Baker McKenzie

Security Vulnerability and Penetration Testing Engineer

Baker McKenzie

Belfast, Northern Ireland, United Kingdom · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
5 days ago
Work mode
In office
Education
Bachelor's in Computer Science or equivalent
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

The Security Vulnerability and Penetration Testing (VAPT) Engineer acts as the principal technical resource for all vulnerability assessments and penetration testing activities within the organization. This position is tasked with evaluating the security posture of current and future systems, platforms, and processes, ensuring the protection and enhancement of confidentiality, integrity, and availability of information assets aligned with the firm's objectives, compliance standards, and strategic goals.

Key Responsibilities

  • Lead penetration testing efforts across organizational systems, applications, and platforms.
  • Serve as the Subject Matter Expert for all VAPT-related tools, techniques, platforms, and processes.
  • Develop and maintain core VAPT infrastructure, ensuring tools and methodologies are up to date.
  • Produce clear, tailored technical assessment reports and provide actionable recommendations grounded in cybersecurity best practices and risk management principles.

Required Skills and Experience

  • In-depth knowledge of vulnerability assessment and penetration testing methodologies, including white-hat ethical hacking standards.
  • Clear understanding of the distinctions between vulnerability assessments and penetration tests regarding scope, goals, and deliverables.
  • Proficient with automated VAPT tools such as Nessus, Appscan, Burp Suite, Nipper, and Trustwave.
  • Skilled in using attack frameworks and tools including Wireshark, Kali Linux, and Metasploit.
  • Expertise in mobile platform security, including tools for discovering and exploiting vulnerabilities, and adherence to mobile security frameworks.
  • Competence in validating identified vulnerabilities with high accuracy.
  • Deep understanding of common application platforms and technologies to evaluate complex apps with manual testing using proxies and browser plugins.
  • Authoritative knowledge of OWASP guidelines, CVEs, general security controls, and the latest exploits affecting applications and operating systems.
  • Familiarity with scripting and programming languages is advantageous.
  • Experience with API security testing methodologies is highly desirable.
  • Demonstrated ability to leverage AI technologies to improve penetration testing and evaluate risks associated with AI-powered applications and agents.
  • Committed to tracking evolving cyber threats and adversary tactics, adapting methodologies swiftly.
  • Capable of maintaining focus and critical thinking under high-pressure situations.
  • Excellent communication skills, able to explain complex technical topics to non-technical stakeholders, with proficiency in written and spoken English.
  • Willingness to contribute to the creation of internal training content and documentation.
  • Ability to work independently without continuous supervision.
  • Strong understanding of VAPT within the context of overall risk management and organizational priorities.
  • Passionate about achieving and maintaining excellence in VAPT practices.

Qualifications

  • Bachelor's degree in Computer Science or equivalent substantial experience.
  • Certified Information Systems Security Professional (CISSP) certification is mandatory.
  • GIAC certifications such as GPEN, GAIPT, or GWAPT are preferred.
  • Offensive Security Certified Professional (OSCP) certification required.

Reporting

This position reports directly to the Manager of the Vulnerability & Penetration Testing team within the Market & Centre Services Development Framework as a Specialist role.

Minimum education

Bachelor's Degree

Industry

Legal Services

Tools & software

Wireshark required Metasploit required Tenable Nessus required Kali Linux required Burp Suite required

How they work

Communication Problem Solving Attention to Detail Adaptability Independence

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer