> Markdown version of [/jobs/ext/2308070-penetration-testing-lead](https://www.wearedevelopers.com/jobs/ext/2308070-penetration-testing-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Testing Lead - **Company:** Motor Insurers' Bureau - **Location:** Milton Keynes, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing Security, Cyber Security, Computer Programming, Python (Programming Language), Kali Linux, Network Protocols, Nmap, Open Web Application Security, Ruby, Software Engineering, Software Vulnerability Management, Web Applications, Scripting, Google Cloud, Metasploit, Devsecops, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815383291-penetration-testing-lead ## About the Role * Significant experience in cyber security, with at least experience in a lead or senior role. * Proven experience in managing and conducting penetration tests, vulnerability assessments, internal security testing, and security audits. * In-depth knowledge of security testing tools such as Burp Suite, Nmap, Metasploit, and Kali Linux. * Strong understanding of common web application vulnerabilities (OWASP Top 10) and network protocols. * Excellent communication and leadership skills, with the ability to articulate complex security concepts to diverse audiences. * Relevant certifications such as OSCP, CEH, or CISSP. * Experience with cloud security testing (AWS, Azure, GCP). * Familiarity with DevSecOps principles and practices. * Scripting or programming experience in Python, Ruby, or similar languages. * Experience with threat modelling. * Experience assisting with business continuity testing and planning. ## Description * As Cyber Security Test Lead, you will be responsible for leading and managing all security testing activities across the organisation. You will develop and implement a comprehensive security testing strategy, oversee penetration testing and vulnerability assessments, and ensure that security findings are managed and remediated effectively. You will provide technical direction, collaborate with cross-functional teams, and mentor team members to foster their professional growth and technical skills. You will also act as the primary point of contact between MIB and third parties who provide testing capability. Your work will help ensure that MIB systems and applications remain secure and resilient against evolving threats., Security Testing Leadership * Lead and manage security testing activities, including (but not limited to) network, application, cloud, and internal security testing. * Develop and implement a comprehensive security testing strategy and roadmap ensuring full coverage of the MIB estate. * Provide technical guidance and support on complex security vulnerabilities and remediation efforts. * Mentor and manage other members in the information security team involved in testing, supporting their professional development., * Manage security findings from penetration tests, vulnerability scans, and internal security assessments, working with development teams to ensure timely remediation. * Provide technical guidance and analysis of complex vulnerabilities as well as proposed remediation efforts. * Ensure reliable validation of remediation actions. Collaboration and Integration of Testing * Collaborate with development, product, infrastructure, change and project teams to integrate security testing into the Secure Software Development Life Cycle (SSDLC). * Prepare and present detailed reporting on security testing findings and the overall security posture to both technical and non-technical stakeholders. Business Continuity and Continual Improvement * Assist with business continuity testing, ensuring security controls and processes support organisational resilience. * Stay up to date with the latest security threats, trends, and testing methodologies. * Foster a culture of continuous improvement within the security testing team. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)