Penetration Tester

Royal London

Alderley Edge

Hybrid

GBP 60,000 - 110,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Royal London is seeking a Penetration Tester to join the Attack Surface Management function. The role focuses on identifying and addressing security vulnerabilities across systems, networks and applications, simulating real-world cyber attacks and strengthening defences.

You will work with the Cyber Testing team to scope, deliver and report tests, applying ethical hacking practices and clear remediation guidance to technical and non-technical stakeholders.

Qualifications

  • Penetration testing methodology knowledge and practical experience.
  • Experience assessing large, complex networks and infrastructure.
  • Strong understanding of network protocols, architecture and security mechanisms.
  • Practical experience across Linux and Windows, capable of identifying and exploiting vulnerabilities.
  • Knowledge of common web application vulnerabilities and how to identify and explain them.
  • Familiarity with cyber security and penetration testing tooling for scanning, recon and exploitation.
  • Ability to define penetration test scope, objectives and rules of engagement in large environments.
  • Strong written and verbal communication to document findings and explain risk clear to all audiences.
  • Analytical, methodical approach to complex technical and business challenges.
  • Proactive, continual learning mindset on latest threats and best practices.
  • Qualifications such as OSCP, OSCE, CRT, GPEN, GXPN, CHECK Team Member or similar are beneficial.
  • Experience in financial services or regulated industries is advantageous.

Responsibilities

  • Scope, deliver and report on penetration tests across Royal London’s systems, networks and applications.
  • Simulate cyber attacks in a controlled and responsible way to identify vulnerabilities and strengthen the Attack Surface.
  • Define testing scope, objectives and rules of engagement with the Penetration Testing Technical Lead.
  • Apply penetration testing methodologies across the full lifecycle, from pre-test to remediation and closure.
  • Use tools and techniques for scanning, reconnaissance, exploitation and analysis (Burp, Metasploit, Wireshark, Nmap).
  • Assess vulnerabilities across Linux, Windows, networks, infrastructure and web apps (SQLi, XSS).
  • Document findings clearly and communicate security risks and remediation guidance to stakeholders.
  • Maintain auditable records to support results and remediation requirements.
  • Contribute to development of testing practices, methods and quality measures across the function.
  • Provide external threat perspectives to team discussions and management information.
  • Support the wider Operational Resilience function through consultation and independent review.

Skills

Penetration testing
Network security
Windows & Linux
Web application security
Communication skills

Tools

Burp Suite
Metasploit
Wireshark
Nmap

Job description

Contract Type: Permanent
Location: Alderley Park (Wilmslow) or Glasgow
Working Style: Hybrid - 50% from home / 50% office based

The Penetration Tester role, working within the Attack Surface Management function, plays a key role in helping Royal London identify, assess and address security vulnerabilities across computer systems, networks and applications. The role supports the delivery of penetration testing across the Group, helping to simulate real-world cyber attacks and strengthen Royal London’s defences against current and emerging threats.

You will work closely with the wider Cyber Testing team to scope, deliver and report on penetration tests, applying ethical hacking principles and responsible testing practices. You’ll use your knowledge of network protocols, infrastructure, operating systems, security tooling and common application vulnerabilities to provide clear, practical insight that helps technical and non-technical stakeholders understand and remediate risk.

More About the role:
Job description:

Contract Type: Permanent
Location: Alderley Park (Wilmslow) or Glasgow
Working Style: Hybrid - 50% from home / 50% office based

The Penetration Tester role, working within the Attack Surface Management function, plays a key role in helping Royal London identify, assess and address security vulnerabilities across computer systems, networks and applications. The role supports the delivery of penetration testing across the Group, helping to simulate real-world cyber attacks and strengthen Royal London’s defences against current and emerging threats.

You will work closely with the wider Cyber Testing team to scope, deliver and report on penetration tests, applying ethical hacking principles and responsible testing practices. You’ll use your knowledge of network protocols, infrastructure, operating systems, security tooling and common application vulnerabilities to provide clear, practical insight that helps technical and non-technical stakeholders understand and remediate risk.

