Hybrid Senior Penetration Tester

Posted 2 weeks ago

Apply now

About the role

  • Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
  • Automation of security testing, and development of internal tooling, to achieve continuous assurance.
  • Collaboration with engineering teams to facilitate secure development, including:
  • Review and analysis of proposed technical solutions to identify appropriate security controls.
  • Input and guidance to security related technical architecture and design decisions.
  • Code review of features and critical security components.
  • Practical security testing.
  • Advising on remediation of security issues and processes to address root causes.
  • Security assurance reviews of third-party solutions.
  • Identifying and implementing improvements to the team’s internal processes and procedures.
  • Review, analysis and reporting of external threats relevant to Starling systems and solutions, in the context of Starling’s desired security posture.

Requirements

  • 5+ years technical information security experience.
  • Experience of mobile, web application, cloud and infrastructure penetration testing.
  • Strong technical knowledge in:
  • Mobile security (iOS and Android)
  • Web application security
  • Networking and associated protocols
  • Cloud security (AWS and GCP)
  • Containers and Kubernetes
  • A desire to learn, and ability to apply technical security knowledge to new and unfamiliar areas.
  • CREST, OSCP or similar industry penetration testing qualification
  • A good understanding of applied cryptographic techniques.
  • Reverse engineering and exploit development capabilities.
  • Experience of security testing in an agile SDLC.
  • Threat modelling experience.
  • Experience performing code reviews, particularly in Java and Go.
  • Experience of fulfilling a client facing security consulting role.
  • Excellent verbal and written communication skills.
  • Experience in automation of security testing, with previous development experience desirable.

Benefits

  • 25 days holiday (plus take your public holiday allowance whenever works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

Job title

Senior Penetration Tester

Job type

Experience level

Senior

Salary

Not specified

Degree requirement

Professional Certificate

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job