Security Testing
Penetration Tester — Web & API
- Location
- Remote (EU/UK)
- Type
- Full-time
- Level
- Mid-level
- Posted
The role
Run hands-on web application and API penetration tests for clients in financial services, healthcare and SaaS — from scoping call to evidence-backed report and retest.
What you’ll do
- Deliver manual web application and API penetration tests against OWASP Top 10 and OWASP API Security Top 10 risks.
- Chain findings into realistic attack paths and prove impact with clear, reproducible evidence.
- Write reports that developers can act on and executives can understand.
- Walk clients through findings on debrief calls and verify fixes during retests.
- Contribute to internal tooling, methodology and knowledge-sharing sessions.
What we’re looking for
- 2+ years of hands-on web or API penetration testing experience.
- Strong understanding of HTTP, authentication and authorisation flaws, and common web frameworks.
- Confident with Burp Suite and scripting in Python, Go or similar.
- Clear written English and the ability to explain technical risk to non-specialists.
- Right to work in the UK or an EU country.
Nice to have
- OSCP, OSWE, CREST CRT or equivalent certification.
- Published CVEs, bug bounty track record or open-source security tooling.
- Experience testing GraphQL, gRPC or mobile back ends.
Don’t tick every box? Apply anyway — we hire for ability and curiosity, not a perfect keyword match.
How we hire
Application review
A consultant — not an automated filter — reads every CV and replies within 5 working days.
Intro call
30 minutes to talk about the role, your background and what you want next.
Practical exercise
A realistic, time-boxed task relevant to the role. No unpaid multi-day projects.
Team interview & offer
Meet the people you'd work with, then a decision within a week.
Apply
Apply for Penetration Tester — Web & API
Takes about 5 minutes. Fields marked * are required.
What happens next
A consultant reads every application and replies within 5 working days.
Your data
Your CV goes straight to our hiring inbox. It is never published or shared outside the hiring team.