Lead Penetration Tester in Technical Vulnerability Management in Leeds

Lead Penetration Tester in Technical Vulnerability Management in Leeds

Leeds Full-Time 72320 - 81360 £ / year (est.) Home office (partial)
Bank of England

At a Glance

  • Tasks: Lead penetration testing to strengthen security across various systems and services.
  • Company: Join the Bank of England's Cyber Security Division in Leeds.
  • Benefits: Competitive salary, flexible working, comprehensive benefits package, and career development opportunities.
  • Other info: Dynamic team environment with opportunities for growth and collaboration.
  • Why this job: Make a real impact on national security while working with cutting-edge technology.
  • Qualifications: Strong hands-on penetration testing experience and leadership skills required.

The predicted salary is between 72320 - 81360 £ per year.

This is an opportunity to join the Bank of England’s Pentest Team as a Lead Penetration Tester and play a senior role in strengthening the Bank’s security. You’ll lead and deliver penetration testing across a broad range of systems and services, assess complex vulnerabilities, and support red and purple team activity. Working with colleagues across Cyber and Technology, you’ll help shape testing approaches, provide technical leadership, and drive effective remediation to reduce risk across the organisation.

Flexible Working Options

  • Flexible start and end time to each day
  • Flexibility to adapt your calendar as needed, for example around the school run, the gym, or appointments
  • A 50% in-office attendance requirement, which can be spread across the month to support different working patterns
  • Working from abroad policy (subject to approval and policy within the team)

Opportunities in Leeds

We’re excited to be growing our presence in Leeds, a city we’ve been connected to for nearly 200 years! Our modern, accessible office in the City Centre offers a supportive, flexible working environment. The majority of roles, including this one, are now available in Leeds, giving you the chance to build a meaningful career outside of London while contributing to our mission from a dynamic and growing location. You’ll work collaboratively with London-based colleagues in a hybrid model, with regular opportunities to travel into the London office to meet and connect together in person.

A day in the role:

No two days in this role are exactly the same. You might start the day aligning priorities with the team, then move into leading a penetration test, reviewing complex findings, or shaping the approach to a new assessment. You’ll work closely with colleagues across Cyber and Technology, providing technical oversight, engaging with stakeholders, and helping to ensure that vulnerabilities are clearly understood and effectively remediated. As a senior member of the team, you’ll also support the development of others, contribute to improving testing practices, and help drive high-quality delivery across a varied portfolio of systems and services. The role also offers flexibility in how you organise your day, with flexible start and finish times and hybrid working between the Leeds office and home.

Role Requirements:

You will bring strong hands-on penetration testing experience and the ability to lead complex assessments across areas such as infrastructure, cloud, and web applications. You should be comfortable working with a high degree of autonomy, applying sound technical judgement, and engaging confidently with stakeholders to explain risk and influence remediation. As a senior member of the team, you will also be expected to provide technical leadership, support the development of others, and contribute to the continued evolution of the Bank’s testing capability.

Minimum Criteria

  • Significant hands-on penetration testing experience, including leading or delivering complex assessments in medium to large enterprise environments
  • Equivalent work experience or two or more of the following certifications: OSCP, OSEP, OSWE, OSED, GXPN, GX-PT, CREST CTL (INF/APP), Cyber Scheme CSTL (INF/APP), CRTO, CRTP
  • Strong practical experience in enterprise infrastructure, cloud, or complex web application pentesting
  • Practical expertise using commercial and open-source offensive security tools
  • A strong understanding of common operating systems and their security considerations
  • A strong understanding of networking concepts, including IP addressing, TCP/IP and UDP
  • A strong understanding of enterprise infrastructure services and protocols
  • A strong understanding of security concepts and controls related to complex enterprise architecture and the ability to evaluate those controls for effectiveness and impact on operational risk
  • A solid understanding of cloud technologies and their security implications
  • Excellent written and verbal communication skills, including the ability to produce clear technical reporting and explain risk to a range of stakeholders
  • A high level of integrity, organisation, self-motivation, and a commitment to continuous improvement and high-quality delivery

Essential Criteria

  • Experience working in financial services or large government organisations
  • Practical experience in source code review
  • Strong scripting capability in Python, PowerShell, or Bash
  • A solid understanding of Governance, Risk and Compliance processes and how they support security decision-making
  • Experience in delivering threat modelling reports that provide a detailed understanding of risks to related systems
  • Red team operator experience

Desirable Criteria

  • Experience working in complex medium to large organisations

How this role fits into the wider Bank

As part of the Cyber Division, you’ll join a penetration testing team that plays a key role in identifying vulnerabilities across the Bank’s technology and infrastructure, assessing complex risk, and driving effective remediation. Working closely with colleagues across Cyber, Technology, and the wider organisation, you’ll provide senior technical input, help shape testing approaches, and support the protection of the critical systems and information the Bank depends on.

