> Markdown version of [/jobs/ext/3100834-lead-penetration-tester](https://www.wearedevelopers.com/jobs/ext/3100834-lead-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Penetration Tester - **Company:** Morson Group - **Location:** Salford, UK - **Experience:** Expert - **Salary:** £36,000.0 - £76,000.0 - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, JIRA, Microsoft Azure, Cloud Computing, Cyber Security, DevOps, Open Web Application Security, PCI Data Security Standards, Strategies of Testing, Software Vulnerability Management, Cloud Platform System - **Published:** September 27, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5899590505 ## About the Role * Significant experience in penetration testing / offensive security, with the ability to lead complex testing engagements. * Strong hands-on understanding of penetration testing across applications, infrastructure and technology environments. * Proven experience managing the full penetration testing lifecycle, including scoping, planning, execution, reporting and remediation. * Experience overseeing and managing third-party penetration testing suppliers. * Strong ability to review, interpret and challenge penetration testing reports and technical findings. * Proven experience managing vulnerabilities and security defects through to remediation. * Experience working closely with engineering, DevOps, product and delivery teams. * Strong stakeholder management skills, with the ability to translate technical vulnerabilities into clear business risks and required actions. * Experience using Jira or similar tooling to manage security findings and remediation activity. * Strong understanding of security risk assessment, vulnerability prioritisation and risk acceptance. * Knowledge of recognised penetration testing methodologies and security frameworks. * Relevant penetration testing/offensive security certifications such as CREST, OSCP, OSWE, GPEN or equivalent. * Experience operating within large, complex or highly regulated organisations. * Experience across cloud environments, particularly Azure and/or AWS. * Experience with application, API, network, infrastructure and/or cloud penetration testing. * Familiarity with vulnerability management and security operations processes. * Experience working within environments subject to ISO 27001, PCI-DSS, GDPR or CAF requirements. ## Description * Lead the end-to-end penetration testing lifecycle, including scoping, planning, execution, reporting and remediation across applications, infrastructure and systems. * Provide hands-on penetration testing expertise while coordinating and overseeing third-party testing providers. * Review and challenge penetration testing reports, assessing findings based on severity, exploitability, business impact and risk. * Work closely with engineering, DevOps, product and delivery teams to prioritise and drive vulnerabilities through to resolution within agreed SLAs. * Own the tracking and management of penetration testing findings in Jira, ensuring actions are assigned, monitored and closed. * Lead regular remediation discussions with internal stakeholders and third parties, escalating blockers and ensuring residual risks are appropriately recorded and accepted. * Ensure penetration testing and remediation activities align with relevant security standards, regulatory requirements and industry best practice, including OWASP, NIST, ISO 27001, PCI-DSS, GDPR and CAF. * Ensure appropriate governance, documentation and evidence is maintained throughout the testing lifecycle. * Provide assurance over the quality and effectiveness of third-party penetration testing engagements. * Identify and implement improvements to penetration testing, vulnerability management and remediation processes. * Use testing outcomes, lessons learned and emerging threats to improve security controls and testing methodologies. Technologies: * API * AWS * Azure * Cloud * DevOps * JIRA * Network * OWASP * Security, This is a contract Lead Penetration Tester role for an initial 6 months at a day rate of £700-£800 per day, inside IR35. We require 1 day per month on site, either in Chesterfield or London. This is a hands-on leadership role where we combine penetration testing expertise with coordination of testing engagements, third-party suppliers, vulnerability remediation and security findings. You will work closely with internal engineering, DevOps, product and delivery teams, as well as external providers, to ensure testing is scoped and executed to a high standard and that vulnerabilities are prioritised through to resolution. This role is suited to a senior/lead-level penetration tester who wants ownership of the testing and remediation lifecycle. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fullstack Developer Salary UK](https://www.wearedevelopers.com/magazine/251-fullstack-developer-salary-uk)