At a Glance
- Tasks: Lead penetration testing to safeguard UK Defence systems and enhance security.
- Company: Thales, a leader in digital security and identity management.
- Benefits: Competitive salary, flexible working hours, and comprehensive health benefits.
- Why this job: Make a real impact on national security while developing your cybersecurity skills.
- Qualifications: Degree in Cybersecurity or related field; experience in penetration testing required.
- Other info: Join a dynamic team with opportunities for professional growth and cutting-edge technology.
The predicted salary is between 36000 - 60000 ÂŁ per year.
Location: Remote UK, United Kingdom
Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.
Together we offer fantastic opportunities for committed employees to learn and develop their career with us. At Thales UK, we research, develop, and supply technology and services that impact the lives of millions of people each day to make life better, and keep us safer. We innovate across the major industries of Aerospace, Defence, Security and Space. Your health and well-being matters to us and that's why we offer you the flexibility to do what's important to you; whether that's part time hours, job sharing, home working, or the ability to flex your start and finish times. Where possible, we support a working pattern that suits your lifestyle and helps you reach your ambitions.
Join a team where red teaming meets real impact - safeguarding defence platforms that shape national security!
What the role has to offer- Safeguard UK Defence systems through advanced penetration testing and red teaming on critical military platforms
- Tackle complex threat simulations and exploit development across IT, OT, cloud, and embedded environments
- Use cuttingâedge tools with funded training and certifications (CHECK, CREST, OSCP, GIAC)
- A developmental role where you'll put your own stamp on future capability
We are seeking a securityâcleared Penetration Tester to join our dynamic Cyber Security team, working at the forefront of UK Defence and national security. In this role, you'll take on advanced security testing, vulnerability assessments, and red team exercises across both classified and unclassified environments - directly strengthening the resilience of missionâcritical networks and applications.
This position offers the opportunity to apply your expertise in offensive security methodologies, secure system design, and the unique challenges of defence environments. While prior defence experience is highly valued, we also welcome applications from seasoned red team specialists and offensive security professionals from sectors such as utilities, nuclear, and automotive, who bring transferable skills and fresh perspectives to our mission.
Building a Future, we can all trust.The Thales product portfolio wouldn't exist without the core engineering specialities that are AI, Cyber and Human Factors. These future-focused skills play an essential role within the wider engineering organisation and provide great opportunities to work on cutting-edge technologies.
Cybersecurity and Digital Identity (CDI) - from secure software to biometrics and encryption, CDI GBU technologies and services enable businesses and governments to authenticate identities and protect data, so they stay safe and enable services in personal devices, connected objects, the cloud and in between. Cybersecurity Premium Services (CPS) supports its enterprise and government customers in the cybersecurity of their digital transformation. We contribute to the identification and control of cyber risks, ensure the implementation of best reduction practices, operate threat driven cyber incident detection and response services, and intervene with our clients when attacks materialise.
What we offer you- Competitive salary and benefits package designed to support our employees' wellbeing and professional growth
- Annual bonus (VCP)
- Pension â match like-for-like up to 7% of annual base salary
- Life Assurance â 2 x base salary minimum (8 x salary if part of the pension scheme)
- Income Protection â 50% of salary less state benefits for 5 years
- Annual Leave â 201 hours, bank holidays, plus 1 company day
- Private Medical Insurance - Couples cover
- Half day every Friday, usually finishing around 1:00pm
- 24/7 Employee Assistance Programme
- 24 hours paid leave for volunteering activities
- Access to flexible benefits and discounts â dental insurance, buying & selling annual leave, cycle to work, and many more
- Lead endâtoâend penetration testing across networks, applications, cloud infrastructures, and embedded systems - delivering actionable insights that strengthen missionâcritical environments
- Drive advanced vulnerability assessments and exploit development, executing postâexploitation activities within authorised scopes to uncover hidden risks and resilience gaps
- Orchestrate red and purple team engagements, simulating sophisticated threat scenarios against defence systems to rigorously test and enhance security posture
- Produce highâimpact technical reports and executive briefings, translating complex findings into clear risk narratives, business impact assessments, and prioritised remediation strategies
- Partner with defensive operations and risk management teams to sharpen detection, accelerate response, and embed proactive resilience across the enterprise
- Stay ahead of adversaries by maintaining expert knowledge of tactics, techniques, and procedures (TTPs) employed by state and nonâstate actors in the defence sector
- Advance security testing methodologies and tooling, contributing to innovative threat modelling approaches tailored for complex, highâassurance environments
- Champion compliance and assurance by aligning practices with MOD, NCSC, and international standards (JSP 440, ISO 27001, NIST, CHECK, CREST), ensuring robust governance and trust
At Thales, we are committed to equal opportunities and welcome all talented individuals to consider joining our team. So even if you don't match every statement below but feel you have some of the experience, knowledge or skills needed for this role, we encourage you to apply. It will take all of us working together to deliver solutions to the world's most critical challenges.
