Penetration Testing Lead

Motor Insurers' Bureau
Milton Keynes, UK
1 day ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Burp Suite Cloud Computing Security Cyber Security Computer Programming Python (Programming Language) Kali Linux Network Protocols Nmap Open Web Application Security
+9 more
Ruby Software Engineering Software Vulnerability Management Web Applications Scripting Google Cloud Metasploit Devsecops Vulnerability Analysis

Job description

  • As Cyber Security Test Lead, you will be responsible for leading and managing all security testing activities across the organisation. You will develop and implement a comprehensive security testing strategy, oversee penetration testing and vulnerability assessments, and ensure that security findings are managed and remediated effectively. You will provide technical direction, collaborate with cross-functional teams, and mentor team members to foster their professional growth and technical skills. You will also act as the primary point of contact between MIB and third parties who provide testing capability. Your work will help ensure that MIB systems and applications remain secure and resilient against evolving threats., Security Testing Leadership

  • Lead and manage security testing activities, including (but not limited to) network, application, cloud, and internal security testing.
  • Develop and implement a comprehensive security testing strategy and roadmap ensuring full coverage of the MIB estate.
  • Provide technical guidance and support on complex security vulnerabilities and remediation efforts.
  • Mentor and manage other members in the information security team involved in testing, supporting their professional development., * Manage security findings from penetration tests, vulnerability scans, and internal security assessments, working with development teams to ensure timely remediation.
  • Provide technical guidance and analysis of complex vulnerabilities as well as proposed remediation efforts.
  • Ensure reliable validation of remediation actions.

Collaboration and Integration of Testing

  • Collaborate with development, product, infrastructure, change and project teams to integrate security testing into the Secure Software Development Life Cycle (SSDLC).
  • Prepare and present detailed reporting on security testing findings and the overall security posture to both technical and non-technical stakeholders.

Business Continuity and Continual Improvement

  • Assist with business continuity testing, ensuring security controls and processes support organisational resilience.
  • Stay up to date with the latest security threats, trends, and testing methodologies.
  • Foster a culture of continuous improvement within the security testing team.

Requirements

  • Significant experience in cyber security, with at least experience in a lead or senior role.
  • Proven experience in managing and conducting penetration tests, vulnerability assessments, internal security testing, and security audits.
  • In-depth knowledge of security testing tools such as Burp Suite, Nmap, Metasploit, and Kali Linux.
  • Strong understanding of common web application vulnerabilities (OWASP Top 10) and network protocols.
  • Excellent communication and leadership skills, with the ability to articulate complex security concepts to diverse audiences.
  • Relevant certifications such as OSCP, CEH, or CISSP.
  • Experience with cloud security testing (AWS, Azure, GCP).
  • Familiarity with DevSecOps principles and practices.
  • Scripting or programming experience in Python, Ruby, or similar languages.
  • Experience with threat modelling.
  • Experience assisting with business continuity testing and planning.

Benefits & conditions

  • Contributory Group Stakeholder Personal pension scheme
  • Life Assurance
  • Employee Incentive Scheme
  • Sports and Social Club
  • 24/7 Employee Assistance Programme
  • Free access to online tools to support mental and physical health
  • Enhanced maternity, paternity and adoption leave
  • 1 volunteer day each year and charity matched funding scheme

We believe in a workplace where everyone can be themselves. Through our different ideas, personalities and experiences, we redefine what is possible every day. And regardless of your colour, age, race, gender, sexual orientation or anything else you consider yourself to be, there is a place for you at MIB. A place where you can bring your best self to work every day.

So, if you think big, love a challenge and want to make a difference to people’s lives, we want to hear from you.

We aim to keep this advert open until the closing date, but on occasion we may close it early if application numbers are high #J-18808-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

Videos

See all

Related articles

See all