Principal Penetration Tester (9 Month FTC)
Core
Senior penetration tester strengthening application security testing and offensive security capabilities for a national lottery operator's systems and services.
Role type
Principal Penetration Tester (Application Security & Offensive Security)
Builds
Security testing standards, playbooks, and internal purple team methodology for a multi-national lottery operator.
Domain
Cybersecurity, Application Security, Offensive Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application penetration testing, Java/Spring Boot, RESTful APIs, microservices, AWS/cloud security, Linux/Windows exploitation, binary exploitation, manual testing, threat modelling, security standards development
Preferred skills
Mobile application assessment, secure code review, ATT&CK informed assessments, EDR/AV evasion concepts, hardware/embedded testing, WAF technology
Technologies
Java, Spring Boot, RESTful APIs, AWS, Linux, Windows, SAST, DAST, EDR, AV
Responsibilities
Lead advanced penetration testing across web applications, APIs, and cloud-hosted services; develop internal purple team methodology; coach team members on testing standards and reporting; support threat modelling and design reviews; assess authentication, authorization, and data exposure risks.
Seniority
Principal, hands-on IC with mentorship responsibilities