Role Overview
As a Senior Penetration Tester, you will lead and deliver technical penetration testing that helps maintain the bank’s risk and security posture. You’ll work across web, infrastructure, networks, cloud, SaaS, mobile and emerging technologies including LLM-based applications, while partnering with stakeholders to identify security weaknesses, demonstrate business impact and support remediation.
About Group Security Engineering
Group Security Engineering is responsible for ensuring the Group embeds security into everything we deliver – from customer products and enterprise platforms to security engineering culture and innovation.
Key Responsibilities
- Lead penetration testing and security testing across web applications, infrastructure, networks, cloud, SaaS, mobile and LLM-based applications.
- Scope and plan testing engagements, including test approach, methodology and level of rigour.
- Develop testing plans and coordinate testers across a broad program of engagements using agile ways of working.
- Create exploitation strategies that demonstrate risk, business impact and remediation priorities.
- Communicate findings clearly to technical and non‑technical stakeholders, including suppliers, project owners and leadership.
- Mentor junior team members and contribute to the ongoing uplift of penetration testing practices, methodologies and innovation.
- Ensure testing activities align with internal policy and external regulatory requirements.
Desired Experience and Skills
- Demonstrated experience leading penetration testing across multiple domains such as applications, infrastructure, cloud and networks.
- Strong capability in vulnerability identification, exploitation techniques and penetration testing methodologies.
- Proven ability to communicate complex security issues clearly and confidently to a wide range of stakeholders.
- Experience developing testing approaches, planning engagements and driving outcomes across multiple concurrent activities.
- Experience mentoring others and contributing to a collaborative, inclusive team environment.
- Experience working in cloud environments, particularly AWS.
- Exposure to tools such as Kali Linux, Burp Suite, Metasploit and related security testing platforms.
- Relevant industry certifications such as OSCP, GXP, or similar are desirable.
- Experience using large language models to support penetration testing workflows is highly desirable.
- Tertiary qualifications in Software Engineering, Computer Science, Cyber Security or a related discipline are desirable.
We’re Interested In Hearing From People Who…
We know great candidates may not meet every requirement listed below. If you’re excited about this opportunity and believe your experience could add value, we’d love to hear from you.
Do Work That Matters
Bring your ambition and we’ll help you grow, belong and shape what’s next.
Grow. Belong. Shape What’s Next.
Within this environment, Group Security is part of Technology and brings together cyber security, protective security, business resilience, fraud technology and cyber defence capabilities. Its purpose is safeguarding a brighter future for all by securing the bank, protecting customers, building recovery capability and creating an admired place to work.
#J-18808-Ljbffr