Contract Type: Permanent
Location: Alderley Park (Wilmslow) or Glasgow
Working Style: Hybrid - 50% from home / 50% office based
The Penetration Tester role, working within the Attack Surface Management function, plays a key role in helping Royal London identify, assess and address security vulnerabilities across computer systems, networks and applications. The role supports the delivery of penetration testing across the Group, helping to simulate real-world cyber attacks and strengthen Royal London’s defences against current and emerging threats.
You will work closely with the wider Cyber Testing team to scope, deliver and report on penetration tests, applying ethical hacking principles and responsible testing practices. You’ll use your knowledge of network protocols, infrastructure, operating systems, security tooling and common application vulnerabilities to provide clear, practical insight that helps technical and non-technical stakeholders understand and remediate risk.
More About the role:
- Scope, deliver and report on penetration tests across Royal London’s systems, networks and applications.
- Simulate cyber attacks in a controlled and responsible way to identify vulnerabilities and help strengthen Royal London’s Attack Surface.
- Work closely with the Penetration Testing Technical Lead to define testing scope, objectives and rules of engagement.
- Apply penetration testing methodologies across the full lifecycle, from pre-test definition through to reporting, remediation support and closure.
- Use tools and techniques for scanning, reconnaissance, exploitation and analysis, including awareness of tools such as Burp, Metasploit, Wireshark and Nmap.
- Assess vulnerabilities across Linux, Windows, networks, infrastructure and web applications, including common issues such as SQL injection and cross-site scripting.
- Document findings clearly and communicate security risks, impacts and remediation guidance to both technical and non-technical stakeholders.
- Maintain auditable records to support penetration test results, management information and remediation requirements.
- Contribute to the development of penetration testing practices, methods and quality measures across the Attack Surface Management function.
- Bring an external view of penetration testing threats, techniques and good practice to team discussions and management information.
- Support the wider Operational Resilience function through consultation, advice, challenge and independent review of activities and proposals.
- Help scope, arrange and deliver external penetration tests with our 3rd party provider, assessing and validating and findings and reporting these to business owners with SME guidance and advice.
What you will bring to the role:
- A credible penetration testing professional with strong knowledge and operational experience of penetration testing methodology.
- Experience assessing large, complex networks and infrastructure environments, ideally within an enterprise-scale organisation.
- Strong understanding of network protocols, architecture and security mechanisms.
- Practical experience across operating systems including Linux and Windows, with the ability to identify and exploit vulnerabilities across platforms.
- Knowledge of common web application vulnerabilities and how they can be identified, assessed and explained.
- Familiarity with cyber security and penetration testing tooling used for scanning, reconnaissance and exploitation.
- Ability to define penetration test scope, objectives and rules of engagement, preferably in a large company environment.
- Strong written and verbal communication skills, with the ability to document findings clearly and communicate security risks to both technical and non-technical audiences.
- Analytical and methodical approach to demanding technical and business challenges, with a high level of accuracy and focus.
- Positive, service-oriented mindset, with the ability to work collaboratively and represent Cyber professionally across the Group.
- Proactive approach to personal development, staying current with the latest threats, techniques and security measures.
- Qualifications such as OSCP, OSCE, CRT, GPEN, GXPN, CHECK Team Member or similar are beneficial.
- Experience working in financial services or another regulated industry would be beneficial.
If you feel you’d be a great fit for Royal London but don’t meet every requirement, we’d still love to hear from you. Research shows some candidates are less likely to apply unless they meet 100% of the criteria - if you meet most requirements and are keen to learn, we encourage you to apply!
About Royal London
We’re the UK’s largest mutual life, pensions and investment company, offering protection, long-term savings and asset management products and services.
Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve.
We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance.
Inclusion, diversity and belonging
We’re an inclusive employer. We celebrate and value different backgrounds and cultures across Royal London. Our diverse people and perspectives give us a range of skills which are recognised and respected – whatever their background.