Cognisys
Penetration Tester - UK (Remote)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location: UK (Remote) Salary: Competitive Compensation
About Cognisys
Cognisys is a global cybersecurity company specialising in Penetration Testing, GRC Consulting and Managed Security services. We work with organisations across more than 30 countries, helping them identify risk, strengthen their security posture and navigate an increasingly complex cybersecurity landscape.
We're a small but mighty team with ambitious plans for growth. We combine deep technical expertise with a strong focus on customer service, practical advice and delivering meaningful outcomes for our clients.
Our people are at the heart of what we do. We value Together, Ownership, Momentum and Excellence, and we want people who are curious, collaborative and willing to take ownership of their work.
As we continue to grow, you'll have the opportunity to work alongside experienced cybersecurity professionals, contribute to challenging client engagements and help shape the way we deliver our services. We believe in giving our people the opportunity to develop, share ideas and make a genuine impact.
The Opportunity
Are you ready to make an impact in the fast-paced world of cybersecurity?
Cognisys is growing rapidly, and we're looking for a Pen Tester to join our team during an exciting period of innovation and expansion.
As a Pen Tester, you'll be responsible for delivering and supporting security assessments across a range of client environments, including networks, applications and cloud infrastructure.
You'll use a combination of automated tools and manual techniques to simulate real-world attack scenarios, identify meaningful vulnerabilities and help clients understand and address their security risks.
This is a client-facing role where technical expertise is only part of the job. You'll also need to communicate your findings clearly, produce high-quality reports and help both technical and non-technical stakeholders understand the risks and practical steps they can take to improve their security posture.
What You'll Be Doing
Penetration Testing & Security Assessments
- Conduct penetration testing across networks, web applications, APIs, mobile applications and cloud environments.
- Simulate real-world attack scenarios to assess client resilience against cyber threats.
- Use a combination of automated vulnerability scanning tools and manual testing and exploitation techniques.
- Identify, analyse and exploit security vulnerabilities across diverse client environments.
- Assess the effectiveness of technical security controls and identify opportunities for improvement.
- Apply appropriate offensive security methodologies, tools and techniques throughout engagements.
- Stay up to date with emerging vulnerabilities, attack techniques and industry developments.
Client Delivery & Communication
- Work directly with clients throughout penetration testing engagements.
- Present findings and recommendations clearly and professionally.
- Help clients understand the potential business and technical impact of identified vulnerabilities.
- Communicate complex technical concepts in a way that is accessible to non-technical stakeholders.
- Support clients in understanding and prioritising remediation activities.
- Build positive and professional relationships with client stakeholders.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Reporting & Quality
- Produce high-quality technical reports following each engagement.
- Clearly document vulnerabilities, exploitation techniques, evidence, risk and remediation recommendations.
- Ensure technical findings are accurate, well-evidenced and easy for clients to understand.
- Translate technical detail into clear, practical recommendations for both technical and executive audiences.
- Maintain Cognisys' high standards for quality, consistency and client service.
Team Contribution & Development
- Work collaboratively with the wider cybersecurity team.
- Share knowledge, techniques and lessons learned with colleagues.
- Contribute to the continued development of Cognisys' penetration testing methodologies and ways of working.
- Take ownership of your continued technical and professional development.
- Support a culture of learning, collaboration and continuous improvement.
About You
We're looking for someone with a strong technical foundation in offensive security who is equally comfortable working with clients and communicating technical findings.
You'll ideally have:
- Hands-on experience conducting penetration testing and security assessments.
- Experience using vulnerability scanning tools alongside manual testing and exploitation techniques.
- A strong understanding of offensive security methodologies, tools and techniques.
- A strong grasp of how to assess and break technical controls, with the ability to explain the findings clearly to clients.
- Experience across one or more of the following areas:
- Network penetration testing
- Web application testing
- API testing
- Mobile application testing
- Cloud security testing
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- The ability to communicate technical vulnerabilities and risks in a clear, non-technical format.
- Strong client engagement skills and a professional approach to customer service.
- The ability to manage your workload effectively and deliver work to agreed deadlines.
- A proactive approach to learning and keeping up to date with developments in offensive security.
Certifications
The following certifications are highly regarded:
- Industry-recognised certifications are preferred and may include:
- OSCP
- CPSA
- CRT
- CREST-related certifications
- Other relevant penetration testing or offensive security certifications
Relevant practical experience will also be considered alongside formal certifications.
What Success Looks Like


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Success in this role means becoming a trusted technical consultant who can independently deliver high-quality penetration testing engagements while providing an excellent client experience.
For Example:
- Deliver thorough, accurate and professional penetration testing engagements across a variety of client environments.
- Confidently assess and exploit vulnerabilities using a combination of automated tools and manual testing techniques.
- Demonstrate a strong understanding of how technical controls can be assessed, bypassed and exploited in realistic attack scenarios.
- Produce clear, detailed and actionable technical reports that help clients understand their vulnerabilities and how to remediate them.
- Communicate technical findings effectively to both technical teams and non-technical stakeholders.
- Present findings and recommendations confidently to clients and support them in prioritising remediation.
- Take ownership of your engagements, managing your testing, documentation and deliverables effectively.
- Continue to develop your technical knowledge and stay current with evolving offensive security techniques, tools and threats.
- Contribute positively to the wider penetration testing team by sharing knowledge, supporting colleagues and continuously looking for ways to improve our approach.
Why Join Us?
At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.
What we Offer:
- Annual Leave: 25 days per year plus 8 English bank holidays.
- Additional Leave: 1 day of paid leave for your Birthday.
- Health & Wellbeing: Access to Westfield Health Care Cash Plan and an employee mental health and wellbeing platform.
- Professional Development: £2,000 annual training budget to support your continued learning and career growth.
- Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.group
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London