> Markdown version of [/jobs/ext/3275064-penetration-tester](https://www.wearedevelopers.com/jobs/ext/3275064-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** Nationwide - **Location:** Swindon, UK (Remote available) - **Salary:** £43,234.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Software System Penetration Testing, Bash Shell, C Sharp (Programming Language), Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Cloud Services, Red Team (Cyber Security), Web Applications, Api Design, Api Management, Programming Languages - **Published:** September 8, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5878638016 ## About the Role You will be joining a growing team of dedicated and like-minded individuals where you will be expected to work independently and proactively to ensure that penetration tests are completed successfully, and the findings are understood by key stakeholders. You will have demonstrable experience in delivering penetration tests from scoping through to reporting and post-test triage activity. You will be able to perform tests across a wide range of system and software stacks. Communication skills are vital for the role. You must be comfortable explaining the risks of identified findings to technical and non-technical stakeholders. We are happy to consider flexible working approaches to help you perform at your best. At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected. For this role, you'll be based at your nearest regional office or hub. We value time spent together to connect with colleagues for collaboration so there will be a regular requirement to attend our London site approximately once per quarter. If you are based at an office location, you'll be expected to meet our hybrid working requirement of at least two days a week, or 40% of your working time if part-time, in the office. If your application is successful, your hiring manager will provide further details on how this works., The Penetration Test team are united by a single, shared purpose and it's all about identifying vulnerabilities in systems and technology, to help protect our members. To support this, we are looking for an energetic and experienced security professional with a proven track record of penetration testing, stakeholder management, organisational skills, and prioritising work in high-pressure/high-tempo conditions., * Hands-on experience delivering penetration tests against complex, business-critical systems, including web application and API testing. Experience in purple or red team testing would also be advantageous to help support the delivery of our wider offensive security objectives * Detailed knowledge of penetration testing tools, techniques and methodologies, with demonstrable understanding of security vulnerabilities and risk reduction approaches * Experience testing cloud services, API-based technologies and modern application architectures, with awareness of common security standards and compliance frameworks such as OWASP, CIS and PCI-DSS * Hold an industry recognised qualification such as the CREST CRT, OSCP, CSTM or equivalent, supported by competence in scripting and/or high-level programming languages such as Python, Shell, C#, Java or JavaScript * Resilient, highly motivated self-starter able to work independently or as part of a close-knit team, building relationships with stakeholders at all levels to support a built-for-security culture * Experience in an equivalent role within a large financial services provider or (organisations within a regulated industry) within the last three years, with a proven ability to produce timely penetration testing reports for both technical and non-technical audiences Our customer first behaviours put customers and members at the heart of how we work together. They are the set of behaviours that every colleague needs to display, in every role ## Description As a Penetration Testing Engineer, you will be conducting security assessments, working within our wider offensive security team, playing a key role in identifying and advising on technical findings across Nationwide's estate., As a Security Engineer (Penetration Tester), you'll play a hugely important role in our team. Your core responsibilities will be to perform penetration tests of new and existing systems and in doing so you'll support the business to meet Strategic, Operational and external Compliance objectives. You will have the freedom to help shape and continuously improve our processes and tooling, and you will be encouraged to obtain and maintain technical certifications to support your personal and professional career goals., * Feel what customers feel - We step into our customers' shoes, using their feedback and insights to empathise with them and to understand their needs, so that every decision we make starts and finishes with our customers in mind * Say it straight - We are brave in speaking out and saying what we think - we're honest and direct with good intent, openly sharing diverse perspectives to reach the best conclusions and using language everyone can understand * Push for better - We don't settle for mediocrity, we challenge the status quo, taking responsibility for continuous improvement and personal development * Get it done - We prioritise what will have the greatest impact, we are decisive, and we take accountability for delivering brilliant customer outcomes You can strengthen your application by showing how our customer first behaviours resonate with you, and where you may have already demonstrated these.