Lead Pentester
Quick Summary
Deliver Penetration Testing Engagements Lead and deliver infrastructure, web application, API, cloud,
Leonardo is seeking an experienced CHECK Team Leader (CTL) to join our growing Offensive Security capability.
Working within a defence-focused environment, you will lead and deliver penetration testing activities across enterprise IT, cloud, applications, and operational technology environments, supporting customers operating within complex and high-assurance systems.
As one of Leonardo's senior penetration testing specialists, you will be responsible for planning, scoping, delivering, quality assuring, and reporting on penetration testing engagements in accordance with NCSC CHECK standards and industry best practice. You will work directly with customers to identify and validate security risks, provide practical remediation advice, and help strengthen the resilience of critical systems that support UK national security.
This role offers the opportunity to be more than a delivery consultant. Alongside technical engagements, you will contribute to the development of Leonardo's offensive security capability, supporting service development, mentoring junior consultants, improving testing methodologies, and helping shape future service offerings.
You will work closely with cyber security specialists across Leonardo, combining hands-on technical delivery with stakeholder engagement, capability development and continuous improvement activities. We are looking for someone who enjoys solving complex technical challenges, maintaining high professional standards and helping develop the next generation of penetration testing talent.
Responsibilities
~2 min read- →Deliver Penetration Testing Engagements
Lead and deliver infrastructure, web application, API, cloud, wireless and operational technology penetration testing activities across defence and government environments. Assess the effectiveness of security controls and provide actionable recommendations that improve customer security posture.
- →Engagement Planning and Scoping
Work with customers and project teams to define scope, objectives, constraints and rules of engagement. Ensure testing activities are appropriately planned, authorised and delivered in line with NCSC CHECK requirements.
- →Technical Leadership and Quality Assurance
Provide technical leadership during engagements and act as a subject matter expert for penetration testing activities. Review testing outputs and reports to ensure quality, accuracy and consistency.
- →Reporting and Risk Communication
Produce high-quality technical and executive reports, translating complex technical findings into clear business risks and practical remediation advice suitable for both technical and non-technical stakeholders.
- →Capability Development
Support the ongoing development of Leonardo's offensive security services, contributing to methodologies, tooling, testing standards and service offerings.
- →Mentoring and Knowledge Sharing
Support the development of junior consultants and CHECK Team Members (CTMs) through coaching, peer review, technical guidance and knowledge sharing activities.
- →Research and Innovation
Maintain awareness of emerging threats, attack techniques, vulnerabilities and testing approaches. Apply new knowledge and techniques to improve customer outcomes and service delivery.
- →Customer and Stakeholder Engagement
Build trusted relationships with customers, project teams and security stakeholders throughout the engagement lifecycle, from initial planning through to final reporting and remediation discussions.
- →Core Consulting Skills
Building client relationships; adaptability to changing schedules; reliability and quality of delivery; flexibility in working arrangements; collaboration and teamwork.
- Professional Development. Access to industry-recognised training, conferences and certification support, including advanced CREST, OffSec and specialist technical development pathways.
- Technical Growth. Opportunities to work across diverse penetration testing assignments spanning Defence, Government, Critical National Infrastructure and emerging technologies.
- Capability Development. Contribute to the growth of Leonardo's Offensive Security capability, influencing future service offerings, methodologies and technical standards.
- Research and Innovation Time. Dedicated opportunities to explore emerging attack techniques, tooling, cloud security, automation and offensive security research.
We are looking for a motivated and self-driven security professional with a passion for offensive security and a strong commitment to technical excellence. This role would suit an experienced pentester looking to lead engagements and support the growth of a mature offensive security function.
Requirements
~1 min read- Current CREST CHECK Team Leader (CTL) qualification.
- Experience delivering penetration testing engagements across one or more of:
- Infrastructure
- Web Applications
- APIs
- Cloud Platforms
- Wireless Networks
- Operational Technology
- Excellent technical report writing skills for both technical and executive audiences.
- Strong stakeholder engagement and client-facing consulting skills.
- Experience planning, leading and assuring penetration testing engagements.
- Good understanding of common security frameworks and standards.
- Ability to identify and communicate security risks and remediation actions effectively.
- Experience using scripting or automation languages such as Python, PowerShell, Bash or similar.
- Strong analytical and problem-solving capability.
- Willingness to travel to customer locations when required.
- Ability to attain SC clearance and potentially higher levels of National Security Vetting.
- Existing SC or DV clearance.
- Experience operating within Defence, MOD or National Security environments.
- CREST CCT qualifications.
- CCT, OSCP, OSEP, OSWE, CRTO or equivalent certifications.
- Experience with cloud security testing (AWS, Azure, GCP).
- Experience with OT/ICS security testing.
- Experience developing tools, automation or testing frameworks.
- Experience mentoring junior penetration testers and conducting quality assurance reviews.
- Knowledge of NCSC CAF, NIST, ISO 27001 and MITRE ATT&CK.
This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn.
This role is subject to pre-employment screening in line with the UK Government’s Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: https://careers.uk.leonardo.com/gb/en/security-and-vetting
What We Offer
~2 min readAt Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work–life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we’re here to help you thrive.
Location & Eligibility
Listing Details
- Posted
- October 3, 2026
- First seen
- October 3, 2026
- Last seen
- October 3, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 51%
- Scored at
- October 3, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.