and through written vulnerability/scope notifications and periodic summaries.
- Continual professional development to maintain and develop knowledge and technical competencies.
- Maintain professional technical qualifications to demonstrate competency to our clients.
- Undertaking projects and support tasks as appropriate to the role.
**Progression**:
- During mentoring and experience progression, the Associate Penetration Tester will be tasked with- Pre-engagement activities including scoping of assessments and statements of work and determining customer requirements and restrictions.
- On boarding customers into the service including configuration of continual scanning and liaising with customer to resolve issues which may reduce the effectiveness of scanning.
- Monitoring of the customers’ external perimeter for changes, and proactive discovery of new targets to include within the customer’s scope.
**About You**:
**Essential**:
- Excellent written and spoken English including presentation, structure, spelling, and grammar. Along with experience conveying technical information in an accessible manner.
- Core computing skills including but not limited to:
- Networking fundamentals - understanding of OSI Model, TCP/IP, HTTP, DNS, SMB, SMTP and relevant tools.
- Microsoft Windows and Office proficiency along with proficiency in one or more Linux distributions.
- REST APIs, XML and JSON formats.
- Vulnerability identification and exploitation (not limited to OWASP Top 10).
- Experience with common assessment tools such as MITM proxies (e.g. Burp Suite Pro and SQLMap).
- General knowledge of internal and external infrastructure technologies and security assessment including but not limited to:
- Identification and exploitation of misconfigurations or known vulnerabilities in common enterprise infrastructure and services (Windows Domains, Linux servers, virtualisation, databases, switches/routers, etc).
- Knowledge of a scripting language such as Python (preferred), Ruby, PowerShell, or Bash, for the development of new, or editing existing, tools.
- Evidence of rapidly and confidently gaining and knowledge of emerging technologies, vulnerabilities, and penetration testing tools and techniques.
- Excellent time management including setting priorities and goals to complete assigned and arising tasks.
**Desirable**:
- CPSA - CREST Practitioner Security Analyst (or above)
- Public speaking experience
- A related Bachelor’s degree.
- Experience with live bug bounties, particularly where automation has been implemented.
- Knowledge of Open Source Intelligence gathering techniques. Including but not limited to use of Google dorks, DNS, domain registration, certificate transparency, and other public sources of information.
**About Us**:
**About Claranet**
At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges. We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation. Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business. We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrington, Bristol, and Leeds, or as homeworkers.
**Working For Claranet**
Here at Claranet we pride ourselves on going the extra mile for and with our employees (yes, we really mean it). We offer an extensive benefits package that you can tailor to
-
penetration testers
7 days ago
Remote, United Kingdom Zync Group Full time £50,000 - £95,000 per yearI`m looking for multiple Penetration Testers to join an innovative Information Security Consultancy specialising in Penetration Testing, cyber security assurance and incident response. They pride themselves on providing the highest quality service and client experience. They have phenomenal rates of employee retention and have a focus on career development...
-
Penetration Tester
16 hours ago
Remote, United Kingdom Glentzes Tech Limited Full timeGreetings from Glentzestech Private Limited. We are looking to hire Penetration Tester for client in UK This role will be heavily client focused, so excellent customer-facing skills are a must. You will be expected to build and implement the Pen Testing & Vulnerability testing capabilities for clients and external customers. You will be supporting the...
-
penetration tester
7 days ago
Remote, United Kingdom Zync Group Full time £30,000 - £70,000 per yearI am looking for a Penetration Tester with current CHECK Team Member status to join an award-winning, CREST and CHECK accredited Penetration Testing team in an MSSP They are currently going through a period of rapid growth and have plenty of interesting projects to work on. They have a friendly and supportive culture to help you grow and progress.The Role:In...
-
Penetration Tester
1 week ago
Remote, United Kingdom Trustmarque Full timeAt Trustmarque, our vision is to enable organisations to harness the power of digital technology. For over 30 years, we have helped organisations in the public and private sectors to work smarter, run their business more effectively and unlock the value of their IT investments. Our mission is to support our customers to buy and use innovative technology to...
-
Penetration Tester
7 days ago
Uk, Remote, United Kingdom EMBS Digital Full time £60,000 - £80,000 per yearCompany: This company is full of energy, purpose and confidence. The team is high on capability, pedigree and reputation which means this is the place where you'll make good great and build a career and skills that will guarantee your future in cyber security. This team is recognised as the best of the best by world governments, financial services,...
-
Penetration Tester
16 hours ago
Remote, United Kingdom IT Governance Ltd Full time**About us**: IT Governance is a leading global provider of IT governance, risk management and compliance solutions, with a special focus on cyber resilience, data protection, ISO 27001 and cyber security. **About the role**: - Work with a range of clients from blue-chip companies to SMEs, in a variety of fields, offering solutions to meet their...
-
Penetration Tester
2 weeks ago
Remote, United Kingdom Claranet Full time**About The Role**: The Continuous Security Testing service is a consultant led vulnerability identification and verification service which makes use of automated vulnerability scanning along with significant manual testing against a broad scope in a continuing engagement. The purpose of the service is to continually monitor a customer’s external attack...
-
penetration tester/check team member
7 days ago
Remote, United Kingdom Zync Group Full time £40,000 - £80,000 per yearI am looking for a CHECK Team Member to join an award-winning, CREST and CHECK accredited Penetration Testing team Theyre growing fast and setting high standards, but theyre also a friendly bunch who`ll help you to learn and progress.The role:Conducting a variety of penetration tests (web/mobile/infrastructure and some other really interesting projects)Scope...
-
Community Support Team Leader
2 weeks ago
Remote, United Kingdom DEBRA Full timeDEBRA have an exciting new opportunity, not to be missed! We are currently looking for an **Community Support Team Leade**r** **to join our friendly team in **Nottingham**. **Working from home, full time 35 hours per week** with occasional attendance to the **DEBRA Head Office in Bracknell, Berkshire** and **our Hospital Clinics **as required for...
-
Senior Scientist
5 days ago
Remote, United Kingdom Certara Full timeOverview: The post involves research and development of PBPK/PD models in various areas. A systematic understanding of the impact of various critical quality attributes _e.g._, formulations, excipients, and physiological variables) on drug product characteristics is important. The post holder is expected to provide on-going customer support and education...