Penetration Testing Lead

Lloyds Banking Group
Manchester, UK
2 days ago
Apply on lbg.wd3.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£92,701.0 - £109,060.0
Working hours
Regular working hours

Tech stack

C (Programming Language) Java (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Software System Penetration Testing Bash Shell C Sharp (Programming Language) C++ (Programming Language) Cloud Computing Cyber Security Python (Programming Language) Software Engineering
+6 more
Strategies of Testing Rust (Programming Language) Model Validation GWAPT Information Technology Vulnerability Analysis

Job description

We’re looking for an experienced and highly capable Penetration Testing Lead to lead and evolve our penetration testing capability. Reporting to the Offensive Security Lead, you’ll be accountable for the strategic direction, operational delivery and technical excellence of the team. This role combines deep technical expertise with inspirational leadership, leading a team of highly skilled penetration testers while shaping the roadmap for both human-led and autonomous security testing across the Group. Spanning traditional end-to-end penetration testing services and continuous assurance capabilities, you’ll work closely with engineering, security and business stakeholders, as well as the Autonomous Vulnerability Research and Harness Engineering teams, to continuously improve the Group’s security posture., We’re looking for an experienced and highly capable Penetration Testing Lead to lead and evolve our penetration testing capability. Reporting to the Offensive Security Lead, you’ll be accountable for the strategic direction, operational delivery and technical excellence of the team. This role combines deep technical expertise with inspirational leadership, leading a team of highly skilled penetration testers while shaping the roadmap for both human-led and autonomous security testing across the Group. Spanning traditional end-to-end penetration testing services and continuous assurance capabilities, you’ll work closely with engineering, security and business stakeholders, as well as the Autonomous Vulnerability Research and Harness Engineering teams, to continuously improve the Group’s security posture.

If you’re passionate about offensive security, enjoy developing high-performing teams, and want to influence cyber resilience at enterprise scale, we’d love to hear from you.

What You’ll Be Doing:

  • Draw on extensive hands-on penetration testing experience to shape testing strategy, guide the execution of complex application and infrastructure security assessments, and ensure the delivery of high-quality, risk-focused testing that helps strengthen the Group’s security posture.
  • Lead, mentor and develop a high-performing team of penetration testers, encouraging a culture of technical excellence, continuous improvement, innovation and open communication.
  • Define and carry out the Penetration Testing roadmap, ensuring alignment to CSO and wider Group security objectives while delivering a comprehensive security testing programme spanning threat resilience, regulatory, change-driven and continuous assurance testing.
  • Drive the evolution of autonomous security testing through close collaboration with the Autonomous Vulnerability Research and Harness Engineering teams, helping embed automation, frontier model testing and scalable security validation capabilities across the testing lifecycle.
  • Build positive relationships across the Chief Security Office and wider organisation. Communicate security risks, testing outcomes, and recommendations to technical practitioners and executives. Collaborate with teams to prioritise and remediate findings swiftly.

Requirements

If you’re passionate about offensive security, enjoy developing high-performing teams, and want to influence cyber resilience at enterprise scale, we’d love to hear from you., * Extensive experience leading penetration testing, application security testing or offensive security functions within a large and complex organisation.

  • Demonstrable expertise in conducting and supervising complex application, API, cloud, infrastructure and network penetration testing engagements.
  • Strong understanding of penetration testing methodologies, vulnerability discovery techniques, offensive security tooling and attacker tradecraft.
  • Experience building, developing and leading high-performing technical teams.
  • Excellent customer interaction skills, with the ability to communicate effectively with technical and non-technical audiences, including senior leadership.
  • Strong understanding of modern enterprise technology environments, cloud platforms, operating systems, networks, software development practices and security controls.
  • Passion for cyber security research, continuous learning and advancing security testing practices., * Recognised offensive security certifications such as CREST, OSCP, OSCE, OSEP, GIAC, GWAPT, CPTS, CAPE or equivalent.
  • Software development, automation or engineering experience in any low-level or high-level language (C#, C++, C, Python, Bash, Java, Rust, etc.).
  • Experience within financial services or other highly regulated environments.
  • Degree or postgraduate qualification in Cyber Security, Computer Science, or a related field, or equivalent experience.
  • Familiarity with autonomous vulnerability discovery, AI-enabled security testing, frontier model evaluation, fuzzing frameworks and modern security engineering practices.

Benefits & conditions

We’re transforming at pace. Investing billions in our people, data and tech to change the way we meet the needs of our 28 million customers. We’re growing, and we’d love you to be part of the journey.

This is a place for you

Our ambition is to be the leading UK business for diversity, equity and inclusion supporting our customers, colleagues and communities, and we’re committed to creating an environment in which everyone can thrive, learn and develop.

We also offer a wide-ranging benefits package, which includes:

  • A generous pension contribution of up to 15%
  • An annual performance-related bonus
  • Share schemes including free shares
  • Benefits you can adapt to your lifestyle, such as discounted shopping
  • 30 days’ holiday, with bank holidays on top
  • A range of wellbeing initiatives and generous parental leave policies

About the company

At Lloyds Banking Group, we’re driven by a clear purpose; to help Britain prosper. Across the Group, our colleagues are focused on making a difference to customers, businesses and communities. With us you’ll have a key role to play in shaping the financial services of the future, whilst the scale and reach of our Group means you’ll have many opportunities to learn, grow and develop.

We keep your data safe. So, we’ll only ever ask you to provide confidential or sensitive information once you have formally been invited along to an interview or accepted a verbal offer to join us which is when we run our background checks. We’ll always explain what we need and why, with any request coming from a trusted Lloyds Banking Group person.

We’re focused on creating a values-led culture and are committed to building a workforce which reflects the diversity of the customers and communities we serve. Together we’re building a truly inclusive workplace where all of our colleagues have the opportunity to make a real difference.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on lbg.wd3.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all