Hamilton Barnes 🌳
Penetration Tester

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
🚀 Security Testing Consultant | £50,000 – £60,000 | Hybrid – London
A great opportunity for a mid-level Security Testing Consultant to join a London-based cybersecurity and AI risk consultancy operating to CREST methodology as an accredited CREST member company. You'll own delivery of your own engagements end-to-end (scoping, testing, reporting and client debriefs) across web, infrastructure, application and cloud testing, with API, mobile and wireless work as the project mix demands.
If you want a role that takes reporting and client communication as seriously as the testing itself, with a clear runway into AI security and red teaming, this is well worth a conversation.
✨ Why this role stands out:
- A genuine, structured growth path: over your first 18–24 months, progress from core testing into AI security assessments, assumed breach exercises and red team operations, backed by a funded personal development plan toward OSCP, OSWE, OSEP, CRTO, CREST CCT and emerging AI security tracks
- Real client-facing ownership: present findings to technical and executive audiences and provide post-test remediation guidance as standard
- A collaborative team with experienced senior testers and an in-house methodology you can help shape, plus hybrid working with some UK client-site travel
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
🛠️ Skills/Must Have:
- Around 3–5 years of hands-on penetration testing experience
- Web application testing aligned to OWASP WSTG, with hands-on Burp Suite work
- Infrastructure and network testing, including Active Directory
- Cloud security testing in at least one of AWS, Azure or GCP (familiarity with a second helpful)
- API testing, including REST and ideally GraphQL
- Confident use of standard offensive tooling: Kali, Burp Suite, Nmap, a recognised vulnerability scanner (Nessus, Qualys or equivalent), Metasploit
- Working understanding of common application, network and cloud security controls, and how they fail
- One or more current accreditations from CREST (CPSA, CRT), Offensive Security (OSCP, OSWE) or equivalent
- Confident written English, as reporting is a substantial part of the role
- No degree required; demonstrable experience, certifications, lab work and research contributions weighed on their own merits
🔨 Useful but not required:
- Programming in any mainstream language
- Containerisation and CI/CD security
- Red team or social engineering exposure
- Hands-on AI/LLM security testing
- Hardware/IoT/ICS security
- Bug bounty or responsible disclosure work
- Mobile (OWASP MASTG) and wireless testing familiarity


Get help with your application
Your very own career expert that helps elevate your application to the next level.
🎯 Responsibilities:
- Conduct penetration tests across web applications, infrastructure, cloud environments and APIs, with mobile and wireless engagements as required
- Produce clear, well-structured reports and present findings to technical and executive client audiences
- Provide post-test remediation guidance and follow-up support
- Contribute to the evolution of the in-house testing methodology and tooling
- Support development of more junior team members
- Stay current with offensive security research, techniques and emerging threats
🎁 Benefits:
- Annual gainshare bonus when company performance is above target
- Funded personal development plan including certifications and conference attendance
- Hybrid working
- Benefits package
💰 Salary: £55,000 – £60,000
📩 Interested? Get in touch to find out more or send your CV directly.
#PenetrationTesting #SecurityTesting #CREST #OSCP #RedTeam #AISecurity #CyberSecurity #LondonJobs #InfoSecJobs
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location