Ethical Hacker
$70,000–$95,000 year
HybridLondon, England, United Kingdom
Job Summary
Plan, execute, and report on simulated attacks across networks, web applications, APIs, mobile, and cloud environments. Conduct red team engagements including phishing, social engineering, and physical security assessments. Identify, document, and prioritize vulnerabilities while using manual techniques and automated tools like Burp Suite and Metasploit. Collaborate with remediation teams to harden systems and produce detailed technical reports for stakeholders. Stay current with the latest exploits and threat actor tactics. Fully remote or hybrid working options available.
Required Qualifications
- Strong proficiency in penetration testing tools (e.g., Kali Linux, Burp Suite, Metasploit, Nmap, Wireshark)
- Experience with OWASP Top 10, vulnerability scanning, and exploit development
- Familiarity with MITRE ATT&CK framework and red team methodology
- Solid knowledge of TCP/IP, firewalls, DNS, HTTP/HTTPS, and encryption protocols
- Strong reporting and communication skills
- At least one industry certification (OSCP, CEH, CREST CRT, or similar)
Desired Qualifications
- Scripting skills in Python, PowerShell, or Bash
- Experience with cloud security testing (AWS, Azure, GCP)
- Familiarity with CI/CD environments and DevSecOps
- Exposure to purple teaming or adversary emulation
- Knowledge of physical security and social engineering tactics
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.