Logo for CyberOne

Penetration Tester

Role overview

Qualifications

  • Proven experience conducting penetration tests across enterprise networks and infrastructure
  • Strong knowledge of Windows environments and Active Directory security
  • Excellent understanding of network protocols and architecture

Responsibilities

  • Conduct comprehensive penetration testing engagements against enterprise infrastructure, networks, systems, and applications
  • Perform manual and automated security assessments to identify vulnerabilities, weaknesses, and potential attack vectors
  • Assess and exploit Active Directory environments, identifying security risks including misconfigurations and privilege escalation paths

Key facts

Hard skills

Other skills

  • Analytical Skills
  • Troubleshooting (Problem Solving)
  • Problem Solving

About the company

CyberOne logo

CyberOne

Cybersecurity

CyberOne is trusted by some of the world's most admired brands and organisations to secure their most important asset, their employee, customer and business data. Bringing together the industry's brightest talent and best technologies, our comprehensive end-to-end cyber security services offer a complete protection and recovery service, ensuring resilience against an ever-evolving and increasing threat landscape, delivering relentless 24x7 round-the-clock threat monitoring and incident response, so clients can focus on what they do best. We harness the class-leading Microsoft Security portfolio and combine it with our proprietary technology, to give complete comprehensive Cyber Security resilience. CyberOne delivers the entire Microsoft Security stack as a fully managed service, called Assure 365. Covering all your Security administration and key technology areas such as Identity, MXDR, Endpoint, XDR and Data Security as a Service ensures our clients have time to focus on their strategic, governance and risk objectives. CyberOne is accredited and authorised by the world’s leading standards bodies including the National Cyber Security Centre (NCSC), part of GCHQ in the UK and CREST, across all key areas including Security Operations Centre, Incident Response and Penetration Testing. We are a highly accredited Microsoft Security partner and have a unique approach to delivering MXDR and Security Managed Services to our global client base. Since 2005, CyberOne's mission has been to reduce business risk whilst increasing its operational resilience. We are client and service-centric and our shared values help to support this goal: Customer Defence Focussed, Relentless Innovation, Act Kind - Be Kind, Be Awesome - Demand Awesome and Execute 100%. Cyber security is not just about providing a service, it’s about building a partnership and a secure foundation for your business to thrive. Securing today, safeguarding tomorrow.

Company details

IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant

About CyberOne

CyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio—across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance.

Job Title: Penetration Tester

Location: Remote

Employment Type: Full-time

We are seeking a highly skilled and motivated Penetration Tester to join our Cyber Security team. The successful candidate will be responsible for conducting advanced penetration testing engagements across enterprise environments, with a particular focus on Active Directory (AD) security assessments. This role requires hands-on experience identifying, exploiting, and documenting security vulnerabilities while providing practical remediation recommendations to strengthen clients' security posture.

Key Responsibilities

  • Conduct comprehensive penetration testing engagements against enterprise infrastructure, networks, systems, and applications.

  • Perform manual and automated security assessments to identify vulnerabilities, weaknesses, and potential attack vectors.

  • Assess and exploit Active Directory environments, identifying security risks including:

    • Misconfigurations

    • Privilege escalation paths

    • Lateral movement opportunities

    • Credential theft vulnerabilities

    • Excessive permissions and insecure delegation

  • Execute network and system exploitation activities to validate security weaknesses and assess their impact.

  • Evaluate the effectiveness of security controls, hardening measures, and defensive configurations within Active Directory environments.

  • Simulate real-world attack scenarios to assess organizational resilience against cyber threats.

  • Develop detailed technical reports outlining attack paths, findings, business impact, proof-of-concept evidence, and remediation recommendations.

  • Present technical findings to both technical and non-technical stakeholders.

  • Work closely with internal teams and clients to support remediation efforts and provide security best-practice guidance.

  • Stay up to date with emerging threats, attack techniques, exploitation methodologies, and security technologies.

Required Skills & Experience

  • Proven experience conducting penetration tests across enterprise networks and infrastructure.

  • Strong knowledge of Windows environments and Active Directory security.

  • Experience identifying and exploiting Active Directory vulnerabilities and attack paths.

  • Excellent understanding of:

    • Network protocols and architecture

    • Windows Server administration

    • Authentication mechanisms (Kerberos, NTLM)

    • Privilege escalation techniques

    • Lateral movement methodologies

  • Hands-on experience with penetration testing and red team tools such as:

    • BloodHound

    • Mimikatz

    • CrackMapExec

    • Impacket

    • Nmap

    • Burp Suite

    • Metasploit

    • Responder

  • Familiarity with vulnerability assessment and security testing methodologies including OWASP, NIST, and PTES.

  • Strong technical documentation and report-writing skills.

  • Excellent analytical, troubleshooting, and problem-solving abilities.

Preferred Qualifications

  • Offensive Security Certified Professional (OSCP)

  • CRTO (Certified Red Team Operator)

  • CREST Registered Penetration Tester (CRT) or CREST Certified Infrastructure Tester (CCT INF)

  • GIAC Penetration Tester (GPEN)

  • Relevant Microsoft security certifications

  • Experience delivering internal or external client-facing security assessments

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Penetration Tester Related jobs

Other jobs at CyberOne

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.