Job Description
We are seeking a world-class Senior Penetration Tester to join our elite security operations team in London. At Apex Cyber Defense, we don't just defend; we proactively hunt for vulnerabilities before malicious actors can exploit them. You will be responsible for conducting complex red team engagements, performing deep-dive vulnerability assessments, and ensuring our clients' infrastructure remains impenetrable.
Why Join Apex?
• Impactful Work: Protect critical infrastructure and high-profile assets.
• Top-Tier Tools: Access to the latest commercial and open-source security frameworks.
• Remote-First Culture: Flexible working arrangements with a focus on work-life balance.
• Growth: Continuous learning opportunities and clear pathways to leadership roles.
Responsibilities
- Execute Red Team Operations: Plan and conduct realistic, multi-stage cyberattacks against internal and external networks to evaluate defensive measures.
- Vulnerability Assessment: Perform comprehensive security audits and penetration tests on web applications, network systems, and mobile platforms.
- Report Generation: Produce detailed, actionable technical reports for stakeholders, clearly articulating findings, risk levels, and remediation strategies.
- Tool Development: Contribute to the development and automation of custom penetration testing tools and scripts to increase testing efficiency.
- Threat Modeling: Collaborate with software engineering teams to design secure architectures and identify potential attack vectors during the development lifecycle.
- Training & Mentorship: Mentor junior security analysts and conduct internal security awareness training sessions.
Qualifications
- Certifications: Active OSCP or CISSP certification is highly preferred; CCE or CEH is required.
- Experience: Minimum of 5 years of professional experience in penetration testing or red teaming.
- Technical Skills: Proficiency in Python, Bash, or PowerShell scripting for automation.
- Knowledge: Deep understanding of the OWASP Top 10, common web vulnerabilities (XSS, SQLi), and network protocols.
- Tools: Hands-on experience with tools such as Burp Suite, Metasploit, Wireshark, and Nmap.
- Soft Skills: Excellent communication skills with the ability to explain complex technical concepts to non-technical stakeholders.