Penetration Tester - UK (Remote)
CognisysPenetration Tester - UK (Remote) Location: UK (Remote) Salary: Competitive Compensation About Cognisys Cognisys is a global cybersecurity company specialising in Penetration Testing, GRC Consulting and Managed Security services . We work with organisations across more than 30 countries, helping them identify risk, strengthen their security posture and navigate an increasingly complex cybersecurity landscape. We're a small but mighty team with ambitious plans for growth. We combine deep technical expertise with a strong focus on customer service, practical advice and delivering meaningful outcomes for our clients. Our people are at the heart of what we do. We value Together, Ownership, Momentum and Excellence, and we want people who are curious, collaborative and willing to take ownership of their work. As we continue to grow, you'll have the opportunity to work alongside experienced cybersecurity professionals, contribute to challenging client engagements and help shape the way we deliver our services. We believe in giving our people the opportunity to develop, share ideas and make a genuine impact. The Opportunity Are you ready to make an impact in the fast-paced world of cybersecurity? Cognisys is growing rapidly, and we're looking for a Pen Tester to join our team during an exciting period of innovation and expansion. As a Pen Tester , you'll be responsible for delivering and supporting security assessments across a range of client environments, including networks, applications and cloud infrastructure. You'll use a combination of automated tools and manual techniques to simulate real-world attack scenarios, identify meaningful vulnerabilities and help clients understand and address their security risks. This is a client-facing role where technical expertise is only part of the job. You'll also need to communicate your findings clearly, produce high-quality reports and help both technical and non-technical stakeholders understand the risks and practical steps they can take to improve their security posture. What You'll Be Doing Penetration Testing & Security Assessments Conduct penetration testing across networks, web applications, APIs, mobile applications and cloud environments. Simulate real-world attack scenarios to assess client resilience against cyber threats. Use a combination of automated vulnerability scanning tools and manual testing and exploitation techniques. Identify, analyse and exploit security vulnerabilities across diverse client environments. Assess the effectiveness of technical security controls and identify opportunities for improvement. Apply appropriate offensive security methodologies, tools and techniques throughout engagements. Stay up to date with emerging vulnerabilities, attack techniques and industry developments. Client Delivery & Communication Work directly with clients throughout penetration testing engagements. Present findings and recommendations clearly and professionally. Help clients understand the potential business and technical impact of identified vulnerabilities. Communicate complex technical concepts in a way that is accessible to non-technical stakeholders. Support clients in understanding and prioritising remediation activities. Build positive and professional relationships with client stakeholders. Reporting & Quality Produce high-quality technical reports following each engagement. Clearly document vulnerabilities, exploitation techniques, evidence, risk and remediation recommendations. Ensure technical findings are accurate, well-evidenced and easy for clients to understand. Translate technical detail into clear, practical recommendations for both technical and executive audiences. Maintain Cognisys' high standards for quality, consistency and client service. Team Contribution & Development Work collaboratively with the wider cybersecurity team. Share knowledge, techniques and lessons learned with colleagues. Contribute to the continued development of Cognisys' penetration testing methodologies and ways of working. Take ownership of your continued technical and professional development. Support a culture of learning, collaboration and continuous improvement. About You We're looking for someone with a strong technical foundation in offensive security who is equally comfortable working with clients and communicating technical findings. You'll ideally have: Hands-on experience conducting penetration testing and security assessments. Experience using vulnerability scanning tools alongside manual testing and exploitation techniques. A strong understanding of offensive security methodologies, tools and techniques. A strong grasp of how to assess and break technical controls, with the ability to explain the findings clearly to clients. Experience across one or more of the following areas: Network penetration testing Web application testing API testing Mobile application testing Cloud security testing Strong analytical and problem-solving skills. Excellent written and verbal communication skills. The ability to communicate technical vulnerabilities and risks in a clear, non-technical format. Strong client engagement skills and a professional approach to customer service. The ability to manage your workload effectively and deliver work to agreed deadlines. A proactive approach to learning and keeping up to date with developments in offensive security. Certifications The following certifications are highly regarded: Industry-recognised certifications are preferred and may include: OSCP CPSA CRT CREST-related certifications Other relevant penetration testing or offensive security certifications Relevant practical experience will also be considered alongside formal certifications. What Success Looks Like Success in this role means becoming a trusted technical consultant who can independently deliver high-quality penetration testing engagements while providing an excellent client experience. For Example: Deliver thorough, accurate and professional penetration testing engagements across a variety of client environments. Confidently assess and exploit vulnerabilities using a combination of automated tools and manual testing techniques. Demonstrate a strong understanding of how technical controls can be assessed, bypassed and exploited in realistic attack scenarios. Produce clear, detailed and actionable technical reports that help clients understand their vulnerabilities and how to remediate them. Communicate technical findings effectively to both technical teams and non-technical stakeholders. Present findings and recommendations confidently to clients and support them in prioritising remediation. Take ownership of your engagements, managing your testing, documentation and deliverables effectively. Continue to develop your technical knowledge and stay current with evolving offensive security techniques, tools and threats. Contribute positively to the wider penetration testing team by sharing knowledge, supporting colleagues and continuously looking for ways to improve our approach. Why Join Us? At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged. What we Offer: Annual Leave: 25 days per year plus 8 English bank holidays. Additional Leave: 1 day of paid leave for your Birthday. Health & Wellbeing: Access to Westfield Health Care Cash Plan and an employee mental health and wellbeing platform. Professional Development: £2,000 annual training budget to support your continued learning and career growth. Referral Bonus: help to grow our team and earn up to £2,000 per successful referral. Applications We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page. Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.group We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs. Department Tech Team Role Security Consultant Locations UK - HQ Remote status Fully Remote Applicant tracking system by Teamtailor