CareerPlanSign in

Principal Penetration Tester (9 Month FTC)

Watford, Hertfordshire💼 Full-time🗓 2026-05-20 → 2026-08-07

Core

Senior penetration tester focusing on application security testing (70%) and offensive security activities (30%) to improve security depth and support purple team operations.

Role type

Principal Penetration Tester (Application Security & Offensive Security)

Builds

Security assurance for modern applications, APIs, backend services, and cloud-hosted workloads

Domain

Cybersecurity, Application Security, Offensive Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Application security testing, Penetration testing, API security, Cloud security (AWS), Binary analysis, OS exploitation, Threat modeling, SAST/DAST analysis, Authentication/Authorization testing

Preferred skills

Purple team development, Adversary informed assessments, ATT&CK aligned testing, Microservice architecture knowledge

Technologies

AWS, Spring Boot, RESTful APIs, Containerized environments, SAST tools, DAST tools

Responsibilities

Lead advanced penetration testing across web applications, APIs, and backend services; Assess Java-based backend systems and microservice architectures; Test authentication, authorization, and session handling; Carry out security testing in cloud and containerized environments; Review SAST/DAST outputs to prioritize risks; Support threat modeling and design reviews; Provide risk-based sign-off for releases.

Seniority

Principal, hands-on IC

Sourced via adzuna · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.