Big Red Recruitment
Penetration Tester

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We are seeking a Penetration Tester to join a growing Offensive Security team within a specialist cyber security consultancy. This is an exciting opportunity to join at a time of significant investment and growth, helping to strengthen existing testing services while contributing to the development of new capabilities across areas such as Red Teaming, Operational Technology (OT), Threat-Led Security Testing and emerging technologies.
The successful candidate will play a key role in delivering penetration testing engagements, supporting process improvement initiatives, and helping to build a scalable and mature testing function. This position offers excellent opportunities for professional development, certification support and future progression into senior or leadership positions.
Job Role - Penetration Tester
Location: London (Occasional on-site work)
Salary: £40,000-£45,000 + Benefits
Key Responsibilities
- Conduct vulnerability assessments and penetration testing engagements across:
- Internal infrastructure
- External infrastructure
- Web applications
- Networks and systems
- Perform configuration and build reviews using recognised security frameworks and benchmarks.
- Produce clear, concise and actionable technical reports detailing findings, risk ratings and remediation recommendations.
- Utilise industry-standard security testing tools including Burp Suite, Nessus, Metasploit, Nmap, Wireshark and related technologies.
- Work directly with clients and stakeholders, presenting findings and providing remediation guidance where required.
- Support the continuous improvement of testing methodologies, processes and documentation.
- Assist in creating and maintaining standard operating procedures, testing guides and knowledge-sharing materials.
- Collaborate with wider cyber security teams to support service development and research initiatives.
- Contribute to research and development activities across new security testing disciplines and technologies.
- Participate in occasional out-of-hours and on-site engagements where client requirements dictate.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Required Skills & Experience
- Minimum 2–3 years' experience in penetration testing, vulnerability assessment or offensive security.
- Experience conducting:
- Internal and external infrastructure testing
- Web application security testing
- Security assessments and audits
- Vulnerability identification and validation
- Strong understanding of networking concepts, protocols, routing and firewall technologies.
- Experience working with Windows, Linux and macOS environments.
- Familiarity with security assessment tools such as:
- Burp Suite
- Nessus
- Metasploit
- Nmap
- Wireshark
- Experience producing high-quality technical reports and client-facing documentation.
- Excellent communication and stakeholder management skills.
- Strong organisational skills and ability to manage workload independently.
- Comfortable working in a consultancy or client-facing environment.
- Eligible to obtain UK Security Clearance.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Skills & Certifications
- CREST CRT, CPSA, CCT or equivalent certification.
- OSCP or similar offensive security qualification.
- Cyber Scheme accreditation.
- CHECK Team Member status.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location