Penetration Tester - Vulnerability Researcher

Penetration Tester - Vulnerability Researcher

Full-Time 63000 - 77000 £ / year (est.) No working from home possible
WeAreTechWomen

At a Glance

  • Tasks: Conduct penetration testing and identify vulnerabilities in complex systems.
  • Company: Join Thales, a global tech leader in defence and cybersecurity.
  • Benefits: Enjoy a competitive salary, private healthcare, and 28 days annual leave.
  • Other info: Flexible work hours, opportunities for career growth, and a supportive team culture.
  • Why this job: Make a real impact on national security while working with cutting-edge technology.
  • Qualifications: Experience in penetration testing and a degree in Computer Science or related field.

The predicted salary is between 63000 - 77000 £ per year.

Location: Crawley, United Kingdom

Thales is a global technology leader with more than 83,000 employees on five continents. With over 7,500 people in the UK, operating across defence, space, aerospace, and digital security, we help build a future we can all trust. Thales supports the security and stability of our nation by providing extraordinary technology to our customers, as well as delivering social value to the UK with our products and services.

Join Thales at a pivotal time as we expand our Cyber Security capability across critical national infrastructure, defence, and aerospace programmes. As a Penetration Tester, you’ll play a key role in identifying vulnerabilities across complex systems and helping secure technologies that truly matter.

From secure software to biometrics and encryption, our CDI technologies and services enable organisations to confidently authenticate identities and protect data with care and precision. We support businesses and governments in keeping people safe and enabling trusted services across personal devices, connected objects, the cloud and everything in between.

The Opportunity:

You’ll work on high-impact projects, performing penetration testing across IT and OT environments while influencing secure design and risk mitigation strategies from early project stages through to delivery.

What You’ll Be Doing:

  • Conduct penetration testing across Windows, Linux, mobile (iOS/Android), web applications, and cloud environments
  • Identify, exploit, and clearly communicate security vulnerabilities and risks
  • Support accreditation and assurance activities on complex, high-security programmes
  • Advise on security controls and mitigation strategies aligned to customer needs
  • Contribute to governance frameworks, policies, and secure operating procedures
  • Produce high-quality technical reports and through-life security documentation
  • Act as a cybersecurity SME across projects, staying aligned with evolving regulations and standards
  • Collaborate with internal teams, customers, and external stakeholders at all levels
  • Support bid activities, including technical input and effort estimation

What We’re Looking For:

  • Hands-on penetration testing experience across diverse platforms (IT and/or OT environments)
  • Strong understanding of security testing methodologies and frameworks
  • Experience producing clear, actionable technical reports
  • Degree in Computer Science, Engineering, or equivalent experience
  • Industry certifications such as CREST, OSCP, CEH, GPEN, GXPN (or similar)

Desirable Experience:

  • Background in Defence, Aerospace, Government, Nuclear, Transport, or other regulated industries
  • Familiarity with compliance-driven environments and secure system accreditation

Why Thales?

  • Work on mission-critical systems that protect national security and infrastructure
  • Opportunities to move across domains, technologies, and international locations
  • Clear pathways into technical leadership or people management
  • Be part of a globally recognised engineering and technology organisation

Benefits:

  • Performance-related bonus
  • Half day every Friday, usually finishing around 13:00
  • 28 days annual leave (plus bank holidays) with opportunity to buy up to 40 hours/year (pro rata)
  • 24 hours volunteering paid for
  • Private healthcare
  • Pension scheme
  • Life cover
  • 24/7 Employee Assistance Program and access to mental wellbeing app
  • Employee discount shopping schemes on major brands and retailers
  • Gym membership discounts

Security Clearance Requirement:

Due to the nature of the work that we do at Thales, many of our roles are subject to security restrictions. This role requires you to be a UK National and achieve Security Clearance (SC) without any caveats. It would be advantageous if currently held, however, if not currently held, it is a requirement that the successful applicant undergo, achieve, and maintain SC Clearance prior to commencing employment. If approved by the MOD, a dual national from a non-ITAR country may be considered.

To be eligible for full SC, you generally need to have resided in the UK for the last 5 years. In some circumstances, a minimum of 3 years’ residence in the UK over the last 5 years may be accepted, with additional overseas checks.

At Thales, we ensure equal opportunities, pay and working conditions for all. The benefits we offer include private medical insurance, buying or selling annual leave, cycle to work schemes, employee discounts, paid volunteering day, stocks and shares, annual bonus and much more depending on the role. We are committed to creating a workplace where everyone feels valued for who they are and the unique strengths they bring.

Penetration Tester - Vulnerability Researcher employer: WeAreTechWomen

At Accenture, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. Our London office provides unparalleled opportunities for professional growth, with access to cutting-edge AI technologies and the chance to work alongside industry leaders. We are committed to your development, ensuring you have the resources and support needed to thrive in your role as a Senior Manager/Associate Director in AI architecture.

WeAreTechWomen

Contact Details:

WeAreTechWomen Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Penetration Tester - Vulnerability Researcher

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including WeAreTechWomen, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through WeAreTechWomen

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at WeAreTechWomen. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Penetration Tester - Vulnerability Researcher

Penetration Testing
Vulnerability Identification
Security Testing Methodologies
Technical Report Writing
Windows Security
Linux Security
Mobile Application Security (iOS/Android)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at WeAreTechWomen insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to WeAreTechWomen that you’re committed to staying ahead in the game.

How to prepare for a job interview at WeAreTechWomen

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at WeAreTechWomen to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at WeAreTechWomen.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.