Penetration Tester Jobs

Ethical hackers who simulate cyber attacks to identify vulnerabilities. A critical role in safeguarding digital assets and ensuring robust security.

Open roles
6
Salary range
£40k – £85k
Hiring companies
6

Penetration testers, also known as ethical hackers, play a vital role in the cyber security landscape. They simulate real-world cyber attacks to identify and mitigate vulnerabilities in systems, networks, and applications. These professionals are hired by a range of organisations, from scaleups and research-heavy startups to larger consultancies, to ensure that digital defences are robust and resilient.

What the role does

Inside the role of a Penetration Tester

A typical week for a penetration tester is a mix of planning, execution, and reporting. They spend time researching attack vectors, conducting tests, and documenting findings.

  1. 01
    Conduct initial reconnaissance on target systems
  2. 02
    Execute simulated attacks to identify vulnerabilities
  3. 03
    Document findings and prepare detailed reports
  4. 04
    Collaborate with development teams to address identified issues
  5. 05
    Stay updated on the latest security threats and techniques
  6. 06
    Participate in debriefing sessions with clients or stakeholders
Salary on the board

£40k – £85k

Based on advertised midpoints across the 20 priced listings posted in the last 12 months. Base salary only.

Salary visibility
4% of listings advertise a salary — up from 0% the year before.
By seniority
£k base
Mid
40
81
12 jobs
Skills & tools

What hiring managers ask for

% of 17 listings posted in the last 12 months that mention each skill, extracted from job descriptions.

Penetration Testing
94%
OSCP
53%
Web Application Security
53%
Vulnerability Assessment
47%
Cloud Security
41%
Burp Suite
35%
Network Security
29%
CREST
29%
Nmap
29%
Metasploit
29%
Infrastructure Testing
24%
Nessus
24%
Career ladder

From Junior to Principal

A typical UK progression for penetration testers. Years are guidance — strong people move faster, and many senior folks sidestep into research, product or management.

  1. Level 1

    Junior Penetration Tester

    0–2 yrs

    Assists in planning and executing basic penetration tests under supervision. Focuses on learning and understanding security testing methodologies.

  2. Level 2

    Penetration Tester

    2–5 yrs

    Conducts comprehensive penetration tests independently. Owns the execution and reporting of test results, and provides recommendations for remediation.

  3. Level 3

    Senior Penetration Tester

    5–8 yrs

    Leads complex penetration testing projects. Mentors junior team members and collaborates with clients to develop and implement security strategies.

  4. Level 4

    Principal Penetration Tester

    8+ yrs

    Oversees the entire penetration testing function. Develops and standardises testing methodologies, and advises on high-level security policies and practices.

Pathway

How to become a Penetration Tester

There's no single route, but most people follow some version of these steps.

  1. 1

    Learn the Basics

    Start with foundational knowledge in networking, programming, and security principles. Gain hands-on experience through courses and certifications.

  2. 2

    Gain Practical Experience

    Work on real-world projects, either through internships or entry-level roles. Build a portfolio of penetration testing reports and case studies.

  3. 3

    Specialise in Tools and Techniques

    Develop expertise in specific tools and techniques used in penetration testing. Stay updated with the latest trends and threats in the cyber security landscape.

  4. 4

    Lead Projects and Teams

    Take on leadership roles, managing complex penetration testing projects and mentoring junior team members. Collaborate with clients to implement security solutions.

  5. 5

    Advise on Security Strategy

    Provide strategic advice on security policies and practices. Influence organisational decisions and contribute to the development of industry standards.

Live jobs

6 live roles

Penetration Tester

This role involves conducting comprehensive penetration tests across IT, web applications, and Operational Technology environments, including industrial control systems. The candidate will identify vulnerabilities, produce actionable reports, and collaborate with internal teams and third parties to strengthen security posture. The position offers deep technical engagement with critical infrastructure and opportunities to influence security improvements across high-impact systems.

Yolk Recruitment Cardiff, South Glamorgan, CF10 2AF, United Kingdom £71,000 – £81,000 pa
Hybrid Permanent Clearance Required

Penetration Tester

This role involves conducting comprehensive penetration tests across networks, web and mobile applications, APIs, and cloud environments using both manual and automated techniques. The tester will simulate real-world cyberattacks, identify vulnerabilities, and produce detailed technical and executive reports with actionable remediation advice. A key focus is translating complex security findings for non-technical stakeholders while adhering to strict ethical and compliance standards in a security-cleared context.

SmartSourcing Ltd United Kingdom £60,000 – £80,000 pa
Remote Permanent Clearance Required

Penetration Tester

This role involves conducting comprehensive penetration tests across internal/external infrastructure, web applications, and networks, using industry-standard tools like Burp Suite, Metasploid, and Nmap. The candidate will produce detailed technical reports, support client engagements, and contribute to research and development in emerging security areas such as OT and threat-led testing. The position supports professional growth with certification opportunities and progression into advanced offensive security disciplines.

Big Red Recruitment Midlands Limited London, United Kingdom £45,000 – £55,000 pa
Hybrid Permanent Clearance Required

Penetration Tester

This role involves conducting web, mobile, and infrastructure penetration tests, delivering detailed technical reports, and providing expert remediation advice to clients. The Penetration Tester will collaborate on digital transformation projects, engage in research and development, and expand their skills across red teaming and social engineering. A strong focus on client interaction and professional communication is required, with opportunities to achieve CREST certifications.

Claranet Leeds, West Yorkshire, United Kingdom
Hybrid Permanent Clearance Required
Bridewell logo

Senior Penetration Tester - CTL

Conduct infrastructure and web application penetration tests for clients, contributing to the development of new testing methodologies. Includes dedicated time for research and access to training platforms and certifications to support professional growth.

Bridewell London, United Kingdom
Hybrid Permanent

Junior Penetration Tester

This role involves conducting penetration tests across various applications, with a focus on learning and developing skills in offensive security. The company provides a 6-month training period to help you start your career in this field.

Akkodis London, United Kingdom £25,000 – £30,000 pa
Hiring locations

Where this role is hiring

The locations with the most live listings for this role today.

FAQs

Common questions

  • A degree in computer science or a related field is beneficial, but practical experience and relevant certifications like CEH or OSCP are highly valued.

  • Participate in industry conferences, join professional groups, and follow leading security blogs and forums. Continuous learning is crucial in this field.

  • Salary ranges can vary widely based on experience and location. For more detailed information, refer to the salary section on this page.

  • Strong technical skills in networking and programming, a deep understanding of security principles, and the ability to think creatively and solve complex problems are essential.

Hiring penetration testers?

Post your role in 90 seconds and reach the specialist audience that already reads this page.