If you need support in completing the application or if you require a different format of this document, please get in touch with at [email protected] with the subject line: “Application Support Request”.
Job Type: Permanent
Location: Letterkenny GDC, Co. Donegal (
Hybrid - 2 days onsite per week)
Careers at TCS: It means more
TCS is a purpose-led transformation company, built on belief. We do not just help businesses to transform through technology. We support them in making a meaningful difference to the people and communities they serve - our clients include some of the biggest brands in the UK and worldwide. For you, it means more to make an impact that matters, through challenging projects which demand ambitious innovation and thought leadership.
-
Gain access to endless learning opportunities.
- Fast track your growth with diverse career opportunities internally.
- Grow your career, while being exposed to new technologies.
The Role
Responsible for planning and executing penetration testing engagements across web applications, APIs, cloud platforms, mobile applications, and infrastructure environments. Conduct vulnerability assessments, performs manual security testing, and validate exploitable weaknesses using industry-recognised methodologies and frameworks. Analyse security risks, assess business impact, and develop practical remediation recommendations to reduce organisational exposure. Produce detailed technical and executive reports, communicate findings to stakeholders, and support remediation validation through re-testing activities. Contribute to continuous improvement of security testing processes, standards, and knowledge sharing across the cyber security function.
Your responsibilities:
- Plan and scope penetration testing engagements, including defining objectives, rules of engagement, testing methodologies (Black Box, Gray Box, White Box), schedules, and target attack surfaces.
-
Perform reconnaissance and information gathering to identify exposed services, technologies, APIs, integrations, and potential attack vectors within the target environment.
-
Conduct vulnerability assessments using approved security scanning tools, validating results, eliminating false positives, and prioritizing findings based on risk and business impact.
-
Execute manual penetration testing across web applications, APIs, mobile applications, cloud environments, and infrastructure to identify security weaknesses not detected through automated methods.
-
Assess application and infrastructure security controls, including authentication, authorization, session management, access controls, encryption, and secure configuration practices.
-
Perform advanced security testing activities, including business logic testing, abuse-case testing, exploit validation, and verification of OWASP Top 10 and API Security Top 10 vulnerabilities.
-
Analyse and assess risk exposure by determining the technical and business impact of identified vulnerabilities and developing realistic attack scenarios and exploitation paths.
-
Produce and present penetration testing reports, documenting findings, evidence, proof-of-concepts, remediation recommendations, and executive risk summaries for stakeholders.
-
Support remediation and re-testing activities, validating implemented fixes, confirming closure of vulnerabilities, and assisting with risk acceptance and exception review processes.
-
Maintain governance and continuous improvement, adhering to recognised frameworks such as OWASP, NIST, OSSTMM and ISSAF, while contributing to testing methodologies, playbooks, knowledge sharing, audits, compliance activities, and mentoring junior team members.
Your Profile:
Essential skills/knowledge/experience:
- Web Application, API and Mobile Application Security Testing.
-
Network and Infrastructure Penetration Testing.
-
Cloud Security Testing (AWS, Azure, GCP).
-
Vulnerability Assessment and Risk Analysis.
-
Authentication and Authorization Testing.
-
Secure Coding and SDLC awareness
-
Threat Modeling and Attack Surface Analysis.
-
Security Reporting and Risk Communication
-
Experience in the following tools : Burp Suite, Nessus, Metasploit, Wireshark, Nmap, OWASP ZAP, Core Impact (preferred), mobile application testing tools, and custom exploitation scripts.
Desirable skills/knowledge/experience:
- Experience in Web, API, Mobile, Cloud, and Infrastructure security assessments.
-
Proven experience conducting manual penetration testing and vulnerability validation.
-
Certification (Desirable): CompTIA Security+, CVA, , OSCP, OWSE, CEH, GWAPT, GPEN, CRTO , CISSP
Rewards & Benefits
TCS is consistently voted a Top Employer in the UK and globally. Our competitive salary packages feature pension, health care, life assurance, laptop and access to extensive training resources and discounts within the larger Tata network.
We offer health & wellness initiatives and sports events; we are the proud sponsor of the London Marathon and partner with our local communities in Ireland.
Diversity, Inclusion and Wellbeing
Tata Consultancy Services UK&I is committed to meeting the accessibility needs of all individuals in accordance with the Ireland Employment Equality Acts 1998-2011 (as amended) and the Equal Status Acts 2000-2012 (as amended).
We welcome and embrace diversity in race, nationality, ethnicity, disability, neurodiversity, gender identity, age, physical ability, gender reassignment, sexual orientation. We are a disability inclusive employer and encourage disabled people to apply for this role.
As a Disability Confident Employer, we offer an interview to applicants with disabilities or long-term conditions who meet the minimum criteria for the role. Please email us at
[email protected] if you would like to opt in.
If you are an applicant who needs any adjustments to the application process or interview, please contact us
at [email protected] with the subject line: “Adjustment Request” to request an adjustment. We welcome requests prior to you completing the application and at any stage of the recruitment process.
Beware of Fraudulent offers
This is to notify you that TCS does not ask for any sort of payment or security deposit from candidates at any stage of the recruitment process. The firm never sends out job offers from free internet email services like Gmail, Yahoo Mail, and so on. TCS has not authorised any third-party company to collect money on their behalf. As a vigilant job seeker, beware of fraudulent recruitment activity and protect your interests! You can write to
[email protected] to report any fraudulent activity.
Due to the high volume of applications, we will be unable to contact each applicant individually on the status of their application. If you have not received a direct response within 30 days, then it should be deemed unsuccessful on this occasion.
Join us and do more of what matters. Apply online now.