Job DescriptionJob Title: Cyber Security Penetration TesterLocations: UK wide (hybrid work- 1x a month in office)Salary: Competitive salary and package (Depending on level of experience)Please Note:Any offer of employment is subject to satisfactory BPSS and SC security clearance which requires 5 years continuous UK address history (typically including no periods of 30 consecutive days or more spent outside of the UK) at the point of application.
Role overviewAs a Penetration Tester, you will deliver hands-on security testing of client web applications, APIs and infrastructure. Working within a collaborative testing team, and supported by senior testers and CHECK Team Leaders on complex engagements, you will find and validate vulnerabilities, demonstrate their real-world impact and give clients clear, practical remediation advice. This role suits an early-career tester who wants to broaden their technical skills and progress through recognised industry certifications.
Key responsibilities- Perform manual and tool-assisted testing of web applications, APIs and internal and external infrastructure.
- Identify, validate and safely exploit vulnerabilities within agreed rules of engagement, including authentication, authorisation, injection, business logic and misconfiguration issues.
- Help identify attack paths, including privilege escalation, and explain their business impact.
- Follow recognised methodologies, including OWASP (WSTG, API Security Top 10), PTES and CHECK/CREST standards.
- Help prepare for engagements by confirming scope, access and prerequisites with the engagement lead.
- Write clear, accurate reports with reproducible evidence, risk ratings and prioritised remediation advice.
- Support client remediation and carry out retests to confirm fixes are effective.
- Escalate critical findings promptly to the engagement lead and help explain their impact to stakeholders.
- Share knowledge with the team through peer review, tooling improvements and technical write-ups.
QualificationEssential skills and experience- Typically 1-2 years' commercial penetration testing experience across web applications, APIs and infrastructure.
- Good working knowledge of common web and API vulnerabilities, including the OWASP Top 10 and API Security Top 10.
- Practical experience with industry-standard tools such as Burp Suite, Nmap and Metasploit.
- Ability to validate findings, rule out false positives and capture reproducible evidence.
- Clear technical writing that explains risk and remediation in plain language.
Desirable skills and experience- Awareness of cloud security and configuration review in AWS, Azure or GCP.
- Some mobile application testing experience (iOS and/or Android).
- Basic scripting (e.g. Python, Bash, PowerShell) to automate tasks or adapt tools.
- Understanding of cryptography and build/hardening standards.
- Sound understanding of networking, common protocols, and Windows and Linux security.
- Holds, or is working towards, a practitioner-level certification such as CREST CRT, Cyber Scheme CSTM, OSCP or PNPT.
Development and support- Mentoring and technical guidance from experienced testers and CHECK Team Leaders.
- A funded certification pathway, for example from CRT or CSTM through to CCT or CSTL.
- A broad mix of engagements to build experience across testing types.
- Dedicated time for training, research and lab work.
- Opportunities to contribute to internal tooling, methodology and innovation projects.
#LI-EU
#LI-MP LocationsLondon
Cheltenham
Edinburgh
Glasgow
Additional InformationEqual Employment Opportunity Statement All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.
Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.
Accenture is committed to providing veteran employment opportunities to our service men and women.
Please read Accenture’s Recruiting and Hiring Statement for more information on how we process your data during the Recruiting and Hiring process.
About AccentureWe work with one shared purpose: to deliver on the promise of technology and human ingenuity. Every day, more than 775,000 of us help our stakeholders continuously reinvent. Together, we drive positive change and deliver value to our clients, partners, shareholders, communities, and each other.
We believe that delivering value requires innovation, and innovation thrives in an inclusive and diverse environment. We actively foster a workplace free from bias, where everyone feels a sense of belonging and is respected and empowered to do their best work.
At Accenture, we see well-being holistically, supporting our people’s physical, mental, and financial health. We also provide opportunities to keep skills relevant through certifications, learning, and diverse work experiences. We’re proud to be consistently recognized as one of the World’s Best Workplaces™.
Join Accenture to work at the heart of change. Visit us at www.accenture.com .