Essential:- Degree in Computing, Cybersecurity, or a related field - or equivalent professional experience in lieu of formal tertiary studies
- CHECK Team Leader accreditation currently held
- Demonstrated track record as a Penetration Tester, Red Team Operator, or equivalent offensive security specialist
- Proven ability to manage small technical teams, demonstrating strong people skills, mentorship, and collaborative leadership
- Deep expertise in network protocols, application security, operating systems, and cloud platforms across both IT and OT environments
- Hands-on proficiency with industry-standard tools including Burp Suite, Metasploit, Cobalt Strike, Nmap, Nessus, plus custom scripting in Python, PowerShell, and Bash
- Proven experience conducting penetration tests across diverse systems: Windows, Linux, Android, iOS, Web Applications, and Cloud infrastructures
- Familiarity with defence and government environments, including secure handling of classified information
- Exceptional written and verbal communication skills, able to translate complex technical findings into clear, actionable insights
- SC or DV clearance (mandatory for project delivery), with eligibility or current holding
- Recognised certifications such as CREST (CPSA, CRT, CCT INF, CCT APP, CCRTS, CCRTM), CHECK Team Member/Leader, OSCP, OSCE3, CEH, or GIAC (GPEN, GWAPT, GRTP, GXPN)
- Exposure to ICS/SCADA, RF systems, or military-grade communication networks
- Strong grasp of Threat Intelligence
Cybersecurity Penetration Tester in London employer: Thales Group
Contact Detail:
Thales Group Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Cybersecurity Penetration Tester in London
â¨Tip Number 1
Network, network, network! Get out there and connect with professionals in the cybersecurity field. Attend meetups, webinars, or conferences to meet potential employers and learn about job openings that might not be advertised.
â¨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects or any relevant work you've done. This can be a game-changer during interviews, as it gives you a chance to demonstrate your expertise in real-world scenarios.
â¨Tip Number 3
Prepare for technical interviews by brushing up on your knowledge of tools like Burp Suite and Metasploit. Practice common penetration testing scenarios and be ready to discuss your thought process and methodologies during the interview.
â¨Tip Number 4
Donât forget to apply through our website! Weâre always looking for talented individuals like you. Tailor your application to highlight your experience in offensive security and how you can contribute to our mission at Thales.
We think you need these skills to ace Cybersecurity Penetration Tester in London
Some tips for your application đŤĄ
Tailor Your CV: Make sure your CV is tailored to the Cybersecurity Penetration Tester role. Highlight your relevant experience, skills, and any certifications that align with what we're looking for. This shows us youâre serious about the position!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a great fit for our team. Keep it concise but impactful â we want to feel your enthusiasm!
Showcase Your Skills: In your application, donât just list your skills; demonstrate them! Mention specific tools you've used, projects you've worked on, or challenges you've overcome in penetration testing. We love seeing real-world applications of your expertise.
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way to ensure your application gets into the right hands. Plus, youâll find all the details about the role and our company culture there!
How to prepare for a job interview at Thales Group
â¨Know Your Stuff
Make sure you brush up on your technical skills and knowledge related to penetration testing. Familiarise yourself with tools like Burp Suite, Metasploit, and Nmap, as well as the latest trends in cybersecurity. Being able to discuss your hands-on experience confidently will impress the interviewers.
â¨Showcase Your Problem-Solving Skills
Prepare to discuss specific challenges you've faced in previous roles and how you tackled them. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will demonstrate your analytical thinking and ability to handle complex scenarios, which is crucial for a Cybersecurity Penetration Tester.
â¨Understand the Companyâs Mission
Research Thales and its role in national security. Be ready to explain how your skills align with their mission of safeguarding defence systems. Showing that you understand their values and objectives will help you stand out as a candidate who is genuinely interested in the role.
â¨Prepare Questions
Have a list of insightful questions ready to ask at the end of the interview. This could include inquiries about the team dynamics, ongoing projects, or opportunities for professional development. Asking thoughtful questions shows your enthusiasm for the position and helps you gauge if the company is the right fit for you.