Rapid7 Logo

Rapid7

Penetration Tester - InfoSec

Posted 4 Days Ago
Be an Early Applicant
Remote
Hybrid
Hiring Remotely in Belfast, County Antrim, Northern Ireland
Mid level
Remote
Hybrid
Hiring Remotely in Belfast, County Antrim, Northern Ireland
Mid level
As a Penetration Tester on the InfoSec team, you will focus on enhancing web application security through targeted penetration testing, vulnerability assessments, and remediation collaboration with development and engineering teams. The role involves performing security tests, providing technical reports, and mentoring team members, requiring hands-on experience and a passion for emerging threats.
The summary above was generated by AI

Do you enjoy attacking web apps, APIs, finding and abusing flaws in source code? Do you want exposure to network pentesting? Do you want to see the direct results of your work implemented? Do you want to dig deeper into a company's security posture and make an impact? Do you want to learn more about how the "blue" team works?
As a Pen Tester on our Information Security Operations team you will be fully integrated into the frontlines of Rapid7's security. Your skills and experience will be used to test and improve production applications and drive change into a full cycle cyber security program.
About the Team
Our Information security team is tasked with enhancing our security posture and elevating customer confidence in Rapid7 products. Together, we lead the effective delivery of business outcomes, and program maturation through standardization and iterative improvement.
As part of our team, you'll work with highly engaged and capable colleagues to build and implement complex, cross-functional initiatives that secure our business, our employees, and our customers.
About the Role
As a Penetration Tester on our InfoSec team, you'll play a crucial part in strengthening our organization's Information Security by focusing on web application penetration testing. You will contribute to enhancing our ability to identify, assess, and mitigate vulnerabilities within web applications, improving our overall security posture. Your responsibilities will include running targeted penetration tests, simulating adversarial tactics, and collaborating with both development teams and defensive security counterparts to address vulnerabilities.
We're looking for someone with hands-on experience in web application security, a solid understanding of penetration testing techniques, and a passion for staying ahead of emerging threats. If you're eager to drive real improvements to our security practices and work within a dynamic team, this position will offer opportunities to sharpen your skills while making a significant impact on our security program.
In this role, you will:

  • Perform web/API/mobile/code review/thick client application penetration testing and other testing where appropriate and as required (such as network, cloud, IoT);
  • Perform vulnerability/attack surface assessments and provide findings with remediation actions to leadership and device/software owners;
  • Provide well-written, concise, technical and non-technical reports in English;
  • Coordinate with development and engineering teams on remediating vulnerabilities;
  • Partner with our Security Operations Center (SOC) / Threat Hunt Team to operationalize new detection concepts
  • Coach and mentor team members where appropriate;
  • Perform any other appropriate job duties in line with the associated skill and experience of the post holder.


The skills you'll bring include:

  • Ideally 2-4 years of experience as a Web Application Penetration Tester with industry recognised security certifications (OSWE, CCT APP);
  • Proven industry experience with offensive security tools (such as Burp Suite, Postman, SAST/DAST tooling);
  • Strong understanding of OWASP and MITRE ATT&CK framework;
  • Demonstrable knowledge of how modern applications are designed and deployed across different platforms and how to abuse workflow logic;
  • Ability to program or script in your preferred language;
  • Experience leading web application penetration testing projects and acting as a lead technical point of contact;
  • Capable of working independently with minimal supervision


We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
About Rapid7
At Rapid7, we are on a mission to create a secure digital world for our customers, our industry, and our communities. We do this by embracing tenacity, passion, and collaboration to challenge what's possible and drive extraordinary impact.
Here, we're building a dynamic workplace where everyone can have the career experience of a lifetime. We challenge ourselves to grow to our full potential. We learn from our missteps and celebrate our victories. We come to work every day to push boundaries in cybersecurity and keep our 11,000+ global customers ahead of whatever's next.
Join us and bring your unique experiences and perspectives to tackle some of the world's biggest security challenges.
#LI-PB1

Top Skills

APIs
Burp Suite
Cloud
Dast
Iot
Mitre Att&Ck
Network Penetration Testing
Offensive Security Tools
Owasp
Postman
Sast
Web Application Penetration Testing

Similar Jobs at Rapid7

4 Hours Ago
Remote
Hybrid
Belfast, County Antrim, Northern Ireland, GBR
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
As a Software Engineer II in the Platform Delivery Automation & Governance team, you will focus on standardizing and automating security practices across the Rapid7 platform. You will collaborate with engineering and information security teams to enhance platform reliability and protect customer data, utilizing tools such as Terraform, Jenkins, and Docker.
Top Skills: BashJavaJavaScriptPythonRuby
7 Hours Ago
Remote
Hybrid
United Kingdom
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Manager of Vulnerability Research will lead a team of researchers, managing vulnerability analysis tasks, overseeing the vulnerability disclosure program, and advising on risk assessments. The role involves triaging new CVEs, delivering research reports, and collaborating with security engineers.
Top Skills: Exploit DevelopmentVulnerability Research
14 Hours Ago
Remote
Hybrid
Belfast, County Antrim, Northern Ireland, GBR
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
As a Senior DevOps Engineer, you will enhance the security and reliability of our microservices infrastructure. Responsibilities include automating operations, managing production infrastructure (Kubernetes, Cassandra), mentoring team members, and developing security measures for customer data while ensuring best practices in AWS.
Top Skills: Python,Ruby,Java,Groovy,Bash

What you need to know about the Manchester Tech Scene

Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account