At a Glance
- Tasks: Lead complex penetration tests and enhance security across diverse technologies.
- Company: Intact Insurance, a forward-thinking company transforming the insurance industry.
- Benefits: Annual bonus, hybrid working, 25 days leave, and career development opportunities.
- Other info: Inclusive culture with flexible working options to support work-life balance.
- Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
- Qualifications: Experience in penetration testing and strong knowledge of security frameworks like MITRE ATT&CK.
The predicted salary is between 60000 - 80000 £ per year.
Intact Insurance is the new name for RSA in the UK, Ireland, and across Europe. It’s a new name and a new way to do business. Backed by global expertise and a commitment to service that feels different, we’re focused on making insurance simpler, faster, and more responsive.
Shape the future: We’re leading a transformation in insurance helping people, businesses and society prosper in good times and be resilient in bad times. When you join us, you’re not just taking a job, you’re stepping into a career where you can make a real difference.
Grow with us: We’re customer-driven, community-focused, and committed to helping our people grow. Whether you’re early in your journey or bringing years of experience, we’ll support you with the tools, flexibility, and opportunities to thrive.
Win as a Team: The Senior Penetration Tester plays a critical role in safeguarding Intact’s assets by leading the scoping, planning, and execution of complex penetration tests across a diverse range of technologies, environments, and business functions, including network, application and cloud. This position requires a deep technical understanding of offensive security methodologies, strong communication skills, and the ability to translate business requirements into actionable testing strategies.
As part of the role, the Senior Penetration Tester will actively contribute to purple team / threat simulation testing, working in close collaboration with defensive security teams to enhance detection and response capabilities. This involves simulating advanced attack scenarios, validating security controls, and leveraging frameworks such as MITRE ATT&CK to ensure comprehensive coverage of adversarial TTPs (Tactics, Techniques and Procedures). The successful candidate will play a key role in translating offensive insights into actionable defensive improvements, fostering a culture of continuous learning and resilience against evolving threats.
You’ll make an impact by:
- Lead the scoping, planning, and delivery of complex penetration tests across networks, applications, cloud environments, and emerging technologies.
- Conduct advanced offensive security assessments to identify and exploit vulnerabilities, providing clear and actionable remediation guidance.
- Collaborate with defensive teams to help design and execute purple team exercises, improving detection and response capabilities.
- Produce high-quality reports and communicate findings effectively to technical and non-technical stakeholders.
- Assist the Cyber Defence team with vulnerability validation, and technical support during incident response.
- Mentor junior team members, sharing knowledge and best practices to develop overall team capability.
- Peer-review methodologies and reports to ensure repeatability and quality.
- Stay current with evolving threats, tools, and techniques, contributing to continuous improvement of testing methodologies and security posture.
- Maintain and champion the security testing elements of the SDLC.
Your skills and experience:
- Experience of leading network, web, cloud, internal and red / purple team penetration tests.
- Excellent knowledge of penetration testing approaches, tools and techniques.
- Excellent knowledge of MITRE ATT&CK framework and TTPs.
- Strong capability in identifying, validating, and clearly articulating vulnerabilities.
- Experience writing high-quality reports with clear risk statements and remediation guidance.
- Ability to perform threat modelling and attack surface analysis.
- Excellent knowledge and understanding of Open Web Application Security Project (OWASP).
- Demonstrable experience with automated, dynamic and static application security testing tools.
- Experience in managing third party suppliers.
- Relevant technical security qualifications or experience, for example OSCP, SANS, CREST, CRTO, or equivalent level.
Why You’ll Love It Here: Being part of our team means you’ll have the support and freedom to bring your best self to work each day. As a permanent member, here’s what you can look forward to:
- Annual discretionary bonus.
- Up to 11% pension contributions.
- Hybrid working + flexible hours.
- 25 days annual leave + bank holidays + buy/sell options.
- Career development and mentoring.
- Inclusive culture + employee networks.
- Share investment options.
Our DEI Commitment: We celebrate individuality and believe our differences make us stronger. We’re proud to foster a culture where everyone feels respected, valued, and empowered to thrive. As an Equal Opportunity and Disability Confident Employer, we ensure fair consideration for all applicants and offer interviews to all disabled candidates who meet the essential criteria. We understand that everyone’s circumstances are different and are happy to explore flexible working options such as reduced hours or job shares to support work–life balance. If you meet the core criteria but not every requirement, we’d still love to hear from you. Let’s explore how this role could support your next career step. If you need adjustments during the recruitment process, just let us know we’re here to support you.
Senior Penetration Tester in Horsham employer: RSA Security LLC
Contact Detail:
RSA Security LLC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Penetration Tester in Horsham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at Intact Insurance. A friendly chat can sometimes lead to opportunities that aren’t even advertised!
✨Tip Number 2
Show off your skills! If you’ve got a portfolio of past penetration tests or projects, make sure to share it during interviews. It’s a great way to demonstrate your expertise and give them a taste of what you can bring to the team.
✨Tip Number 3
Prepare for those tricky interview questions! Brush up on your knowledge of the MITRE ATT&CK framework and be ready to discuss how you’d approach specific scenarios. This shows you’re not just book-smart but also practical.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the Intact Insurance family.
We think you need these skills to ace Senior Penetration Tester in Horsham
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Penetration Tester role. Highlight your experience with penetration testing, especially in areas like network and cloud environments, and don’t forget to mention any relevant qualifications!
Show Off Your Skills: When writing your application, be sure to showcase your technical skills and knowledge of frameworks like MITRE ATT&CK. We want to see how you can translate complex security concepts into actionable strategies that align with our mission.
Communicate Clearly: Your ability to communicate findings effectively is key! Use your application to demonstrate how you can articulate technical information to both technical and non-technical stakeholders. Clear communication is crucial in this role.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets the attention it deserves. Plus, you’ll find all the details about the role and our company culture there!
How to prepare for a job interview at RSA Security LLC
✨Know Your Stuff
Make sure you brush up on your penetration testing knowledge, especially around the MITRE ATT&CK framework and OWASP. Be ready to discuss specific tools and techniques you've used in past assessments, as well as any complex scenarios you've tackled.
✨Communicate Clearly
Since you'll be working with both technical and non-technical stakeholders, practice explaining your findings in a way that's easy to understand. Prepare to share examples of how you've communicated vulnerabilities and remediation strategies effectively in previous roles.
✨Show Your Team Spirit
Intact Insurance values collaboration, so be prepared to discuss how you've worked with defensive teams or mentored junior members in the past. Highlight any experiences where you contributed to team exercises or improved overall security posture.
✨Stay Current
The cybersecurity landscape is always changing, so demonstrate your commitment to continuous learning. Share any recent training, certifications, or personal projects that showcase your proactive approach to staying updated on evolving threats and security methodologies.