Our Approach to Inclusion

The Bank values diversity, equity and inclusion. We play a key role in maintaining monetary and financial stability, and to do that effectively, we believe we need a workforce that reflects the society we serve. At the Bank of England, we want all colleagues to feel valued and respected, so we're working hard to build an inclusive culture which supports people from all backgrounds and communities to be at their best at work. We celebrate all forms of diversity, including (but not limited to) age, disability, ethnicity, gender, gender identity, race, religion, sexual orientation and socioeconomic status. We believe that it’s by drawing on different perspectives and experiences that we’ll continue to make the best decisions for the public. We welcome applications from individuals who work flexibly, including job shares and part time working patterns. We've also partnered with external organisations to support us in making adjustments for candidates and employees in the recruitment process where they're needed.

Salary and Benefits Information

We offer a salary as follows: Leeds circa £72,320 - £81,360. In addition, we also offer a comprehensive benefits package.

National Security Vetting Process

Employment in this role will be subject to the National Security Vetting clearance process and the passing of additional Bank security checks in accordance with the Bank policy.

The Application Process

Important: Please ensure that you complete the ‘work history’ section and answer ALL the application questions fully. All candidate applications are anonymised to ensure that our hiring managers will not be able to see your personal information, including your CV, when reviewing your application details at the screening stage.

Lead Penetration Tester in Technical Vulnerability Management in Leeds employer: Bank of England

The Bank of England is an exceptional employer, offering a dynamic and inclusive work environment in Leeds, where you can thrive as a Lead Penetration Tester. With flexible working options, a commitment to employee development, and a comprehensive benefits package, you will have the opportunity to make a meaningful impact on national security while enjoying a balanced work-life integration. Join a team that values diversity and fosters collaboration, allowing you to grow your career in a supportive atmosphere.

Bank of England

Contact Details:

Bank of England Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Penetration Tester in Technical Vulnerability Management in Leeds

Tip Number 1

Network like a pro! Reach out to your connections in the cyber security field, especially those who work at the Bank of England or similar organisations. A friendly chat can sometimes lead to insider info about job openings or even a referral.

Tip Number 2

Prepare for the interview by brushing up on your technical skills and understanding the latest trends in penetration testing. We recommend practising common interview questions and scenarios that might come up, so you can showcase your expertise confidently.

Tip Number 3

Don’t underestimate the power of follow-ups! After an interview, send a quick thank-you email to express your appreciation for the opportunity. It keeps you fresh in their minds and shows your enthusiasm for the role.

Tip Number 4

Check out our website for more roles that might suit you! If this Lead Penetration Tester position isn’t quite right, there are plenty of other opportunities in our Cyber team that could be a perfect fit for your skills.

We think you need these skills to ace Lead Penetration Tester in Technical Vulnerability Management in Leeds

Penetration Testing
Technical Leadership
Vulnerability Assessment
Red Team Activity
Cloud Security
Web Application Security
Infrastructure Security

Some tips for your application 🫡

Be Yourself:When you're filling out your application, let your personality shine through! We want to get to know the real you, so don’t be afraid to show your passion for penetration testing and cyber security.

Tailor Your Responses:Make sure to tailor your answers to the specific role of Lead Penetration Tester. Highlight your relevant experience and skills that align with the job description, especially your hands-on testing experience and technical leadership.

Showcase Your Achievements:Don’t just list your responsibilities; showcase your achievements! Use specific examples of how you've led complex assessments or improved testing practices in previous roles to demonstrate your impact.

Complete Every Section:It’s super important to fill out every section of the application form. We anonymise applications, so make sure your work history and answers are detailed and complete to give us a clear picture of your qualifications.

How to prepare for a job interview at Bank of England

Know Your Stuff

Make sure you brush up on your penetration testing skills and the specific tools mentioned in the job description. Be ready to discuss your hands-on experience with complex assessments, especially in enterprise environments. This is your chance to showcase your technical expertise!

Showcase Leadership Skills

As a Lead Penetration Tester, you'll need to demonstrate your ability to lead teams and projects. Prepare examples of how you've provided technical leadership in past roles, and be ready to discuss how you can support the development of others in the team.

Communicate Clearly

You'll be engaging with various stakeholders, so practice explaining complex technical concepts in simple terms. Think about how you would communicate risk and remediation strategies to non-technical colleagues. Clear communication is key!

Understand the Company Culture

Familiarise yourself with the Bank of England's values, especially around diversity and inclusion. Be prepared to discuss how you can contribute to a positive team culture and support the organisation's mission. Showing that you align with their values can set you apart!