Nordic Investin is recruiting a Penetration Tester on behalf of one of our partner companies. You want offensive security work where findings are technically credible, clearly explained and useful to the engineers who must fix them.
The partner conducts security testing across web applications, APIs, cloud environments and selected internal systems. You will plan engagements, validate exploit paths and communicate risk without exaggeration.
Security work is expected to reduce real exposure while preserving the organisation’s ability to deliver. The strongest candidates can connect a technical weakness with a credible threat, an appropriate control and a practical path to implementation.
How you will workYou will work directly with the people who design, operate and depend on the systems being protected. Recommendations must identify the threat, the affected asset and a realistic implementation path. The partner values careful evidence, proportionate controls and clear escalation when risk cannot be removed immediately.
You will receive meaningful ownership while working with senior colleagues on the most consequential decisions. The partner expects you to deliver independently within a clear area, ask for context early and contribute ideas grounded in what you observe. There is room to deepen your specialism or broaden toward adjacent responsibilities.
What you will do- Perform scoped penetration tests and security assessments.
- Test web applications, APIs, identity flows and infrastructure.
- Develop proof of concept exploits when appropriate.
- Distinguish theoretical weakness from practical attack paths.
- Write clear reports with reproducible evidence and remediation guidance.
- Present findings to engineering and risk stakeholders.
- Hands on penetration testing experience.
- Strong web, API and network security fundamentals.
- Ability to use and extend common testing tools.
- Clear understanding of authorisation, safety and test boundaries.
- High quality technical writing in English.
- Constructive communication during remediation.
- Cloud or mobile penetration testing.
- Source code assisted assessments.
- OSCP, CREST or comparable evidence of practical skill.
Your route may include security consulting, development, system administration or independent research. The partner is interested in disciplined testing and useful judgement, not a catalogue of scanner output.
What makes the opportunity interestingYou will encounter varied technical environments and have time to understand the systems you assess. The role offers close contact with skilled engineers and the satisfaction of seeing findings converted into stronger products.
The exact partner, employment model, compensation, start date and working arrangement will be explained openly during the process. Nordic Investin will make sure you understand the context, expectations and decision path before you are asked to commit significant time.
The recruitment conversationDuring the process, Nordic Investin will focus on concrete decisions you have made: the context you received, the alternatives you considered, the result you observed and what you would change today. You do not need every optional technology if your core experience transfers and you can explain how you would close the gap.
How to applyApply with your CV or LinkedIn profile and a short note describing the most relevant system, product or transformation you have helped deliver. Nordic Investin welcomes candidates with different routes into technology and assesses applicants on relevant capability, judgement and potential.
