Lead Penetration Tester in Technical Vulnerability Management
Listed on 2026-06-04
-
IT/Tech
Cybersecurity
Lead Penetration Tester (Lead Cyber Analyst), Technical Vulnerability Management - Cyber Security Division
Permanent
Full time
We currently have a number of Penetration Tester opportunities across our Cyber team - if this role isn't the right fit, we encourage you to explore what else is available:
- Junior Penetration Tester (Cyber Analyst), Threat & Vulnerability Management - Cyber Security Division
This is an opportunity to join the Bank of England's Pentest Team as a Lead Penetration Tester and play a senior role in strengthening the Bank's security. You'll lead and deliver penetration testing across a broad range of systems and services, assess complex vulnerabilities, and support red and purple team activity. Working with colleagues across Cyber and Technology, you'll help shape testing approaches, provide technical leadership, and drive effective remediation to reduce risk across the organisation.
FlexibleWorking Options
This role is open to flexible working patterns as follows:
- Flexible start and end time to each day
- Flexibility to adapt your calendar as needed, for example around the school run, the gym, or appointments
- A 50% in-office attendance requirement, which can be spread across the month to support different working patterns
- Working from abroad policy (subject to approval and policy within the team)
We're excited to growing our presence in Leeds, a city we've been connected to for nearly 200 years! Our modern, accessible office in the City Centre offers a supportive, flexible working environment. The majority of roles, including this one, are now available in Leeds, giving you the chance to build a meaningful career outside of London while contributing to our mission from a dynamic and growing location.
You'll work collaboratively with London-based colleagues in a hybrid model, with regular opportunities to travel into the London office to meet and connect together in person.
Want to learn more? Discover what makes our Leeds office such a dynamic place to work by visiting our Leeds page for more details.
A day in the roleNo two days in this role are exactly the same. You might start the day aligning priorities with the team, then move into leading a penetration test, reviewing complex findings, or shaping the approach to a new assessment. You'll work closely with colleagues across Cyber and Technology, providing technical oversight, engaging with stakeholders, and helping to ensure that vulnerabilities are clearly understood and effectively remediated.
As a senior member of the team, you'll also support the development of others, contribute to improving testing practices, and help drive high-quality delivery across a varied portfolio of systems and services. The role also offers flexibility in how you organise your day, with flexible start and finish times and hybrid working between the Leeds office and home.
You will bring strong hands‑on penetration testing experience and the ability to lead complex assessments across areas such as infrastructure, cloud, and web applications. You should be comfortable working with a high degree of autonomy, applying sound technical judgement, and engaging confidently with stakeholders to explain risk and influence remediation. As a senior member of the team, you will also be expected to provide technical leadership, support the development of others, and contribute to the continued evolution of the Bank's testing capability.
To be successful in this role, you will need to demonstrate strong technical capability and credible hands‑on experience across the core areas below.
- Significant hands‑on penetration testing experience, including leading or delivering complex assessments in medium to large enterprise environments
- Equivalent work experience or two or more of the following certifications: OSCP, OSEP, OSWE, OSED, GXPN, GX‑PT, CREST CTL (INF/APP), Cyber Scheme CSTL (INF/APP), CRTO, CRTP
- Strong practical experience in enterprise infrastructure, cloud, or complex web application pentesting
- Practical expertise using commercial and open‑source offensive security tools
A strong understanding of common…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: