Deliver hands-on penetration tests across web applications, APIs, and network infrastructure, plus Cyber Essentials Plus and wider technical security reviews. Identify and validate vulnerabilities, explain business risk, and provide remediation. Produce reports, present findings, manage engagement scope, and contribute to advisory work, business development, and continuous improvement of methodologies and tooling.
Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors.
This is a hands-on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client.
Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges.
We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice.
This is a hands-on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client.
Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges.
We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice.
Key Responsibilities
- Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure.
- Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs.
- Apply manual and tool-assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK.
- Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements.
- Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance.
- Produce clear, high-quality deliverables and present findings to technical and non-technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting.
- Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice.
- Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services.
- Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance.
- Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability.
Skills, Knowledge and Expertise
Essential
- Professional experience delivering client-facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team.
- Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus.
- Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language.
- Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths.
- Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS.
- Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required.
- Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data.
- Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports.
- Strong verbal communication and stakeholder-management skills, with the ability to explain technical findings, risk, and business impact to technical and non-technical audiences.
- A proactive, client-oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale-ups to larger enterprises.
Desirable
- A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification.
- Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social-engineering assessments.
- Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands-on security or IT engineering experience such as hardening systems and implementing technical controls.
- An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls.
Benefits
About
At Moore Kingston Smith, we believe in the potential of people to make a positive impact, fuelled by the power of genuine understanding. Working with small, medium and large clients, we are a multi-disciplinary advisory, tax and audit firm with expertise across multiple sectors, uniquely positioned to help people realise their ambitions. Our London and regional teams deliver quality results locally and nationally, and worldwide alongside the Moore Global network. Through respect, collaboration and active listening, understanding is at the heart of everything we do with our clients, colleagues and communities. We value people and projects that promote positive change for the future. Come and join us to make a difference.
Moore Kingston Smith London, England Office
London, United Kingdom
Moore Kingston Smith Hayes, England Office
Hayes, United Kingdom
Moore Kingston Smith Reigate and Banstead, England Office
Reigate and Banstead, United Kingdom
Moore Kingston Smith Romford, England Office
Romford, United Kingdom
Moore Kingston Smith St Albans, England Office
St Albans, United Kingdom
Similar Jobs
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Own deal economics and final approvals for Samsara’s EMEA Mid-Market portfolio. Evaluate discounts, payment terms, and non-standard requests against policy; escalate exceptions; protect revenue and quarter-end metrics; and manage a high-volume deal queue. Partner with Sales, Legal, Finance, and customers, provide guidance on deal structuring, train Sales on policies, and improve deal desk processes using AI tools and systems expertise.
Top Skills:
Ai ToolsCpqCrm SystemsExcelGoogle SheetsSalesforce
AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Own the strategic vision and roadmap for Expedia Group’s sponsored listings auction platform. Lead auction mechanics, bidding, pricing, ad relevance, and optimization initiatives to improve traveler experience, partner ROI, marketplace efficiency, and revenue. Partner with engineering, machine learning, data science, and business teams to deliver technical products, define metrics, analyze performance, and use experimentation and AI tools to guide decisions. Communicate strategy and results to senior stakeholders while driving innovation in digital advertising and marketplace technology.
Top Skills:
AgileAuction OptimizationGenerative AiLarge Language ModelsMachine LearningProgrammatic AdvertisingSponsored Search
AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Lead CRM data and platform initiatives for outbound channels (email, push, in-product). Define data requirements, support a platform transition, build and QA audiences/content, collaborate with engineers, data scientists, and marketers to enable personalized automated journeys and measure CRM performance.
Top Skills:
AmpscriptAutomation StudioBig Data TechnologiesCloud TechnologiesConfluenceCSSEinsteinEmail StudioExcelGtlHTMLIntelligence ReportsJIRAJourney BuilderPowerPointSalesforce Marketing CloudSQLSsjs
What you need to know about the London Tech Scene
London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.


.png)