Junior Penetration Tester
Indexed description
Role Summary
As a security company, Sophos takes its own security very seriously and has a Cyber Security team which focuses on protecting our own products, systems and infrastructure. We’ll need you to contribute to the continual improvement of our security posture through the testing of Sophos applications and infrastructure. This role is not customer facing which means you not only get to perform tests but also see the impact of your findings as you help the teams design and architect resolutions to the issues you find.
The ideal candidate will have real-world experience in a Red Team and previously worked on all stages of penetration testing from scoping to reporting.
You’ll need to be highly motivated, have an innovative mind-set and a good attention to detail. You will need to stay up to date with the latest techniques and threats and apply this knowledge to help protect Sophos and our customers.
This a great opportunity to help secure a world-leading cybersecurity company. As you’d expect you’ll be joining an organization that takes security seriously. You will become a key member of the Cyber Security team working with some world-leading experts from across the company in a fast-paced and varied environment where security is a priority.
What You Will Do (Duties and Responsibilities)
-
Organize, plan and deliver penetration tests against Sophos web applications across a wide range of technologies
-
Organize, plan and deliver penetration tests against the Sophos infrastructure including on-premise networks, AWS/Azure and virtual environments
-
Use AI-assisted workflows (including internal agents/skills where available) to augment penetration testing activities and improve coverage and efficiency, with appropriate oversight and review
-
Assist in the scoping, planning and delivery of pentests by 3rd party vendors
-
Disseminate results to teams throughout the business
-
Work closely with the wider Cybersecurity team to develop common goals and outcomes
What You Will Bring (Experience and Qualifications)
-
A solid background in both application and infrastructure penetration testing
-
Familiarity with common web technologies (PHP, Javascript, API etc)
-
Good knowledge of offensive techniques, OWASP & MITRE ATT&CK frameworks
-
Experience working with or assessing systems that incorporate AI or LLMs, including an understanding of common AI‑related security risks and abuse scenarios
-
Experience in delivery of security testing projects
-
Practical knowledge of AWS technologies (S3, EC2, IAM, Lambda etc)
-
Good interpersonal & networking skills
-
Industry recognised ethical hacking qualifications: OSCP, GPEN or equivalent
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search