← Back to Directory

Security Testing Consultant (Penetration Tester) Hybrid

Clearance Level
SC
Salary Range
Competitive
Employment Type
FULL TIME
Work Style
onsite

// Role Summary

Join BAE Systems Digital Intelligence as a Security Testing Consultant – Penetration Tester, investigating and tracking cyber-attacks globally and shaping a safer future. This role offers extensive travel opportunities across the UK, Europe, and Africa.

// Key Responsibilities

  • Perform comprehensive security testing across web applications, infrastructure, and cloud environments.
  • Identify, validate, and document vulnerabilities with practical remediation advice.
  • Utilise industry-standard security tools and contribute to developing internal methodologies.
  • Collaborate with diverse teams including Threat Intelligence and Incident Response.
  • Eligible and willing to obtain CHECK Team Member status within 6 months.
  • Requires flexibility for UK and international travel (approx. 25%).

// Role Specification

About the Role

BAE Systems Digital Intelligence is seeking experienced Security / Penetration Testers to join our cyber threat intelligence team. In this role, you will investigate and track cyber-attacks against organisations worldwide, playing a crucial part in building rich profiles of high-priority threat actor campaigns. You will provide our threat intelligence customers with technical data feeds and contextualised reports via a secure portal, making a tangible impact and helping to shape a safer future.

What You Will Be Doing

  • Support the delivery of security testing engagements across various domains, including web applications, infrastructure assessments, cloud environments, and external attack surfaces.
  • Conduct and deliver security assessments independently, and complex assessments under senior supervision, adhering to established methodologies and customer requirements.
  • Identify, validate, and document security vulnerabilities, offering accurate and practical remediation advice.
  • Produce clear and professional reports tailored for both technical and non-technical audiences.
  • Safely utilise security testing tools and techniques in line with company standards and customer requirements.
  • Collaborate with colleagues in Security Testing, Threat Intelligence, Incident Response, and Security Consulting to achieve high-quality client outcomes.
  • Contribute to the development of internal tooling, automation, testing methodologies, and research initiatives.
  • Maintain awareness of emerging threats, vulnerabilities, attack techniques, and security technologies.
  • Participate in technical training, mentoring, and certification programmes to support progression towards CHECK Team Member status.

Skills and Experience Required

  • Experience in penetration testing, vulnerability assessment, systems administration, software development, or a closely related technical security role.
  • Demonstrable understanding of common security testing methodologies, tools, and techniques across one or more of the following: Web Application Security, Infrastructure Security, Cloud Security, API Security, Mobile Security.
  • Strong understanding of common vulnerabilities and exploitation techniques (e.g., OWASP Top 10, network security fundamentals).
  • Ability to clearly communicate technical findings in both written reports and verbal discussions.
  • Practical experience with industry-standard security tools such as Burp Suite, Nmap, Nessus, Metasploit, BloodHound, or similar.
  • Self-motivated with a desire for continuous technical and consulting skill development.
  • Eligible and willing to obtain CHECK Team Member status within the first 6 months of employment.
  • Flexibility and willingness to travel within the UK and Internationally when required.

Desirable Requirements

  • Offensive security certifications such as Offensive Security Certified Professional, Practical Network Penetration Tester, CREST CPSA, CREST Registered Tester, Cyberscheme Team Member, eLearnSecurity Certified Professional Penetration Tester, CompTIA PenTest+.
  • Working Towards the Practitioner Level of the UK Professional Charter.
  • Experience participating in Capture The Flag (CTF) competitions, bug bounty programmes, or personal security research projects.
  • Current Security Clearance (SC) or ability to obtain clearance.

Life at BAE Systems Digital Intelligence

We embrace Hybrid Working, offering flexibility in when and where you work to help balance work and personal life. Diversity and inclusion are integral to our success, fostering a culture where varying perspectives and backgrounds contribute to excellence.

Division Overview: Government

As a leader in the cyber defence industry, BAE Systems Digital Intelligence has extensive experience in Government contracts. You will play a role in defending critical infrastructure and ensuring the protection of nations.