Senior Pen Tester (Engineering & Vulnerability Management)
Senior Pen Tester (Engineering & Vulnerability Management)

Senior Pen Tester (Engineering & Vulnerability Management)

Full-Time 43200 - 72000 £ / year (est.) No home office possible
London Stock Exchange Group

At a Glance

  • Tasks: Drive closure of penetration testing findings and enhance security across teams.
  • Company: Join LSEG, a leading global financial markets infrastructure provider.
  • Benefits: Enjoy competitive salary, healthcare, retirement planning, and paid volunteering days.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Experience in penetration testing and strong communication skills required.
  • Other info: Be part of a diverse team that values innovation and continuous improvement.

The predicted salary is between 43200 - 72000 £ per year.

LSEG is seeking a Senior Vulnerability Management Engineer to join our internal offensive security team with focus on driving closure of penetration testing findings. This role bridges offensive security and engineering by translating penetration test results into clear, actionable remediation guidance and partnering with application and platform teams to implement secure fixes. The successful candidate has a strong penetration testing or application security background, hands-on remediation experience, and the ability to coordinate multiple collaborators to reduce risk at scale. This is a highly technical, delivery-focused role with responsibility for both individual findings and systemic improvements.

Key Responsibilities

  • Analyze and review penetration test reports to understand technical impact, exploitability, and business risk.
  • Develop, document and maintain remediation guidance, patterns, and blueprints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations).
  • Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-level and business-level recommendations.
  • Coordinate remediation activities across multiple teams, ensuring clear ownership, agreed timelines, and risk-based prioritization.
  • Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure.
  • Manage and track the remediation backlog, including SLAs, aging findings, and critical issues when needed.
  • Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes.
  • Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners.
  • Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions.
  • Contribute to continuous improvement of the pentest-to-remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines.
  • Compile technical documents, track and document remediation metadata.
  • Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references.
  • Contribute to the continuous improvement of testing methodologies, tooling, automation.
  • Stay ahead of emerging threats, vulnerabilities, and offensive security techniques.
  • Participate in R&D initiatives as guided from leadership.
  • Support knowledge sharing and mentoring within the team.

Required Skills & Experience

  • Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud-native based environments).
  • Proficiency with tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed.
  • Experience in automating pentesting tasks.
  • Solid understanding of application security, network protocols, and operating systems.
  • Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes).
  • Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least one major language stack (e.g. Java/Springboot, .NET, JavaScript/Node, Python).
  • Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners.
  • Experience working in large, complex enterprise environments.
  • Proficient communication skills in English, both written and verbal.
  • Relevant certifications and engagement with the security community is a plus.
  • Threat Modelling experience is a plus.
  • Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles.
  • Ability to identify, assess, and communicate technical and project risks to partners.
  • Understanding project requirements and aligning work with agreed upon objectives and timelines.

Career Stage: Senior Associate

LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our culture of connecting, creating opportunity and delivering excellence shapes how we think, how we do things and how we help our people fulfil their potential.

Senior Pen Tester (Engineering & Vulnerability Management) employer: London Stock Exchange Group

At LSEG, we pride ourselves on being an exceptional employer, offering a dynamic work environment in London that fosters innovation and collaboration. Our commitment to employee growth is evident through tailored benefits, including healthcare and wellbeing initiatives, alongside opportunities for professional development within a diverse and inclusive culture. Join us to make a meaningful impact while working with cutting-edge technology in the financial markets sector.
London Stock Exchange Group

Contact Detail:

London Stock Exchange Group Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Pen Tester (Engineering & Vulnerability Management)

✨Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field, especially those who work at LSEG or similar companies. A friendly chat can lead to insider info about job openings and even referrals.

✨Tip Number 2

Prepare for interviews by brushing up on your technical skills and understanding the latest trends in vulnerability management. We recommend practising common interview questions and scenarios related to penetration testing to show off your expertise.

✨Tip Number 3

Don’t underestimate the power of follow-ups! After an interview, send a thank-you email to express your appreciation and reiterate your interest in the role. It keeps you fresh in their minds and shows your enthusiasm.

✨Tip Number 4

Apply through our website for the best chance of landing that Senior Pen Tester role. It’s the most direct route and ensures your application gets the attention it deserves. Plus, we love seeing candidates who are proactive!

We think you need these skills to ace Senior Pen Tester (Engineering & Vulnerability Management)

Penetration Testing
Application Security
Remediation Guidance
Vulnerability Analysis
Burp Suite
Scripting Skills
Cloud Platforms (AWS, Azure, GCP)
Containerization (Docker, Kubernetes)
OWASP Top 10
Technical Reporting
Project Risk Assessment
Threat Modelling
Communication Skills
Collaboration Skills
Continuous Improvement

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Senior Pen Tester role. Highlight your hands-on experience in penetration testing and any relevant tools you've used, like Burp Suite. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about vulnerability management and how your background makes you a perfect fit for our team. Keep it engaging and personal – we love to see your personality!

Showcase Your Technical Skills: In your application, don't shy away from showcasing your technical skills. Mention specific vulnerabilities you've tackled and how you approached remediation. We appreciate candidates who can communicate complex ideas clearly, so make sure to highlight that!

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for the role. Plus, it’s super easy – just follow the prompts!

How to prepare for a job interview at London Stock Exchange Group

✨Know Your Stuff

Make sure you brush up on your penetration testing skills and the tools mentioned in the job description, like Burp Suite. Be ready to discuss your hands-on experience with web applications, APIs, and cloud environments, as this will show you're not just familiar with the theory but can apply it in real-world scenarios.

✨Speak Their Language

Familiarise yourself with the key responsibilities and required skills listed in the job description. Use relevant terminology during the interview to demonstrate your understanding of the role and how your experience aligns with their needs. This will help you connect better with the interviewers.

✨Showcase Your Problem-Solving Skills

Prepare examples of how you've tackled vulnerabilities in the past. Discuss specific instances where you provided remediation guidance or coordinated with teams to resolve issues. This will highlight your ability to drive closure on penetration testing findings and work collaboratively.

✨Ask Insightful Questions

Prepare thoughtful questions about the company's approach to vulnerability management and their expectations for the role. This shows your genuine interest in the position and helps you gauge if the company culture aligns with your values, especially around innovation and continuous improvement.

Senior Pen Tester (Engineering & Vulnerability Management)
London Stock Exchange Group

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>