Test Engineer (Security) ...
Government Digital & Data, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Staff Backend Engineer - ...
Grafana Labs, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Cloud Architect
Sitel, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Formal Methods Engineer -...
Io Global, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Lead Test Engineer (Secur...
Companies House, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Senior Test Engineer (Sec...
Companies House, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Application Support Analy...
Synectics Solutions, Stoke-upon-Trent, City of Stoke-on-Trent
- Full time
- Permanent
Apply on company site
Solution Architect
Version 1 Solutions Limited, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Lead Back End Developer
Cox Automotive, Broadeye, Stafford
- Full time
- Permanent
Apply on company site
MAXIMO Application Suite ...
General Dynamics Information Technology, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Network Architect
Cencora, Inc., Can be based anywhere.
- Full time
- Permanent
Apply on company site
People Analyst
The Wave, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Third Party Risk Lead
Admiral Group Plc, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Senior Software Engineer ...
Mozilla, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Juju Software Engineer (G...
Canonical Ltd., Can be based anywhere.
- Full time
- Permanent
Apply on company site
Senior Software Engineer ...
Canonical Ltd., Can be based anywhere.
- Full time
- Permanent
Apply on company site
IoT Platform Engineer
Canonical Ltd., Can be based anywhere.
- Full time
- Permanent
Apply on company site
Site Reliability Engineer
Sporty Group, Can be based anywhere.
- Full time
- Permanent
Apply on company site
Senior Jira Software Engi...
Canonical Ltd., Can be based anywhere.
- Full time
- Permanent
Apply on company site
IT Infrastructure Adminis...
Royal London Group, Nether Alderley, Cheshire East
- Full time
- Permanent
Apply on company site
Test Engineer (Security) - Companies House - HEO
Salary not available. View on company website.
Government Digital & Data, Can be based anywhere.
- Remote working
- Full time
- Permanent
Posted 1 week ago, 7 Jul
Job ref: 7d00197b335247bbb8196c72080a38b2
Full Job Description
This is an exciting opportunity in the Digital Services team! You'll be joining our team at a time of transformation, and you will be part of shaping the future of our department. We use Agile Methodologies and promote a culture of continuous improvement. We are looking for an enthusiastic Senior Test Engineer (Non-Functional Security) with great technical skills, able to deliver and support security testing workstreams, including vulnerability assessments and penetration testing. You will also offer guidance to other testers on security testing best practices. You will be part of our non-functional testing specialist team, working collaboratively with your team and overseeing the testing journey. This provides an opportunity to make the test community thrive by exploring new and emerging tools and approaches and working out how you can help the organisation deliver better services. This is a rewarding role within the Test Team and provides an opportunity to contribute to the success of existing and future services provided by Companies House., As a Senior Test Engineer focusing on security you will;
- Working within a delivery team, youll contribute to the coordination and execution of security testing across the software development lifecycle. This will involve running vulnerability scans using tools such as Burp, coordinating with relevant teams, testing security related issues.??
- Support the wider test team by sharing knowledge and guidance on security testing approaches and tooling.????
- Attend meetings and provide stakeholders with updates.??
- Design and implement pipeline solutions to support automated security testing and reporting.?
Experience in Security testing. - A relevant certification in ethical hacking or penetration testing, such as such as 7Safe CSTA or GIAC Penetration testing,?OR currently working towards this OR have proven working experience.???
- Working knowledge of at least 5 of the following security tools and technologies: 1. Burp Suite (including Burp Scanner) - for web app vulnerability scanning and manual security testing. 2. OWASP ZAP - for DAST and automated security regression testing. 3. Postman or SOAP UI - for API testing with a security focus (e.g. injection, authorisation, token misuse). 4. OAuth2 / OpenID Connect - for testing secure authentication and access control scenarios. 5. Jenkins or Concourse - for integrating security testing into CI/CD pipelines. 6. Unix/Linux-based systems - for using command-line tools, analysing logs, and running manual tests. 7. AWS (or similar cloud provider) - with a focus on IAM, S3 access, and common misconfiguration risks. 8. SQL / MongoDB / Oracle - for testing injection flaws, access controls, and data sanitisation. 9. Karate DSL or Rest Assured - for automating security-focused API tests. 10. Git or other version control systems - for secure code handling and integration with security scanners. 11. Static Application Security Testing (SAST) tools - e.g. SonarQube, Checkmarx, Semgrep. 12. Dynamic Application Security Testing (DAST) tools - e.g. OWASP ZAP, Burp Suite Pro.
- Making Effective Decisions
- Managing a Quality Service
- Working Together
- Seeing the Big Picture Technical skills We'll assess you against these technical skills during the selection process:
- Penetration testing / ethical hacking
Companies House offers a flexible and welcoming culture that promotes a healthy work life balance as well as a proactive approach to wellbeing that allows us to be our best at work. We recognise that people are the key to our success so offer a fantastic benefits package including flexible working with no core hours, 30 days annual leave, 8 bank holidays and 1 privilege day as well as enrolment into the Civil Service Pension scheme with a contribution rate averaging 28%. We're able to consider both full-time and part-time working patterns for this opportunity. For part-time, this must be a minimum of 30 hours per week, over 4 or 5 days., We'll assess you against these behaviours during the selection process: