At a Glance
- Tasks: Lead end-to-end penetration testing across applications and infrastructure, ensuring vulnerabilities are resolved.
- Company: Dynamic tech firm focused on security and innovation.
- Benefits: Competitive day rate, flexible working, and opportunities for professional growth.
- Other info: Join a collaborative environment with a focus on continuous improvement and learning.
- Why this job: Take ownership of critical security processes and make a real impact in tech.
- Qualifications: Extensive experience in penetration testing and strong stakeholder management skills.
The predicted salary is between 51750 - 63250 £ per year.
Job Description
- Lead Penetration Tester
- Contract: Initial 6 months
Day Rate: £700–£800 per day
IR35: Inside IR35
1 day per month on site, either Chesterfield or London.
About the Role
We are looking for an experienced Lead Penetration Tester to take ownership of the end-to-end penetration testing process across applications, infrastructure and wider technology environments.
This is a hands-on role combining penetration testing expertise with the coordination and oversight of testing engagements, third-party suppliers, vulnerability remediation and security findings.
You will be responsible for ensuring tests are appropriately scoped, executed to a high standard, and that resulting vulnerabilities are clearly documented, prioritised and driven through to resolution.
The role will involve working closely with internal engineering, Dev Ops, product and delivery teams, as well as third-party penetration testing providers and other stakeholders.
Key Responsibilities
- Lead the end-to-end penetration testing lifecycle, including scoping, planning, execution, reporting and remediation across applications, infrastructure and systems.
- Provide hands-on penetration testing expertise while coordinating and overseeing third-party testing providers.
- Review and challenge penetration testing reports, assessing findings based on severity, exploitability, business impact and risk.
- Work closely with engineering, Dev Ops, product and delivery teams to prioritise and drive vulnerabilities through to resolution within agreed SLAs.
- Own the tracking and management of penetration testing findings in Jira, ensuring actions are assigned, monitored and closed.
- Lead regular remediation discussions with internal stakeholders and third parties, escalating blockers and ensuring residual risks are appropriately recorded and accepted.
- Ensure penetration testing and remediation activities align with relevant security standards, regulatory requirements and industry best practice, including OWASP, NIST, ISO 27001, PCI-DSS, GDPR and CAF.
- Ensure appropriate governance, documentation and evidence is maintained throughout the testing lifecycle.
- Provide assurance over the quality and effectiveness of third-party penetration testing engagements.
- Identify and implement improvements to penetration testing, vulnerability management and remediation processes.
- Use testing outcomes, lessons learned and emerging threats to improve security controls and testing methodologies.
Essential Experience
- Significant experience in penetration testing / offensive security, with the ability to lead complex testing engagements.
- Strong hands-on understanding of penetration testing across applications, infrastructure and technology environments.
- Proven experience managing the full penetration testing lifecycle, including scoping, planning, execution, reporting and remediation.
- Experience overseeing and managing third-party penetration testing suppliers.
- Strong ability to review, interpret and challenge penetration testing reports and technical findings.
- Proven experience managing vulnerabilities and security defects through to remediation.
- Experience working closely with engineering, Dev Ops, product and delivery teams.
- Strong stakeholder management skills, with the ability to translate technical vulnerabilities into clear business risks and required actions.
- Experience using Jira or similar tooling to manage security findings and remediation activity.
- Strong understanding of security risk assessment, vulnerability prioritisation and risk acceptance.
- Knowledge of recognised penetration testing methodologies and security frameworks.
Desirable Experience
- Relevant penetration testing/offensive security certifications such as CREST, OSCP, OSWE, GPEN or equivalent.
- Experience operating within large, complex or highly regulated organisations.
- Experience across cloud environments, particularly Azure and/or AWS.
- Experience with application, API, network, infrastructure and/or cloud penetration testing.
- Familiarity with vulnerability management and security operations processes.
- Experience working within environments subject to ISO 27001, PCI-DSS, GDPR or CAF requirements.
What We're Looking For
The successful candidate will be someone who can combine strong technical penetration testing knowledge with excellent delivery and stakeholder management skills.
You will be comfortable getting into the technical detail of penetration testing findings, while also taking ownership of the wider process, coordinating suppliers, challenging reports, managing Jira defects, engaging with delivery teams and ensuring vulnerabilities are driven through to closure.
This is particularly suited to a senior/lead-level penetration tester who wants ownership of the testing and remediation lifecycle, rather than someone focused solely on executing individual tests.
Lead Penetration Tester in Norwich employer: Morson Edge
As a leading player in the Energy Sector, our company offers an exceptional work environment in Bridgwater, Somerset, where you can thrive as a Welding / NDT Field Engineer. We pride ourselves on fostering a collaborative culture that prioritises employee growth and development, alongside competitive daily rates and the potential for contract extensions until December 2026. Join us to be part of a dynamic team dedicated to making a meaningful impact in the energy industry.
StudySmarter Expert Advice🤫
We think this is how you could land Lead Penetration Tester in Norwich
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Morson Edge.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Morson Edge.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Morson Edge.
We think you need these skills to ace Lead Penetration Tester in Norwich
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Morson Edge a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Morson Edge; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Morson Edge.
How to prepare for a job interview at Morson Edge
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Morson Edge for the Lead Penetration Tester, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Morson Edge.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Lead Penetration Tester role at Morson Edge.