10Nex Consultancy
Penetration Tester

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Testing Consultant
London | Hybrid | Permanent | Competitive Salary + Bonus
I’m working with a growing cybersecurity business in London that’s looking to add a Security Testing Consultant to its team.
This is a good one for someone who already has a few years of penetration testing experience under their belt and wants to keep progressing technically.
The work is varied. You’ll be testing across web applications, infrastructure, cloud environments and APIs, rather than being boxed into one particular area. There’ll also be opportunities to get involved in things like mobile, wireless, red teaming and newer areas of security as you develop.
What you’ll be doing
- Penetration testing across web apps, infrastructure, cloud and APIs
- Working with Active Directory and network environments
- Testing across AWS, Azure and/or GCP
- Using tools such as Burp Suite, Kali Linux, Nmap, vulnerability scanners and Metasploit
- Taking ownership of your own testing engagements
- Writing clear reports and talking clients through your findings
- Helping clients understand how vulnerabilities can actually be remediated
- Contributing ideas around testing approaches, tooling and methodology
- Sharing knowledge with other members of the team
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What I’m looking for
You’ll ideally have around 3–5 years of hands-on penetration testing experience.
You don’t need to tick every box, but experience across a good mix of the below would be ideal:
- Web application penetration testing
- OWASP / Burp Suite
- Infrastructure and network testing
- Active Directory
- Cloud security testing
- API testing
- Kali Linux
- Nmap
- Metasploit
- Vulnerability scanning
If you’ve got certifications such as CREST CPSA / CRT, OSCP, OSWE or something similar, even better.
There’s no degree requirement for this role. They’re much more interested in what you can actually do technically and the experience you’ve built up.
Not essential, but any exposure to the following would be a bonus:


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Python or another programming language
- Docker / Kubernetes
- CI/CD security
- Red teaming
- Social engineering
- AI / LLM security
- Mobile security
- IoT / hardware security
- Bug bounty or responsible disclosure work
Why it’s worth considering
The main attraction here is the progression.
They’re happy to invest in people technically, including funded certifications, training and conference attendance, and there’s scope to move into more advanced areas of offensive security as you grow.
That could include:
- Red team engagements
- Assumed breach testing
- AI security
- More advanced application and infrastructure testing
You’ll still be hands-on day to day, but you’re joining somewhere that gives you room to develop rather than just putting more and more standard penetration tests in your diary.
If you’re a penetration tester in or around London and fancy hearing a bit more about it, drop me a message.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location