Organisation: Cyber and Fraud Centre Scotland
Location: Scotland (hybrid working)
Contract: Permanent / Full‑time (4 day week)
Salary: £35,000 - £45,000 depending on experience
About the Cyber and Fraud Centre
The Cyber and Fraud Centre Scotland supports organisations across Scotland to strengthen their resilience against cybercrime and fraud. We are Scotland’s only cyber social enterprise working at the intersection of cyber security, threat intelligence, and harm prevention, we partner with businesses, public sector bodies, and law enforcement to reduce risk and improve security maturity nationwide.
We are a small, high performing team with our values: ethical, integrity and making a difference at the heart of everything we do. We are working to bring cyber safety to organisations around Scotland. The threat landscape is constantly evolving, and this is an exciting time to join us as we continue to grow and expand our services. As demand for our trusted, high‑quality assurance services grows, we are expanding our technical team and are seeking a Penetration Tester to play a key role in delivering impactful testing and advisory work.
The Role
You will deliver high‑quality, ethical penetration testing engagements aligned with CREST standards. A hands‑on technical role with opportunities to grow and develop your skills as part of a social enterprise contributing to Scotland’s wider cyber resilience ecosystem.
A hands‑on technical role with opportunities to grow and develop your skills as part of a social enterprise contributing to Scotland’s wider cyber resilience ecosystem.
Key Responsibilities
- Deliver CREST‑aligned penetration testing engagements, including:
- Infrastructure and network testing
- Web and application testing
- Cloud and hybrid environments
- Execute tests in line with agreed methodologies and best practice
- Produce clear, high‑quality technical and executive‑level reports
- Communicate findings and risk in a clear, constructive manner to a range of stakeholders
- Support remediation discussions and re‑testing where required
- Maintain accurate records and testing artefacts in line with governance and assurance requirements
- Contribute to continuous improvement of tools, methodologies, and internal knowledge sharing.
- Stay informed about emerging cyber threats, fraud trends, and regulatory changes affecting organisations.
- Achieve and maintain CREST accreditation.
About you
You will be joining a caring and committed team with a strong sense of purpose.
Essential Skills & Experience
- 1-2 years of proven experience delivering penetration testing in professional or client‑facing environments.
- Understanding of common vulnerabilities and attack techniques (e.g. OWASP Top 10, MITRE ATT&CK).
- Experience with industry‑standard tools (e.g. Burp Suite, Nmap, Metasploit, Nessus or equivalents).
- Ability to write clear, high‑quality technical reports.
- Strong ethical mindset and commitment to responsible disclosure.
Desirable
- CREST penetration testing certifications, such as CPSA or CRT.
- Experience in cloud security testing (AWS, Azure, GCP).
- Knowledge of secure architecture or defensive controls.
- Additional certifications (e.g. OSCP, CHECK, CISSP, cloud security certs).
What We Offer
- Meaningful work with real‑world impact across Scotland’s cyber ecosystem
- Flexible and hybrid working arrangements
- Support for continued professional development and certification
- A collaborative, mission‑driven culture
- Competitive salary and benefits package (commensurate with experience)
How to Apply
Job description available on our website. To apply, please submit your CV and a short covering statement to [email protected] by 5pm Friday 11th September 2026
Pay: £35,000.00-£45,000.00 per year
Benefits:
- Company pension
- Gym membership
Work Location: Hybrid remote in Edinburgh EH1 2BB