Lead Penetration Tester

Morson Group · Not specified, United Kingdom

Lead Penetration Tester at Morson Group, based in Not specified, United Kingdom. This is a contract role.

Salary
Competitive
Location
Not specified, United Kingdom
Contract
Contract
Posted
6 hours ago
Closes
24 Sep 2026
Sector
QA Tester

Reference https://www.morson.com/jobs/it-and-digital/contract/united-kingdom/lead-penetrat

About the role

Lead Penetration Tester

Contract: Initial 6 months
Day Rate: £700–£800 per day
IR35: Inside IR35
1 day per month on site, either Chesterfield or London.

About the Role

We are looking for an experienced Lead Penetration Tester to take ownership of the end-to-end penetration testing process across applications, infrastructure and wider technology environments.

This is a hands-on role combining penetration testing expertise with the coordination and oversight of testing engagements, third-party suppliers, vulnerability remediation and security findings. You will be responsible for ensuring tests are appropriately scoped, executed to a high standard, and that resulting vulnerabilities are clearly documented, prioritised and driven through to resolution.

The role will involve working closely with internal engineering, DevOps, product and delivery teams, as well as third-party penetration testing providers and other stakeholders.

Key Responsibilities: 

  • Lead the end-to-end penetration testing lifecycle, including scoping, planning, execution, reporting and remediation across applications, infrastructure and systems.
  • Provide hands-on penetration testing expertise while coordinating and overseeing third-party testing providers.
  • Review and challenge penetration testing reports, assessing findings based on severity, exploitability, business impact and risk.
  • Work closely with engineering, DevOps, product and delivery teams to prioritise and drive vulnerabilities through to resolution within agreed SLAs.
  • Own the tracking and management of penetration testing findings in Jira, ensuring actions are assigned, monitored and closed.
  • Lead regular remediation discussions with internal stakeholders and third parties, escalating blockers and ensuring residual risks are appropriately recorded and accepted.
  • Ensure penetration testing and remediation activities align with relevant security standards, regulatory requirements and industry best practice, including OWASP, NIST, ISO 27001, PCI-DSS, GDPR and CAF.
  • Ensure appropriate governance, documentation and evidence is maintained throughout the testing lifecycle.
  • Provide assurance over the quality and effectiveness of third-party penetration testing engagements.
  • Identify and implement improvements to penetration testing, vulnerability management and remediation processes.
  • Use testing outcomes, lessons learned and emerging threats to improve security controls and testing methodologies.

Essential Experience

  • Significant experience in penetration testing / offensive security, with the ability to lead complex testing engagements.
  • Strong hands-on understanding of penetration testing across applications, infrastructure and technology environments.
  • Proven experience managing the full penetration testing lifecycle, including scoping, planning, execution, reporting and remediation.
  • Experience overseeing and managing third-party penetration testing suppliers.
  • Strong ability to review, interpret and challenge penetration testing reports and technical findings.
  • Proven experience managing vulnerabilities and security defects through to remediation.
  • Experience working closely with engineering, DevOps, product and delivery teams.
  • Strong stakeholder management skills, with the ability to translate technical vulnerabilities into clear business risks and required actions.
  • Experience using Jira or similar tooling to manage security findings and remediation activity.
  • Strong understanding of security risk assessment, vulnerability prioritisation and risk acceptance.
  • Knowledge of recognised penetration testing methodologies and security frameworks.

Desirable Experience

  • Relevant penetration testing/offensive security certifications such as CREST, OSCP, OSWE, GPEN or equivalent.
  • Experience operating within large, complex or highly regulated organisations.
  • Experience across cloud environments, particularly Azure and/or AWS.
  • Experience with application, API, network, infrastructure and/or cloud penetration testing.
  • Familiarity with vulnerability management and security operations processes.
  • Experience working within environments subject to ISO 27001, PCI-DSS, GDPR or CAF requirements.

What We’re Looking For

The successful candidate will be someone who can combine strong technical penetration testing knowledge with excellent delivery and stakeholder management skills.

You will be comfortable getting into the technical detail of penetration testing findings, while also taking ownership of the wider process, coordinating suppliers, challenging reports, managing Jira defects, engaging with delivery teams and ensuring vulnerabilities are driven through to closure.

This is particularly suited to a senior/lead-level penetration tester who wants ownership of the testing and remediation lifecycle, rather than someone focused solely on executing individual tests.

Reference: https://www.morson.com/jobs/it-and-digital/contract/united-kingdom/lead-penetrat · Posted 6 hours ago · Closes 24 Sep 2026 · Listed via Morson Group

Know someone who'd be great for this? Get a shareable card

Apply for this job

This role is listed via Morson Group. Applications are handled on the employer's site.

Apply on employer site

Opens the employer's website in a new tab.

Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.

Report this job
Salary Competitive
Apply now