At a Glance
- Tasks: Lead advanced penetration testing and ensure security across complex systems.
- Company: Join State Street's innovative Penetration Testing Team in a dynamic banking environment.
- Benefits: Enjoy competitive salary, comprehensive benefits, and a hybrid work schedule.
- Other info: Collaborative culture focused on continuous improvement and innovation.
- Why this job: Make a real impact on security while working with cutting-edge technologies and AI techniques.
- Qualifications: 5+ years in penetration testing with strong application and network expertise.
The predicted salary is between 120000 - 202500 £ per year.
We are seeking a Senior Penetration Testing Engineer to join State Street’s Penetration Testing Team, reporting to the Penetration Testing Team Manager. This role sits within the Threat Intelligence and Assurance organization and is a deeply technical engineering position with strong hands‑on expectations.
As a subject‑matter expert in application penetration testing, you will execute detailed assessments, contribute to the design and oversight of network penetration testing with third‑party providers, and build rigorous, repeatable testing approaches that evaluate security controls and real‑world exploitability across complex systems. You will operate in a highly regulated banking environment, ensuring testing outputs are technically sound, evidence‑based, and aligned to risk and audit expectations. Collaboration with engineering and infrastructure teams will be essential to analyze root causes, validate fixes, and drive improvements in secure system design and implementation.
What You Will Be Responsible For
- Design and manage third‑party network penetration tests, including scoping, vendor selection, rules of engagement, quality assurance, and validation of results.
- Lead end‑to‑end application penetration testing across internal and third‑party providers (web, API), including scoping, execution, exploitation, and retesting.
- Perform advanced testing across authentication/authorization, business logic, injection, API abuse, crypto misuse, and access control weaknesses.
- Establish and enforce testing standards for both internal teams and external vendors to ensure consistency, depth, and regulatory defensibility.
- Deliver high‑quality, regulator‑ready reporting with clear exploitability, risk context, and actionable remediation guidance.
- Lead the use of AI/LLM‑enabled testing techniques and conduct assurance testing of enterprise AI/LLM deployments (e.g., prompt injection, model abuse, data exposure risks).
- Partner with engineering and infrastructure teams to validate remediation, reduce recurrence, and strengthen secure development and deployment practices.
What We Value
- Technical depth with ownership, balancing hands‑on expertise with accountability for end‑to‑end outcomes across internal and external testing.
- Strong judgment and vendor oversight, ensuring third‑party testing meets enterprise standards and delivers meaningful assurance.
- Practical, risk‑focused mindset, prioritising real‑world exploitability and business impact.
- Clear, concise communication, producing executive‑ready outputs and actionable technical guidance.
- Collaboration and partnership, working closely with engineering, infrastructure, and risk stakeholders.
- Innovation and adaptability, particularly in applying AI/LLM techniques to offensive security challenges.
- Continuous improvement, enhancing methodologies, playbooks, and testing consistency across internal and third‑party efforts.
Education & Preferred Qualifications
- 5+ years in penetration testing with strong experience across both application and network testing in high‑security/highly regulated environments.
- Experience managing third‑party penetration testing vendors, including quality validation and outcome assurance.
- Deep expertise in application penetration testing (web, APIs, mobile) and solid understanding of enterprise network attack paths.
- Strong knowledge of modern architectures (cloud‑native, microservices, identity platforms, CI/CD pipelines).
- Ability to translate technical findings into actionable, risk‑based remediation guidance and influence stakeholders.
- Nice to have: experience using AI/LLM tools to perform network and application penetration testing and configuration/security reviews.
- Education/Certifications (desired, not mandatory): BS/MS in relevant field; OSCP/OSEP/OSWE, GPEN/GXPN, GWAPT, PNPT, GCPN, or similar.
Additional Requirements
- Hybrid schedule based on location.
Salary Range
$120,000 – $202,500 Annual (range applies to the primary specified location; other locations may differ).
Benefits
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long‑term disability, and other optional additional coverages; paid‑time off including vacation, sick leave, short‑term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance‑based awards; and, eligibility for certain tax‑advantaged savings plans.
Equal Opportunity Employer
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Job Application Disclosure
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Penetration Testing Engineer- VP in London employer: State Street
State Street is an exceptional employer for a Senior Penetration Testing Engineer, offering a dynamic work environment that fosters innovation and collaboration within a highly regulated banking sector. Employees benefit from a comprehensive benefits package, including a robust retirement plan, health insurance, and generous paid time off, all while having the opportunity to engage in cutting-edge security practices and continuous professional development. The company's commitment to diversity and inclusion ensures a supportive culture where every team member can thrive and contribute meaningfully to the organisation's success.
StudySmarter Expert Advice🤫
We think this is how you could land Penetration Testing Engineer- VP in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including State Street, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through State Street
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at State Street. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Penetration Testing Engineer- VP in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at State Street insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to State Street that you’re committed to staying ahead in the game.
How to prepare for a job interview at State Street
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at State Street to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at State Street.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.