At a Glance
- Tasks: Lead ethical hacking exercises to uncover and fix cyber vulnerabilities.
- Company: Join Capital One, a leader in information-based technology.
- Benefits: Enjoy flexible working, competitive salary, and extensive training opportunities.
- Why this job: Make a real impact on cybersecurity while developing your skills.
- Qualifications: Experience in penetration testing and strong communication skills required.
- Other info: Diverse and inclusive workplace with excellent career growth potential.
The predicted salary is between 43200 - 72000 £ per year.
Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan, coordinate, execute and report on sophisticated ethical hacking exercises, to identify cyber vulnerabilities and reduce the risk posture of enterprise systems. This role will be responsible for the identification and exploitation of security weaknesses, providing actionable recommendations, and collaborating with various teams to enhance our security posture.
What you’ll do:
- Leading and overseeing penetration testing of enterprise networks, services, applications, and infrastructure.
- Contributing to the development of a comprehensive penetration testing strategy that aligns with the organization's overall security objectives.
- Analyzing penetration testing results and providing actionable insights to relevant stakeholders to drive remediation efforts and improve the organization’s security posture.
- Staying abreast of emerging threats and attack techniques to ensure that the team’s strategy and techniques remain relevant and effective.
- Providing mentorship and guidance to foster professional development and enhance the team’s overall capabilities.
- Working with developers on remediation guidance and improvements throughout the Software CI/CD pipeline.
- Clearly and effectively conveying technical information and results to diverse audiences, including senior management and those without a technical background.
What we’re looking for:
- Information security experience in one or more of the following areas: red teaming, penetration testing, application security, or network security.
- Experience with security testing tools and tradecraft.
- Able to communicate effectively up, down and across the organization, both verbally and in writing, including the ability to explain complex technical findings to technical teams and executive audiences.
- Proven ability to manage technical staff and projects, perform effective long term planning and implement continuous process improvement practices.
- Should have a strong understanding of networking concepts, Windows, Linux and Mac operating systems, cloud and web application vulnerabilities and exploitation.
Any of these would be advantageous (but we’d still love to hear from you):
- Bachelors Degree or equivalent certification.
- Security testing of cloud environments. We’re invested with AWS but will consider those who have worked on any other major public cloud provider (Azure, GCP).
- Experience in offensive security tool development, customization or expansion.
- Ability to code comfortably in one or more interpreted languages (e.g., Python, Bash, PowerShell, Perl, Ruby) and one or more compiled languages (e.g., C, C++, C#, Golang, Rust, Java, Objective-C).
- One or more of the following certifications (OSCP, OSCE, GPEN, GXPN, CRTO, CREST Certified Simulated Attack Manager).
Where and how you’ll work:
- This is a permanent position and can be based in either our London or Nottingham Head Offices.
- We have a hybrid working model which gives you flexibility to work from our offices and from home.
- We’re big on collaboration and connection, so you’ll be based in our London Head Office office 3 days a week.
- Many of our associates have flexible working arrangements, and we’re open to talking about an arrangement that works for you.
What’s in it for you:
- Bring us all this - and you’ll be well rewarded with a role contributing to the roadmap of an organisation committed to transformation.
- We offer high performers strong and diverse career progression, investing heavily in developing great people through our Capital One University training programmes (and appropriate external providers).
- Immediate access to our core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance – with flexible benefits available including season-ticket loans, cycle to work scheme and enhanced parental leave.
- Open-plan workspaces and accessible facilities designed to inspire and support you. Our Nottingham head-office has a fully-serviced gym, subsidised restaurant, mindfulness and music rooms. In London, you can heighten your mood with a run on our rooftop running track or an espresso at the Workshop Coffee café.
What you should know about how we recruit:
We pride ourselves on hiring the best people, not the same people. Building diverse and inclusive teams is the right thing to do and the smart thing to do. We want to work with top talent: whoever you are, whatever you look like, wherever you come from. We know it’s about what you do, not just what you say. That’s why we make our recruitment process fair and accessible. And we offer benefits that attract people at all ages and stages.
We also partner with organisations including the Women in Finance and Race At Work Charters, Stonewall and upReach to find people from every walk of life and help them thrive with us. We have a whole host of internal networks and support groups you could be involved in, to name a few:
- REACH – Race Equality and Culture Heritage group focuses on representation, retention and engagement for associates from minority ethnic groups and allies.
- OutFront – to provide LGBTQ+ support for all associates.
- Mind Your Mind – signposting support and promoting positive mental wellbeing for all.
- Women in Tech – promoting an inclusive environment in tech.
- EmpowHER - network of female associates and allies focusing on developing future leaders, particularly for female talent in our industry.
Capital One is committed to diversity in the workplace. For reasonable adjustments, please contact ukrecruitment@capitalone.com. All information will be kept confidential and will only be used for the purpose of applying a reasonable adjustment.
Penetration Testing Manager in Nottingham employer: Capital One (Europe) plc
Contact Detail:
Capital One (Europe) plc Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Penetration Testing Manager in Nottingham
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend meetups, conferences, or even online webinars. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects or any relevant work you've done. This is your chance to demonstrate your expertise and make a lasting impression on potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on common technical questions and scenarios related to penetration testing. Practice explaining complex concepts in simple terms, as you'll need to communicate effectively with both technical and non-technical audiences.
✨Tip Number 4
Don't forget to apply through our website! We love seeing applications directly from candidates who are genuinely interested in joining our team. Plus, it gives you a better chance to stand out in the crowd!
We think you need these skills to ace Penetration Testing Manager in Nottingham
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Penetration Testing Manager role. Highlight your experience in red teaming, penetration testing, and any relevant certifications. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about offensive security and how you can contribute to our team. Keep it engaging and relevant to the job description.
Showcase Your Communication Skills: Since you'll be conveying technical information to diverse audiences, make sure to demonstrate your communication skills in your application. Use clear language and avoid jargon where possible – we want to see how you can bridge the gap between tech and non-tech folks!
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Capital One (Europe) plc
✨Know Your Stuff
Make sure you brush up on your knowledge of penetration testing tools and techniques. Familiarise yourself with the latest trends in offensive security, as well as any specific tools mentioned in the job description. This will help you demonstrate your expertise and show that you're serious about the role.
✨Communicate Clearly
Since you'll need to convey complex technical information to various audiences, practice explaining your past projects and findings in simple terms. Use examples that highlight your ability to communicate effectively with both technical teams and non-technical stakeholders.
✨Show Your Leadership Skills
As a Penetration Testing Manager, you'll be expected to lead and mentor your team. Prepare examples of how you've successfully managed projects or guided colleagues in the past. Highlight your experience in fostering professional development and improving team capabilities.
✨Ask Smart Questions
At the end of the interview, don't forget to ask insightful questions about the company's security strategy and team dynamics. This shows your genuine interest in the role and helps you assess if the company is the right fit for you. Plus, it gives you a chance to engage with the interviewers on a deeper level.