Penetration Testing & Ethical Hacking Jobs in the IT Industry

Find your next role in Penetration Testing or Ethical Hacking in New Zealand

Penetration Testers and Ethical Hackers probe for and exploit vulnerabilities in web applications, networks, and systems, using tools like Metasploit, Fortify, and AppScan, often holding certifications such as OSCP, CREST, or CEH. At Younity, we specialise in connecting Penetration Testers and Ethical Hackers with New Zealand’s leading tech companies, helping you find a role that matches your skills and career goals.

 

Why choose Younity as your recruitment partner for Penetration Testing & Ethical Hacking roles?

Pen testing roles are specialised, and the best matches go beyond a keyword search. At Younity, we support both the IT employer and the IT jobseeker with practical, people-first tech recruitment, helping you find roles where your skills will be valued and your work will have real impact.

Working with us, you can expect NZ market guidance, with insight into what hiring managers in New Zealand are prioritising right now, from web app testing to internal network assessments and red team capability.

 

We also offer role-fit support, helping align your experience with the type of testing the organisation actually needs (white box, black box, or a mix), along with career progression conversations, whether you’re aiming for deeper technical work or a pathway toward Security Architect, Security Manager, Red Team Lead, Security Consultant or even CISO roles over time. We know these roles require trust, discretion and strong communication, and we recruit accordingly.

 

What does a Penetration Tester & Ethical Hacker do in IT?

A Penetration Tester & Ethical Hacker helps organisations understand how they could be compromised, and what to fix first.

In practical terms, penetration testers:

  • Probe for and exploit security vulnerabilities in web-based applications, networks and systems
  • Design and run white box and black box tests to assess system strengths and weaknesses, from “we know everything about the environment” to “test it like a real attacker would”
  • Enable full risk assessments by providing evidence-based findings that security teams and leadership can act on
  • Document what they found and how they found it, so issues can be reproduced, prioritised and remediated

Common tools and technologies you may encounter in New Zealand penetration testing roles include Java, C++, Metasploit, Fortify, AppScan, Burp Suite, and Kali Linux.

 

What’s it like to work in this discipline?

Penetration testing is hands-on, investigative, and continuously evolving. It can be highly rewarding if you enjoy problem-solving and learning, but it also comes with real responsibility.

Many people enjoy the variety, since every environment is different and the “puzzle” changes by client, system, and threat landscape. There’s clear impact too: good testing helps prevent real-world incidents and reduces organisational risk. New Zealand also has a strong, active cyber security community, with plenty of places to learn, connect and share responsibly, including ISIG meetups held regularly across Wellington, Auckland, Hamilton, Christchurch and Dunedin, Kawaiicon (New Zealand’s hacker conference, held in Wellington), CHCon (Christchurch’s annual security conference), and the InfosecNZ Discord, a great channel for staying connected to the community and upcoming events.

A key reality of the job: writing is a major part of the work. You’ll typically produce:

  • Technical reports for operations teams, with clear steps to reproduce and fix issues
  • Executive summaries for non-technical stakeholders, covering what the risk means, what to prioritise, and why
  • Soft skills matter more than many people expect. Emotional intelligence, clear communication, and the ability to work across diverse teams, from developers and infrastructure engineers to executives and governance leads, are qualities that set strong candidates apart.

 

What qualifications or experience does this role benefit from?

There’s no single path into penetration testing in New Zealand, but employers typically look for a mix of practical capability, trustworthy judgement, and evidence of continuous learning.

Highly regarded certifications include:

  • OSCP, Offensive Security Certified Professional (OffSec PEN-200): widely regarded as the gold standard for penetration testers, with a strong emphasis on hands-on, real-world skills.
  • CREST CRT, Registered Tester (CREST Australia New Zealand): an entry-level, industry-recognised qualification that assesses practical vulnerability assessment and penetration testing capability.
  • CEH, Certified Ethical Hacker (EC-Council): a globally recognised certification covering the tools and techniques used by ethical hackers.
  • CompTIA PenTest+: a vendor-neutral certification covering all stages of penetration testing, a solid entry point for those building their credentials.

Formal education pathways in New Zealand include the Bachelor of Computer and Information Sciences, Networks and Cybersecurity major (AUT), which covers network security, enterprise networks, secure systems, and information security management, with practical industry projects, and cybersecurity study options at Victoria University of Wellington, where you can study cybersecurity within a Bachelor of Engineering with Honours (BE(Hons)) or as a specialisation, a strong academic foundation for the field. Lumify Work NZ also offers a range of penetration testing and ethical hacking courses in New Zealand, including OSCP (OffSec PEN-200), CEH, and CompTIA PenTest+.

Experience that strengthens your profile includes:

  • Web application testing, API testing, and exposure to secure software development lifecycles
  • Network and system fundamentals, understanding how real environments are built and managed
  • Evidence of structured approaches, such as planning, scoping, testing, reporting, and retesting
    Community participation and ongoing learning, especially within the NZ cyber security scene
  • Career progression is strong for those who build depth and trust. Many professionals move into roles such as Security Architect, Security Manager, CISO, Red Team Lead, or Security Consultant.

 

Preparing a CV or cover letter for a Penetration Tester & Ethical Hacker role

Pen testing CVs are most effective when they’re evidence-led, specific, and easy to scan. List certifications prominently, near the top, not buried at the end, and include tangible results, such as CVEs found (where publicly attributable), bug bounty achievements, and HackTheBox or TryHackMe rankings.

Mention the specific tools and methodologies you’ve used, for example, Burp Suite workflows, Kali Linux toolsets, or structured OWASP-based web app testing approaches, and highlight both your technical report writing (for ops and engineering teams) and your executive summary writing (for non-technical stakeholders who need clarity and priorities).

For your cover letter, tailor it to the type of testing the role focuses on, web app penetration testing, network testing, or red team / adversary simulation. Briefly show how you communicate risk: what you found, why it matters, and how you support teams to fix it. Keep it concise and specific, since hiring managers in this space value precision.

On LinkedIn and in your portfolio, show active engagement with the security community, since events, responsible learning, and thoughtful posts signal genuine interest. Follow New Zealand security firms and community channels to stay current, and build a portfolio you can safely share, linking to write-ups, blog posts, and responsible disclosure reports where appropriate and ethical.