Location: Salary: dependent on skills and experience Division: Group Technology Department: Cybersecurity, Risk & Resilience Title: Junior Web Application & Infrastructure Penetration Tester Department: Cyber Security Location: Remote About the Role Introduction At Oxford University Press (OUP), our mission is to advance learning, education, and research worldwide. As a Cyber Security & Resilience Testing Specialist, you will play a key role in helping protect the systems, applications, and digital services that support this mission. This is an excellent opportunity for an experienced penetration tester looking to broaden their impact across a complex and varied technology landscape. You'll join a collaborative Cyber Security team where your expertise will directly influence the security posture of the organisation and help safeguard products and services used globally. The role offers exposure to modern web applications, APIs, cloud environments, mobile platforms, and infrastructure technologies. You'll work with industry-leading security tools, contribute to the evolution of testing methodologies, and collaborate closely with development, infrastructure, and business teams to drive meaningful security improvements. Opportunity As a Cyber Security & Resilience Testing Specialist, you will: Conduct penetration testing against web applications, APIs, cloud-native services, internal networks, and supporting infrastructure. Identify, exploit, validate, and document security vulnerabilities, including those aligned to the OWASP Top 10 framework. Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify coding weaknesses and runtime vulnerabilities. Assess API security, including authentication, authorisation, and data exposure risks. Conduct security assessments for mobile applications across iOS and Android platforms. Produce high-quality technical reports with clear findings, risk analysis, and remediation recommendations. Collaborate with technical and business stakeholders to improve security controls and resilience across the organisation. Support the continuous improvement of security testing processes, standards, and methodologies. Impact Your work will directly contribute to strengthening OUP's security and resilience capabilities. By identifying vulnerabilities before they can be exploited, you will help protect critical systems, sensitive information, and the digital experiences relied upon by learners, educators, researchers, and employees around the world. About You Essential Criteria Demonstrable experience conducting manual and automated web application penetration testing. Strong understanding of offensive security principles and vulnerability assessment methodologies. Deep knowledge of the OWASP Top 10 and experience identifying, validating, and reporting vulnerabilities across these categories. Experience testing modern applications built using technologies such as: .NET / ASP.NET Java / Spring Node.js Python frameworks PHP frameworks React, Angular, Vue.js, and other JavaScript technologies REST and GraphQL APIs Single Page Applications (SPAs) Experience assessing API security. Strong communication skills with the ability to present complex technical concepts to both technical and non-technical audiences. Experience using industry-recognised security tools, including: Kali Linux Nmap Burp Suite Professional Desirable Criteria Experience with tools such as OWASP ZAP, JWT Toolkits, ffuf, GoBuster, Feroxbuster, Metasploit, CrackMapExec/NetExec, WPScan, CMSMap, SQLMap, Nuclei, and Wafw00f/LBD. Experience conducting mobile application security testing. Degree in Computer Science, Information Security, or a related discipline. Relevant industry certifications such as OSCP, CEH, CISSP, or equivalent. Key Attributes Naturally curious and motivated to explore beyond the obvious to understand systems and risks. Analytical, detail-oriented, and methodical in approach. Able to translate technical findings into practical business recommendations. Excellent communicator, comfortable engaging with diverse stakeholders. Adaptable, proactive, and committed to continuous learning. Capable of working independently while maintaining high standards of quality and delivery. Queries Please contact aarti.rana@oup.com with any queries relating to this role. To ensure a smooth application process, please submit your CV through the application link rather than via email. Diversity & Inclusion We are committed to supporting diversity in our workforce, and ensuring an inclusive environment where all individuals can thrive. We seek to employ a workforce representative of the markets that we serve and encourage applications from all. Salary Dependent on skills and experience. We are committed to supporting diversity in our workforce, and ensuring an inclusive environment where all individuals can thrive. We seek to employ a workforce representative of the markets that we serve and encourage applications from all. Job Category: Technology
Principal Penetration Tester
Clearwater
Senior Penetration Tester
Aveva
Senior Penetration Tester (12-Month Contract)
Sectigo
Penetration Tester (ME)
BreachLock
Principal Penetration Tester/ Offensive Security Team Lead
BreachLock
Developer - Application Development Microsoft N 4A
Genpact