Penetration Tester

RSA Group
UK
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Web Applications Cloud Platform System Purple Team (Cyber Security) Vulnerability Analysis

Job description

  • Delivering penetration testing across applications, infrastructure, APIs, and cloud environments to identify and validate security weaknesses.
  • Contributing to end-to-end testing activities including reconnaissance, exploitation, and reporting using recognised industry methodologies.
  • Supporting the oversight of external penetration testing suppliers through scoping, quality review, and validation of findings.
  • Working with development and delivery teams to embed proportionate security testing into projects and change.
  • Collaborating with Cyber Defence colleagues during remediation, investigations, and purple team activities to translate technical issues into business risk
  • Delivering penetration testing across applications, infrastructure, APIs, and cloud environments to identify and validate security weaknesses.
  • Contributing to end-to-end testing activities including reconnaissance, exploitation, and reporting using recognised industry methodologies.
  • Supporting the oversight of external penetration testing suppliers through scoping, quality review, and validation of findings.
  • Working with development and delivery teams to embed proportionate security testing into projects and change.
  • Collaborating with Cyber Defence colleagues during remediation, investigations, and purple team activities to translate technical issues into business risk

Requirements

  • Experience delivering penetration testing across web applications, APIs, infrastructure, and cloud environments.
  • Excellent understanding of common vulnerability classes and attacker techniques, including those aligned to recognised industry guidance.
  • Ability to apply penetration testing methodologies and tools in practical testing scenarios and interpret vulnerability scanning results.
  • Ability to produce clear, structured reports that explain technical risk and remediation for technical and non technical audiences.
  • Interest in developing offensive security capability and contributing to continuous improvement through learning and knowledge sharing.

Benefits & conditions

Being part of our team means you’ll have the support and freedom to bring your best self to work each day. As a permanent member, here’s what you can look forward to

  • Annual discretionary bonus
  • Up to 11% pension contributions
  • Hybrid working + flexible hours
  • 25 days annual leave + bank holidays + buy/sell options
  • Health & wellbeing + virtual GP
  • Career development and mentoring
  • Inclusive culture + employee networks
  • Share investment options

About the company

Intact Insurance is the new name for RSA in the UK, Ireland, and across Europe. It’s a new name and a new way to do business. Backed by global expertise and a commitment to service that feels different, we’re focused on making insurance simpler, faster, and more responsive.

Shape the future:

We’re leading a transformation in insurance helping people, businesses and society prosper in good times and be resilient in bad times. When you join us, you’re not just taking a job, you’re stepping into a career where you can make a real difference.

Grow with us:

We’re customer-driven, community-focused, and committed to helping our people grow. Whether you’re early in your journey or bringing years of experience, we’ll support you with the tools, flexibility, and opportunities to thrive.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.rsagroup.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

1:36 min

Running AI applications with PWAs and background web workers

Maxim Salnikov Maxim Salnikov · WWC 2025

2:27 min

Exploring Rust for cloud and web services

Patrick Koss Patrick Koss · WWC 2024

3:17 min

Embedding automated vulnerability analysis within CircleCI workflows

Milecia Mcgregor · LIVE

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

6:11 min

Overview of the 2025 OWASP Top Ten list

Christian Wenz Christian Wenz · WWC Europe 2026

Videos

See all

Related articles

See all