> Markdown version of [/jobs/ext/2256144-penetration-testing-lead](https://www.wearedevelopers.com/jobs/ext/2256144-penetration-testing-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Testing Lead - **Company:** Lloyds Banking Group - **Location:** Manchester, UK - **Experience:** Expert - **Salary:** £92,701.0 - £109,060.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Bash Shell, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing, Cyber Security, Python (Programming Language), Software Engineering, Strategies of Testing, Rust (Programming Language), Model Validation, GWAPT, Information Technology, Vulnerability Analysis - **Published:** August 26, 2026 - **Apply:** https://lbg.wd3.myworkdayjobs.com/LBG_Careers/job/Manchester/Penetration-Testing-Lead_162277-1 ## About the Role If you're passionate about offensive security, enjoy developing high-performing teams, and want to influence cyber resilience at enterprise scale, we'd love to hear from you., * Extensive experience leading penetration testing, application security testing or offensive security functions within a large and complex organisation. * Demonstrable expertise in conducting and supervising complex application, API, cloud, infrastructure and network penetration testing engagements. * Strong understanding of penetration testing methodologies, vulnerability discovery techniques, offensive security tooling and attacker tradecraft. * Experience building, developing and leading high-performing technical teams. * Excellent customer interaction skills, with the ability to communicate effectively with technical and non-technical audiences, including senior leadership. * Strong understanding of modern enterprise technology environments, cloud platforms, operating systems, networks, software development practices and security controls. * Passion for cyber security research, continuous learning and advancing security testing practices., * Recognised offensive security certifications such as CREST, OSCP, OSCE, OSEP, GIAC, GWAPT, CPTS, CAPE or equivalent. * Software development, automation or engineering experience in any low-level or high-level language (C#, C++, C, Python, Bash, Java, Rust, etc.). * Experience within financial services or other highly regulated environments. * Degree or postgraduate qualification in Cyber Security, Computer Science, or a related field, or equivalent experience. * Familiarity with autonomous vulnerability discovery, AI-enabled security testing, frontier model evaluation, fuzzing frameworks and modern security engineering practices. ## Description We're looking for an experienced and highly capable Penetration Testing Lead to lead and evolve our penetration testing capability. Reporting to the Offensive Security Lead, you'll be accountable for the strategic direction, operational delivery and technical excellence of the team. This role combines deep technical expertise with inspirational leadership, leading a team of highly skilled penetration testers while shaping the roadmap for both human-led and autonomous security testing across the Group. Spanning traditional end-to-end penetration testing services and continuous assurance capabilities, you'll work closely with engineering, security and business stakeholders, as well as the Autonomous Vulnerability Research and Harness Engineering teams, to continuously improve the Group's security posture., We're looking for an experienced and highly capable Penetration Testing Lead to lead and evolve our penetration testing capability. Reporting to the Offensive Security Lead, you'll be accountable for the strategic direction, operational delivery and technical excellence of the team. This role combines deep technical expertise with inspirational leadership, leading a team of highly skilled penetration testers while shaping the roadmap for both human-led and autonomous security testing across the Group. Spanning traditional end-to-end penetration testing services and continuous assurance capabilities, you'll work closely with engineering, security and business stakeholders, as well as the Autonomous Vulnerability Research and Harness Engineering teams, to continuously improve the Group's security posture. If you're passionate about offensive security, enjoy developing high-performing teams, and want to influence cyber resilience at enterprise scale, we'd love to hear from you. What You'll Be Doing: * Draw on extensive hands-on penetration testing experience to shape testing strategy, guide the execution of complex application and infrastructure security assessments, and ensure the delivery of high-quality, risk-focused testing that helps strengthen the Group's security posture. * Lead, mentor and develop a high-performing team of penetration testers, encouraging a culture of technical excellence, continuous improvement, innovation and open communication. * Define and carry out the Penetration Testing roadmap, ensuring alignment to CSO and wider Group security objectives while delivering a comprehensive security testing programme spanning threat resilience, regulatory, change-driven and continuous assurance testing. * Drive the evolution of autonomous security testing through close collaboration with the Autonomous Vulnerability Research and Harness Engineering teams, helping embed automation, frontier model testing and scalable security validation capabilities across the testing lifecycle. * Build positive relationships across the Chief Security Office and wider organisation. Communicate security risks, testing outcomes, and recommendations to technical practitioners and executives. Collaborate with teams to prioritise and remediate findings swiftly. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)