Hybrid Cybersecurity Penetration Tester

Posted 4 weeks ago

Apply now

About the role

  • Cybersecurity Penetration Tester role at Thales safeguarding UK Defence systems through advanced penetration testing. Working at the forefront of national security with red teaming on military platforms.

Responsibilities

  • Safeguard UK Defence systems through advanced penetration testing and red teaming on critical military platforms
  • Tackle complex threat simulations and exploit development across IT, OT, cloud, and embedded environments
  • Use cutting‑edge tools with funded training and certifications (CHECK, CREST, OSCP, GIAC)
  • Lead end‑to‑end penetration testing across networks, applications, cloud infrastructures, and embedded systems - delivering actionable insights that strengthen mission‑critical environments
  • Drive advanced vulnerability assessments and exploit development, executing post‑exploitation activities within authorised scopes to uncover hidden risks and resilience gaps
  • Orchestrate red and purple team engagements, simulating sophisticated threat scenarios against defence systems to rigorously test and enhance security posture
  • Produce high‑impact technical reports and executive briefings, translating complex findings into clear risk narratives, business impact assessments, and prioritised remediation strategies
  • Partner with defensive operations and risk management teams to sharpen detection, accelerate response, and embed proactive resilience across the enterprise
  • Stay ahead of adversaries by maintaining expert knowledge of tactics, techniques, and procedures (TTPs) employed by state and non‑state actors in the defence sector
  • Champion compliance and assurance by aligning practices with MOD, NCSC, and international standards (JSP 440, ISO 27001, NIST, CHECK, CREST), ensuring robust governance and trust

Requirements

  • Degree in Computing, Cybersecurity, or a related field - or equivalent professional experience in lieu of formal tertiary studies
  • CHECK Team Leader accreditation currently held
  • Demonstrated track record as a Penetration Tester, Red Team Operator, or equivalent offensive security specialist
  • Proven ability to manage small technical teams, demonstrating strong people skills, mentorship, and collaborative leadership
  • Deep expertise in network protocols, application security, operating systems, and cloud platforms across both IT and OT environments
  • Hands-on proficiency with industry-standard tools including Burp Suite, Metasploit, Cobalt Strike, Nmap, Nessus, plus custom scripting in Python, PowerShell, and Bash
  • Proven experience conducting penetration tests across diverse systems: Windows, Linux, Android, iOS, Web Applications, and Cloud infrastructures
  • Familiarity with defence and government environments, including secure handling of classified information
  • Exceptional written and verbal communication skills, able to translate complex technical findings into clear, actionable insights
  • SC or DV clearance (mandatory for project delivery), with eligibility or current holding

Benefits

  • Annual bonus (VCP)
  • Pension – match like-for-like up to 7% of annual base salary
  • Life Assurance – 2 x base salary minimum (8 x salary if part of the pension scheme)
  • Income Protection – 50% of salary less state benefits for 5 years
  • Annual Leave – 201 hours, bank holidays, plus 1 company day
  • Private Medical Insurance - Couples cover
  • Half day every Friday, usually finishing around 1:00pm
  • 24/7 Employee Assistance Programme
  • 24 hours paid leave for volunteering activities
  • Access to flexible benefits and discounts – dental insurance, buying & selling annual leave, cycle to work, and many more

Job title

Cybersecurity Penetration Tester

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job