Moore Kingston Smith
Cyber Security Consultant
Job Description
Salary: £40,000 - 80,000 per year
Requirements:- Professional experience delivering client-facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team.
- Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus.
- Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language.
- Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths.
- Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS.
- Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required.
- Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data.
- Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports.
- Strong verbal communication and stakeholder-management skills, with the ability to explain technical findings, risk, and business impact to technical and non-technical audiences.
- A proactive, client-oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale-ups to larger enterprises.
- A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification, is desirable.
- Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social-engineering assessments, is desirable.
- Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands-on security or IT engineering experience such as hardening systems and implementing technical controls, is desirable.
- An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls, is desirable.
- Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure.
- Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs.
- Apply manual and tool-assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK.
- Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements.
- Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance.
- Produce clear, high-quality deliverables and present findings to technical and non-technical stakeholders.
- Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting.
- Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice.
- Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services.
- Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance.
- Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability.
- API
- AWS
- Active Directory
- Azure
- Bash
- Cloud
- GCP
- Support
- Linux
- Microsoft 365
- Mobile
- Network
- OWASP
- PowerShell
- Python
- Security
- TCP/IP
- Web
- Windows
- Office 365
More:
Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. We are an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands-on hybrid role focused primarily on technical delivery, with at least 70% of time spent on penetration testing and wider technical security reviews, while up to 30% may be spent on broader cyber security engagements to broaden consulting expertise. We offer the opportunity to deepen offensive security skills and contribute to the growth of a collaborative, commercially focused cyber security practice. The role is in our Cyber department on a permanent, full-time basis.
last updated 36 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Moore Kingston Smith
Moore Kingston Smith
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£60,000
This role
£55,000
UK median
This salary is 9% above the UK median for UK tech roles (£55,000/yr).
Based on 2024–2025 UK technology sector benchmarks