  • Scope, deliver and report on penetration tests across Royal London’s systems, networks and applications.
  • Simulate cyber attacks in a controlled and responsible way to identify vulnerabilities and help strengthen Royal London’s Attack Surface.
  • Work closely with the Penetration Testing Technical Lead to define testing scope, objectives and rules of engagement.
  • Apply penetration testing methodologies across the full lifecycle, from pre-test definition through to reporting, remediation support and closure.
  • Use tools and techniques for scanning, reconnaissance, exploitation and analysis, including awareness of tools such as Burp, Metasploit, Wireshark and Nmap.
  • Assess vulnerabilities across Linux, Windows, networks, infrastructure and web applications, including common issues such as SQL injection and cross-site scripting.
  • Document findings clearly and communicate security risks, impacts and remediation guidance to both technical and non-technical stakeholders.
  • Maintain auditable records to support penetration test results, management information and remediation requirements.
  • Contribute to the development of penetration testing practices, methods and quality measures across the Attack Surface Management function.
  • Bring an external view of penetration testing threats, techniques and good practice to team discussions and management information.
  • Support the wider Operational Resilience function through consultation, advice, challenge and independent review of activities and proposals.
  • Help scope, arrange and deliver external penetration tests with our 3rd party provider, assessing and validating and findings and reporting these to business owners with SME guidance and advice.
What you will bring to the role:
  • A credible penetration testing professional with strong knowledge and operational experience of penetration testing methodology.
  • Experience assessing large, complex networks and infrastructure environments, ideally within an enterprise-scale organisation.
  • Strong understanding of network protocols, architecture and security mechanisms.
  • Practical experience across operating systems including Linux and Windows, with the ability to identify and exploit vulnerabilities across platforms.
  • Knowledge of common web application vulnerabilities and how they can be identified, assessed and explained.
  • Familiarity with cyber security and penetration testing tooling used for scanning, reconnaissance and exploitation.
  • Ability to define penetration test scope, objectives and rules of engagement, preferably in a large company environment.
  • Strong written and verbal communication skills, with the ability to document findings clearly and communicate security risks to both technical and non-technical audiences.
  • Analytical and methodical approach to demanding technical and business challenges, with a high level of accuracy and focus.
  • Positive, service-oriented mindset, with the ability to work collaboratively and represent Cyber professionally across the Group.
  • Proactive approach to personal development, staying current with the latest threats, techniques and security measures.
  • Qualifications such as OSCP, OSCE, CRT, GPEN, GXPN, CHECK Team Member or similar are beneficial.
  • Experience working in financial services or another regulated industry would be beneficial.
About Royal London

We’re the UK’s largest mutual life, pensions and investment company, offering protection, long-term savings and asset management products and services.

Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve.

We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance.

Inclusion, diversity and belonging

We’re an inclusive employer. We celebrate and value different backgrounds and cultures across Royal London. Our diverse people and perspectives give us a range of skills which are recognised and respected – whatever their background.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Testing Lead
Penetration Testing Lead

LLOYDS BANKING GROUP • City of Edinburgh

On-site
GBP 93,000 - 120,000
Generous pension contribution
Annual bonus
Share schemes including free shares
+3
Penetration Testing Lead
Penetration Testing Lead

LLOYDS BANKING GROUP • City Of London

Hybrid
GBP 95,000 - 139,000
Pension up to 15%
Annual bonus
Share schemes
+4
Penetration Testing Lead
Penetration Testing Lead

LLOYDS BANKING GROUP • West of England

On-site
GBP 93,000 - 120,000
Pension up to 15%
Annual bonus
Share schemes
+3
Penetration Testing Lead
Penetration Testing Lead

Lloyds Bank plc • United Kingdom

Hybrid
GBP 93,000 - 120,000
Generous pension contribution
Annual bonus
Share schemes
+2
Penetration Testing Lead — Hybrid, Enterprise Impact
Penetration Testing Lead — Hybrid, Enterprise Impact

LLOYDS BANKING GROUP • City of Edinburgh

Hybrid
GBP 93,000 - 120,000
Generous pension contribution
Annual bonus
Share schemes including free shares
+3
Penetration Tester
Penetration Tester

Royal London • City of Edinburgh

Hybrid
GBP 40,000 - 55,000
28 days annual leave
14% employer matching pension scheme
Private medical insurance
Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Securi[...]
Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Securi[...]

Bank of England • City Of London

Hybrid
GBP 90,000 - 120,000
Hybrid working
Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Securi[...]
Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Securi[...]

Bank of England • Leeds

Hybrid
GBP 90,000 - 120,000
Non-contributory pension
Private medical insurance
Income protection
+1
Penetration Tester
Penetration Tester

Barlowe LLP • Greater London

On-site
GBP 90,000 - 130,000
Discretionary bonus
Lunch via Just Eat for Business
35 days annual leave
+5
Penetration Tester
Penetration Tester

G-Research • City Of London

On-site
GBP 70,000 - 110,000
Competitive compensation
35 days annual leave
Healthcare and life assurance
+1