Top Benefits
About the role
Who you are
- To succeed in this role, you’ll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks
- A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively
- Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell,
- Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security,
- Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills
- Ability to mentor junior testers and contribute to internal tooling
What the job involves
- As the Penetration Tester within the internal cybersecurity team, you’ll play a key role in identifying and mitigating security risks across the organisation’s digital landscape
- This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities
- You’ll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams
- Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats
- Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments
- Simulating real-world attack scenarios to assess system and infrastructure resilience
- Producing detailed technical reports and executive summaries for stakeholders
- Collaborating with internal teams to validate findings and support remediation efforts
- Staying up to date with emerging threats, vulnerabilities, and offensive security techniques
Benefits
- 23 days paid holiday plus UK bank holidays, increasing to 25 days after two years’ service
- Additional birthday day off
- Salary Sacrifice pension scheme with 4% employer contribution and minimum 5% employee contribution
- Optional BUPA private medical insurance for you and your immediate family
- Life assurance with a benefit of 4x your annual basic salary
- Employee Assistance Programme offering both on-line and telephone support and resources to you and your family
- Cycle to work scheme
- Active social and charity initiatives including our matched charitable giving scheme and employee recognition scheme
About Darktrace
Darktrace is a global leader in cybersecurity AI, providing the essential cybersecurity platform to secure organizations today and for an ever-changing future. Darktrace AI learns from each business's unique data in real time, detecting threats and intervening against attacks with precision and speed. We are a diverse and inclusive team of over 2,400 employees, each playing a crucial role in protecting nearly 10,000 organizations and communities worldwide from known, unknown, and novel cyber-threats.
Top Benefits
About the role
Who you are
- To succeed in this role, you’ll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks
- A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively
- Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell,
- Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security,
- Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills
- Ability to mentor junior testers and contribute to internal tooling
What the job involves
- As the Penetration Tester within the internal cybersecurity team, you’ll play a key role in identifying and mitigating security risks across the organisation’s digital landscape
- This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities
- You’ll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams
- Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats
- Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments
- Simulating real-world attack scenarios to assess system and infrastructure resilience
- Producing detailed technical reports and executive summaries for stakeholders
- Collaborating with internal teams to validate findings and support remediation efforts
- Staying up to date with emerging threats, vulnerabilities, and offensive security techniques
Benefits
- 23 days paid holiday plus UK bank holidays, increasing to 25 days after two years’ service
- Additional birthday day off
- Salary Sacrifice pension scheme with 4% employer contribution and minimum 5% employee contribution
- Optional BUPA private medical insurance for you and your immediate family
- Life assurance with a benefit of 4x your annual basic salary
- Employee Assistance Programme offering both on-line and telephone support and resources to you and your family
- Cycle to work scheme
- Active social and charity initiatives including our matched charitable giving scheme and employee recognition scheme
About Darktrace
Darktrace is a global leader in cybersecurity AI, providing the essential cybersecurity platform to secure organizations today and for an ever-changing future. Darktrace AI learns from each business's unique data in real time, detecting threats and intervening against attacks with precision and speed. We are a diverse and inclusive team of over 2,400 employees, each playing a crucial role in protecting nearly 10,000 organizations and communities worldwide from known, unknown, and novel cyber-threats.