CHECK or CREST Penetration Tester

Oscar Technology
Leeds, United Kingdom
3 weeks ago
£40,000 – £45,000 pa

Salary

£40,000 – £45,000 pa

Job Type
Permanent
Work Pattern
Full-time
Work Location
Hybrid
Seniority
Mid
Education
Degree
Security Clearance
Required
Posted
5 May 2026 (3 weeks ago)

Benefits

Company Pension Scheme

Role: Penetration Tester
Location: Leeds (Hybrid + Site Visits)
Salary: £40,000 - £45,000 DOE
Type: Permanent, Full-Time

Summary:

We are looking for a skilled and motivated Penetration Tester to join a growing security team in Leeds. The main purpose of this role is to deliver high-quality offensive security assessments across web applications, APIs, and infrastructure, helping clients understand and remediate vulnerabilities across their environments.

This is a great opportunity for a CHECK Team Member (CTM) or a tester actively progressing along the CREST pathway (CRT) to take ownership of engagements end-to-end, work alongside experienced consultants, and continue developing technically across a varied client base. This role operates on a hybrid basis in Leeds, with occasional site visits required.

Key Responsibilities:

  • Carry out web application, API, and infrastructure penetration tests, taking ownership of engagements from scoping through to final report delivery.
  • Support purple team activities including phishing simulations and malicious insider style assessments.
  • Produce clear, professional reports for clients, tailoring findings to client-specific context and business risk.
  • Communicate high-risk vulnerabilities to clients as they are identified, supporting swift remediation.
  • Support junior team members and assist with quality assurance on reports where required.
  • Assist with the maintenance of internal penetration testing infrastructure, including device setup and tooling updates.
  • Stay up to date with the evolving threat landscape, contributing to internal knowledge sharing and continued team development.


Requirements:

  • CHECK Team Member (CTM) status, or actively working towards CREST Registered Tester (CRT) on the CREST pathway.
  • Hands-on experience delivering web application, API, and/or infrastructure penetration tests in a professional setting.
  • Strong understanding of common vulnerability classes (e.g. OWASP Top 10), exploitation techniques, and remediation guidance.
  • Confident client-facing communication skills, with the ability to explain technical findings to both technical and non-technical audiences.
  • Strong written reporting skills, with the ability to produce clear, well-structured deliverables.
  • A genuine passion for offensive security, demonstrated through CTFs, labs (e.g. Hack The Box, TryHackMe), research, or community involvement.


Benefits:

  • Salary: £40,000 - £45,000 DOE
  • Hybrid Working
  • Company Pension Scheme

Role: Penetration Tester
Location: Leeds (Hybrid + Site Visits)
Salary: £40,000 - £45,000 DOE
Type: Permanent, Full-Time

Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.

To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Related Jobs

View all jobs

CHECK Team Leader Penetration Tester

Oscar Technology London, United Kingdom
£80,000 – £90,000 pa Remote Clearance Required

Security Architect

Meritus Andover, Hampshire, United Kingdom
£800 – £900 pd On-site Clearance Required

Senior Cyber Security Engineer

Pertemps Thames Water Reading, Berkshire, United Kingdom
£78,000 pa Hybrid Clearance Required

Senior Cyber Security Engineer

Thames Water Rg18Db, RG1 8DB, United Kingdom
Hybrid Clearance Required

Principal Engineer (Microsoft)

Claranet Wc2E7Bb, WC2E 7BB, United Kingdom
On-site Clearance Required

Senior Channel Account Executive

Sophos United Kingdom
Remote

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.