Skip to content

Security Testing

Penetration Tester — Web & API

Location
Remote (EU/UK)
Type
Full-time
Level
Mid-level
Posted
Apply for this role ↓

The role

Run hands-on web application and API penetration tests for clients in financial services, healthcare and SaaS — from scoping call to evidence-backed report and retest.

What you’ll do

  • Deliver manual web application and API penetration tests against OWASP Top 10 and OWASP API Security Top 10 risks.
  • Chain findings into realistic attack paths and prove impact with clear, reproducible evidence.
  • Write reports that developers can act on and executives can understand.
  • Walk clients through findings on debrief calls and verify fixes during retests.
  • Contribute to internal tooling, methodology and knowledge-sharing sessions.

What we’re looking for

  • 2+ years of hands-on web or API penetration testing experience.
  • Strong understanding of HTTP, authentication and authorisation flaws, and common web frameworks.
  • Confident with Burp Suite and scripting in Python, Go or similar.
  • Clear written English and the ability to explain technical risk to non-specialists.
  • Right to work in the UK or an EU country.

Nice to have

  • OSCP, OSWE, CREST CRT or equivalent certification.
  • Published CVEs, bug bounty track record or open-source security tooling.
  • Experience testing GraphQL, gRPC or mobile back ends.

Don’t tick every box? Apply anyway — we hire for ability and curiosity, not a perfect keyword match.

How we hire

01

Application review

A consultant — not an automated filter — reads every CV and replies within 5 working days.

02

Intro call

30 minutes to talk about the role, your background and what you want next.

03

Practical exercise

A realistic, time-boxed task relevant to the role. No unpaid multi-day projects.

04

Team interview & offer

Meet the people you'd work with, then a decision within a week.

Apply

Apply for Penetration Tester — Web & API

Takes about 5 minutes. Fields marked * are required.

Role
About you
Experience & availability
CV & cover note
CV / résumé *

What happens next

A consultant reads every application and replies within 5 working days.

Your data

Your CV goes straight to our hiring inbox. It is never published or shared outside the hiring team.