At a Glance
- Tasks: Lead and develop a cutting-edge security testing practice while staying hands-on with technical delivery.
- Company: Dynamic security firm in London focused on innovation and team growth.
- Benefits: Competitive salary, hybrid work model, and opportunities for professional development.
- Other info: Join a collaborative environment with the flexibility to balance leadership and technical work.
- Why this job: Shape the future of security testing while mentoring a high-performing team.
- Qualifications: Hands-on penetration testing experience and strong leadership skills required.
Are you an experienced penetration tester who's ready to take ownership of a growing practice, but doesn't want to leave the technical work behind? We're looking for a Security Testing Practice Lead to drive the growth, quality and commercial success of our offensive security capability. This is a genuine leadership role, but not one where you'll spend your days buried in spreadsheets and meetings. You'll still get involved in technical delivery when required, helping the team tackle more complex engagements and maintaining your own hands‑on expertise.
You’ll work closely with the Managing Director and Commercial Team to shape the future of the practice, support clients, develop new service offerings and ensure our consultants are set up for success.
The Opportunity
This role combines technical leadership, commercial engagement and practice ownership with the flexibility to remain actively involved in testing. You’ll be responsible for:
- Leading and developing the Security Testing practice.
- Managing capacity, utilisation and scheduling across the team.
- Supporting pre‑sales activities, scoping calls and proposal development.
- Building strong relationships with key clients.
- Ensuring the quality and consistency of all testing engagements.
- Developing methodologies, tooling and service offerings.
- Mentoring and growing a high‑performing team.
- Contributing thought leadership and helping shape the future direction of the practice.
- Rolling up your sleeves and delivering security assessments when required.
Because you’ll own resource planning and scheduling, you’ll have the flexibility to balance technical delivery with leadership responsibilities rather than being permanently tied to either.
What We’re Looking For
We’re looking for someone who enjoys building teams and developing services just as much as performing great technical work. You’ll likely have:
- Significant hands‑on penetration testing experience across web applications, APIs, infrastructure and cloud environments.
- Experience leading or mentoring security testing teams.
- Strong commercial awareness and the ability to translate client requirements into well‑defined scopes of work.
- Experience supporting proposals, project planning and customer engagements.
- Deep knowledge of modern penetration testing methodologies and tooling.
- Excellent written and verbal communication skills.
- A passion for raising standards, improving delivery and developing people.
- 2 or more professional certifications such as CREST CRT/CCT, OSCP, OSWE, CISSP or CHECK are needed.
Why Join
This isn’t a management title bolted onto a technical role, nor is it a role for someone who stopped testing years ago. We’re looking for someone who wants to build and lead a modern security testing practice while remaining close enough to the work to influence quality, mentor others and step into delivery when needed. You’ll have the autonomy to shape the practice, introduce new capabilities, influence strategy and play a key role in the continued growth of the business.
Offensive Security Practice Lead employer: Oscar
Oscar is an exceptional employer, offering a dynamic work environment in Surrey where innovation meets collaboration. With a strong focus on employee growth, you will have access to professional development opportunities and a generous benefits package, including 25 days of leave and a pension scheme, all while enjoying the flexibility of a hybrid working model.