Cybersecurity Penetration Tester role at Thales safeguarding UK Defence systems through advanced penetration testing. Working at the forefront of national security with red teaming on military platforms.
Responsibilities
Safeguard UK Defence systems through advanced penetration testing and red teaming on critical military platforms
Tackle complex threat simulations and exploit development across IT, OT, cloud, and embedded environments
Use cutting‑edge tools with funded training and certifications (CHECK, CREST, OSCP, GIAC)
Lead end‑to‑end penetration testing across networks, applications, cloud infrastructures, and embedded systems - delivering actionable insights that strengthen mission‑critical environments
Drive advanced vulnerability assessments and exploit development, executing post‑exploitation activities within authorised scopes to uncover hidden risks and resilience gaps
Orchestrate red and purple team engagements, simulating sophisticated threat scenarios against defence systems to rigorously test and enhance security posture
Produce high‑impact technical reports and executive briefings, translating complex findings into clear risk narratives, business impact assessments, and prioritised remediation strategies
Partner with defensive operations and risk management teams to sharpen detection, accelerate response, and embed proactive resilience across the enterprise
Stay ahead of adversaries by maintaining expert knowledge of tactics, techniques, and procedures (TTPs) employed by state and non‑state actors in the defence sector
Champion compliance and assurance by aligning practices with MOD, NCSC, and international standards (JSP 440, ISO 27001, NIST, CHECK, CREST), ensuring robust governance and trust
Requirements
Degree in Computing, Cybersecurity, or a related field - or equivalent professional experience in lieu of formal tertiary studies
CHECK Team Leader accreditation currently held
Demonstrated track record as a Penetration Tester, Red Team Operator, or equivalent offensive security specialist
Proven ability to manage small technical teams, demonstrating strong people skills, mentorship, and collaborative leadership
Deep expertise in network protocols, application security, operating systems, and cloud platforms across both IT and OT environments
Hands-on proficiency with industry-standard tools including Burp Suite, Metasploit, Cobalt Strike, Nmap, Nessus, plus custom scripting in Python, PowerShell, and Bash
Proven experience conducting penetration tests across diverse systems: Windows, Linux, Android, iOS, Web Applications, and Cloud infrastructures
Familiarity with defence and government environments, including secure handling of classified information
Exceptional written and verbal communication skills, able to translate complex technical findings into clear, actionable insights
SC or DV clearance (mandatory for project delivery), with eligibility or current holding
Benefits
Annual bonus (VCP)
Pension – match like-for-like up to 7% of annual base salary
Life Assurance – 2 x base salary minimum (8 x salary if part of the pension scheme)
Income Protection – 50% of salary less state benefits for 5 years
Annual Leave – 201 hours, bank holidays, plus 1 company day
Private Medical Insurance - Couples cover
Half day every Friday, usually finishing around 1:00pm
24/7 Employee Assistance Programme
24 hours paid leave for volunteering activities
Access to flexible benefits and discounts – dental insurance, buying & selling annual leave, cycle to work, and many more
Compliance Quality Assurance Manager ensuring compliance risk management at TD Bank. Leading independent reviews and providing strategic guidance for compliance structures and processes.
QA Engineer specializing in test automation handling functional and non - functional tests. Seeking a detail - oriented individual with experience in SQL and automated testing tools for a hybrid role in Santo Domingo.
Automation QA Engineer at Pwrteams maintaining tests and creating automation frameworks for diverse IT projects. Join our diverse team providing IT solutions for global customers.
Quality Assurance Technician responsible for testing and compliance in medical device manufacturing. Ensuring product standards and collaborating across departments at Terumo Medical Corporation.
Senior Engineer QA ensuring quality for consumer - facing software applications at Dolby. Collaborating with cross - functional teams to drive quality outcomes through automation and validation.
Penetration Tester in AI cybersecurity firm Darktrace, focusing on identifying and mitigating security risks. Conducting penetration tests and collaborating with teams to enhance digital resilience.
Quality Assurance Engineer testing embedded control systems at Normet in Finland. Planning and executing software test cases and developing automated tests using Python and Robot Framework.
Staff Quality Engineer overseeing TRB and Global Change Control processes at Johnson & Johnson. Leading continuous improvement in quality systems within the medical device sector.
Senior Software Quality Engineer responsible for designing and maintaining test automation frameworks and CI/CD pipelines for the R&D department. Collaborating with teams in an agile environment to ensure product quality.
Instruments Quality Engineer ensuring quality for diagnostic instruments at Grifols. Participating in quality assurance activities and collaborating with production and quality control teams.