At a Glance
- Tasks: Lead complex penetration tests and enhance security across diverse technologies.
- Company: Join a forward-thinking company dedicated to cybersecurity excellence.
- Benefits: Enjoy flexible hours, hybrid working, and generous annual leave.
- Other info: Inclusive culture with a commitment to diversity and career development.
- Why this job: Make a real impact by safeguarding assets and mentoring future talent.
- Qualifications: Experience in penetration testing and strong communication skills required.
The predicted salary is between 60000 - 80000 £ per year.
The Senior Penetration Tester plays a critical role in safeguarding Intact’s assets by leading the scoping, planning, and execution of complex penetration tests across a diverse range of technologies, environments, and business functions, including network, application and cloud. This position requires a deep technical understanding of offensive security methodologies, strong communication skills, and the ability to translate business requirements into actionable testing strategies.
As part of the role, the Senior Penetration Tester will actively contribute to purple team / threat simulation testing, working in close collaboration with defensive security teams to enhance detection and response capabilities. This involves simulating advanced attack scenarios, validating security controls, and leveraging frameworks such as MITRE ATT&CK to ensure comprehensive coverage of adversarial TTPs (Tactics, Techniques, and Procedures). The successful candidate will play a key role in translating offensive insights into actionable defensive improvements, fostering a culture of continuous learning and resilience against evolving threats.
You’ll make an impact by:
- Leading the scoping, planning, and delivery of complex penetration tests across networks, applications, cloud environments, and emerging technologies.
- Conducting advanced offensive security assessments to identify and exploit vulnerabilities, providing clear and actionable remediation guidance.
- Collaborating with defensive teams to help design and execute purple team exercises, improving detection and response capabilities.
- Producing high-quality reports and communicating findings effectively to technical and non-technical stakeholders.
- Assisting the Cyber Defence team with vulnerability validation, and technical support during incident response.
- Mentoring junior team members, sharing knowledge and best practices to develop overall team capability.
- Peer-reviewing methodologies and reports to ensure repeatability and quality.
- Staying current with evolving threats, tools, and techniques, contributing to continuous improvement of testing methodologies and security posture.
- Maintaining and championing the security testing elements of the SDLC.
Your skills and experience:
- Experience of leading network, web, cloud, internal and red / purple team penetration tests.
- Excellent knowledge of penetration testing approaches, tools and techniques.
- Excellent knowledge of MITRE ATT&CK framework and TTPs.
- Strong capability in identifying, validating, and clearly articulating vulnerabilities.
- Experience writing high-quality reports with clear risk statements and remediation guidance.
- Ability to perform threat modelling and attack surface analysis.
- Excellent knowledge and understanding of Open Web Application Security Project (OWASP).
- Demonstrable experience with automated, dynamic and static application security testing tools.
- Experience in managing third‑party suppliers.
- Relevant technical security qualifications or experience, for example OSCP, SANS, CREST, CRTO, or equivalent level.
Why You’ll Love It Here:
- Annual discretionary bonus.
- Up to 11% pension contributions.
- Hybrid working + flexible hours.
- 25 days annual leave + bank holidays + buy/sell options.
- Health & wellbeing + virtual GP.
- Career development and mentoring.
- Inclusive culture + employee networks.
- Share investment options.
Our DEI Commitment: We celebrate individuality and believe our differences make us stronger. We’re proud to foster a culture where everyone feels respected, valued, and empowered to thrive. As an Equal Opportunity and Disability Confident Employer, we ensure fair consideration for all applicants and offer interviews to all disabled candidates who meet the essential criteria. We understand that everyone’s circumstances are different and are happy to explore flexible working options such as reduced hours or job shares to support work–life balance.
Senior Penetration Tester in Horsham employer: Intact Insurance (previously RSA)
Contact Detail:
Intact Insurance (previously RSA) Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Penetration Tester in Horsham
✨Tip Number 1
Network like a pro! Attend industry meetups, conferences, or webinars where you can connect with fellow penetration testers and security professionals. You never know who might have the inside scoop on job openings or can refer you directly to hiring managers.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects, reports, and any contributions to open-source security tools. This not only demonstrates your expertise but also gives potential employers a taste of what you can bring to their team.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each application by researching the company’s security posture and mentioning how your skills align with their needs. This shows that you’re genuinely interested and have done your homework.
✨Tip Number 4
Leverage our website! Apply through StudySmarter’s platform to streamline your job search. We’ve got resources and tips to help you stand out, plus you’ll be part of a community that supports your career growth in cybersecurity.
We think you need these skills to ace Senior Penetration Tester in Horsham
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Penetration Tester role. Highlight your experience with penetration testing, especially in networks, applications, and cloud environments. We want to see how your skills align with our needs!
Show Off Your Technical Skills: Don’t hold back on showcasing your technical expertise! Mention your familiarity with offensive security methodologies, MITRE ATT&CK framework, and any relevant certifications like OSCP or SANS. This is your chance to shine!
Communicate Clearly: When writing your application, keep it clear and concise. We appreciate candidates who can articulate complex ideas simply, especially when it comes to explaining vulnerabilities and remediation strategies. Remember, we’re looking for strong communication skills!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details about the role and our company culture there!
How to prepare for a job interview at Intact Insurance (previously RSA)
✨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around penetration testing methodologies and tools. Familiarise yourself with the MITRE ATT&CK framework and be ready to discuss how you've applied it in past projects.
✨Communicate Clearly
Since you'll need to explain complex findings to both technical and non-technical stakeholders, practice articulating your thoughts clearly. Prepare examples of how you've communicated vulnerabilities and remediation strategies in previous roles.
✨Show Your Collaborative Side
This role involves working closely with defensive teams, so be prepared to discuss your experience in collaborative environments. Think of examples where you've contributed to purple team exercises or worked alongside others to enhance security measures.
✨Bring Your Reports to Life
High-quality reporting is key in this role. Have a couple of your best reports ready to discuss during the interview. Highlight how you structured your findings and the impact they had on improving security posture.