Senior Penetration Testing Engineer
Job Description
Overall
4+ years in cybersecurity, security testing, or software engineering with a strong security focus
Structured, methodical approach to testing - able to plan and document, not just test ad-hoc
Good written English - reporting is a significant part of the role
Must have
Hands-on experience in vulnerability assessment and penetration testing (web, API, network, or infrastructure)
Secure code review experience
Solid coding skills (Python preferred) for automation, tooling and test scripts
Experience writing automated tests and building them into repeatable suites
Strong understanding of vulnerability classes (OWASP Top 10, CWE) and CVE/CVSS triage
Familiarity with standard security tooling (e.g. Burp Suite, Nmap, SAST/DAST scanners)
Nice to have
Experience applying AI/LLMs to security work - highly desirable
Vulnerability management processes and tooling
Cloud security (AWS/Azure/GCP) or OT/embedded/product security background
CI/CD security integration
Certifications: OSCP, CEH, CISSP, or similar
Job Responsibilities
Perform vulnerability assessments and penetration testing against applications, services and infrastructure
Conduct secure code and configuration reviews
Triage and validate findings; assess severity, eliminate false positives, support remediation
Write and maintain automated security tests and tooling
Design test plans, execute testing campaigns, document and report results
Evaluate AI-assisted approaches to security testing and help integrate what works into the workflow
Department/Project Description
An enterprise technology group is building a dedicated security validation team focused on vulnerability assessment and security testing across the group's products and systems. The team runs structured testing campaigns: penetration testing, vulnerability discovery and triage, secure code review, and building automated test suites to make the process repeatable at scale.
The team also gets early access to specialized AI models and evaluates how they can accelerate security testing - an area we're actively investing in, though the core of the work remains hands-on security engineering. Scope covers internal systems as well as business-unit products across the group, agreed campaign by campaign. The team starts small and scales into a permanent capability.
Skill Category
QA - Automation
Keyskills - Must Have
- Security
- Application Security
- Penetration Testing and Reporting