Penetration Testing Lead (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: Manchester, Bristol, Edinburgh or London, UK; hybrid working with at least two days per week or 40% of working time in an office.
Salary: Β£92,701βΒ£119,966 outside London; Β£107,304βΒ£138,864 in London. Annual performance-related bonus also available.
Company
is a major UK financial services organisation transforming its security, data and technology capabilities for 28 million customers.
What you will do
- Shape the penetration testing strategy and lead complex application and infrastructure security assessments.
- Lead, mentor and develop a high-performing team of penetration testers.
- Define and deliver a security testing roadmap covering threat resilience, regulatory, change-driven and continuous assurance testing.
- Advance autonomous security testing in collaboration with Autonomous Vulnerability Research and Harness Engineering teams.
- Communicate security risks, testing outcomes and recommendations to technical practitioners, executives and wider business stakeholders.
- Work with engineering and security teams to prioritise and remediate findings.
Requirements
- Extensive experience leading penetration testing, application security testing or offensive security functions in a large, complex organisation.
- Expertise in complex application, API, cloud, infrastructure and network penetration testing.
- Strong knowledge of penetration testing methodologies, vulnerability discovery, offensive security tooling and attacker tradecraft.
- Experience building and leading high-performing technical teams.
- Strong understanding of enterprise technology, cloud platforms, operating systems, networks, software development practices and security controls.
- Excellent communication skills with technical, non-technical and senior leadership audiences.
Nice to have
- CREST, OSCP, OSCE, OSEP, GIAC, GWAPT, CPTS, CAPE or equivalent offensive security certification.
- Software development, automation or engineering experience with languages such as C#, C++, C, Python, Bash, Java or Rust.
- Experience in financial services or another highly regulated environment.
- Degree or postgraduate qualification in Cyber Security, Computer Science or a related field, or equivalent experience.
- Familiarity with autonomous vulnerability discovery, AI-enabled security testing, frontier model evaluation and fuzzing frameworks.
Culture & Benefits
- Hybrid working with an emphasis on diversity, equity and inclusion.
- Pension contribution of up to 15%.
- Annual performance-related bonus and share schemes including free shares.
- 30 days of holiday plus bank holidays.
- Adaptable lifestyle benefits, wellbeing initiatives and generous parental leave.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β