Penetration Testing Program Governance & Vendor Strategy Manager

Reference: 9icwhjw61lqtq4yivbhb

We are seeking a Penetration Testing Program Governance & Vendor Strategy Manager to lead the governance, planning and continuous improvement of an enterprise-wide penetration testing programme. In this role, you will establish and maintain standards, policies, procedures and control frameworks that support effective testing across applications, infrastructure, cloud environments, networks and emerging technologies. You will oversee the annual testing roadmap, prioritising activity according to business risk, regulatory expectations, threat intelligence and changes to the technology estate.

You will manage relationships with external penetration testing providers, including supplier selection, due diligence, onboarding, contract management, performance reviews and service-level governance. Responsibilities will include developing statements of work, defining testing requirements, assessing proposals, monitoring delivery quality and ensuring findings are documented, risk-rated and remediated within agreed timeframes. You will partner with cybersecurity, technology, risk, compliance, procurement and business stakeholders to provide clear reporting on programme status, vulnerabilities, exceptions, remediation progress and residual risk. You will also support audits and regulatory reviews, maintain accurate management information and identify opportunities to improve efficiency, coverage and assurance.

The successful candidate will have significant experience in penetration testing, cybersecurity assurance, security governance, third-party risk or a related discipline, with a strong understanding of testing methodologies, vulnerability management and risk assessment. Experience managing specialist security vendors and complex programmes across multiple technology domains is essential. You should be confident interpreting technical reports, challenging results constructively and communicating security risk to both technical and senior non-technical audiences. Strong negotiation, organisation, stakeholder management and analytical skills are required, together with the ability to manage competing priorities in a changing environment. Relevant certifications such as OSCP, CREST, CISSP, CISM, CRISC or equivalent experience are desirable.

COMPETITIVE SALARY
Added 02/09/2026
Reference: 9icwhjw61lqtq4yivbhb

Penetration Testing Program Governance & Vendor Strategy Manager

London, England, United Kingdom Permanent Penetration Tester

Other similar jobs

Program Manager, Security Risk Program

Added 07/09/2026

We are seeking an experienced Program Manager, Security Risk Program to lead the development, delivery, and continuous improvement of security risk initiatives across a complex business environment. In this role, you will coordinate cross-functional programs that strengthen risk identification, assessment, treatment, monitoring, and reporting. You will work closely with information security, technology, compliance, legal, internal audit, and business stakeholders to ensure security risks are understood, prioritised, and managed in line with organisational objectives and applicable regulatory requirements. Your responsibilities will include establishing program plans, governance structures, delivery milestones, reporting routines, and success measures for security risk initiatives. You will maintain...

Learn more

Cyber Vendor Manager

Added 01/09/2026

We are seeking an experienced Cyber Vendor Manager to oversee the security, risk and performance management of third-party technology and service providers. In this role, you will help ensure that external partners meet contractual, regulatory and internal cybersecurity requirements throughout the supplier lifecycle. You will work closely with procurement, legal, technology, information security and business stakeholders to assess vendor risk, establish appropriate controls and support secure commercial relationships. Your responsibilities will include leading cybersecurity due diligence and risk assessments for new and existing suppliers; reviewing security questionnaires, audit reports, certifications and remediation plans; maintaining accurate records of vendor risks, controls,...

Learn more

Enablement Manager (Penetration Testing) - Leeds UK

Added 30/07/2026

We are seeking a proactive and knowledgeable Enablement Manager specializing in Penetration Testing to join our dynamic team in Leeds, UK. In this role, you will be responsible for developing and implementing comprehensive training programs to equip our cybersecurity professionals with the necessary skills and knowledge in penetration testing. You will collaborate closely with various teams to ensure that the latest tools, techniques, and methodologies are effectively integrated into training modules, fostering a culture of continuous learning and improvement. Your key responsibilities will include creating instructional materials, conducting workshops, and facilitating hands-on training sessions. You will also be tasked with...

Learn more

Security Testing Consultant (Penetration Tester) Hybrid

Added 15/09/2026

We are seeking a Security Testing Consultant (Penetration Tester) to join a collaborative cybersecurity team on a hybrid basis. In this role, you will plan and deliver penetration tests across web applications, APIs, mobile platforms, infrastructure, cloud environments and networks. You will assess security controls, identify vulnerabilities and determine the potential business impact of weaknesses using recognised testing methodologies and industry-standard tools. The position involves working with technical and non-technical stakeholders to understand environments, agree testing objectives and provide clear, practical advice to improve security resilience. Your responsibilities will include conducting manual and automated security assessments, validating findings, safely exploiting...

Learn more

Security Testing Consultant (Penetration Tester) Hybrid

Added 15/09/2026

We are seeking a Security Testing Consultant (Penetration Tester) to join a collaborative cyber security team in a hybrid working environment. In this role, you will plan and deliver authorised penetration tests across web applications, mobile applications, APIs, networks, cloud environments and infrastructure. You will work with technical and business stakeholders to understand testing objectives, identify attack paths, assess risk and provide practical recommendations that improve overall security resilience. Your responsibilities will include scoping engagements, developing test plans, conducting manual and automated security assessments, validating vulnerabilities and maintaining accurate evidence throughout each assignment. You will prepare clear, professional reports that...

Learn more

Penetration Testing Engineer- VP

Added 15/09/2026

We are seeking an experienced Penetration Testing Engineer at Vice President level to lead and deliver sophisticated security assessments across applications, infrastructure, cloud environments, networks, and emerging technologies. The successful candidate will combine strong technical expertise with strategic leadership, helping to identify and communicate security risks before they can be exploited. This role requires an individual who can operate independently, influence senior stakeholders, and contribute to the continued development of a high-performing offensive security function. Responsibilities will include planning and executing red team exercises, penetration tests, vulnerability assessments, and adversary simulation engagements. You will assess complex environments, develop attack paths,...

Learn more

Penetration Testing Lead

Added 09/09/2026

We are seeking an experienced Penetration Testing Lead to provide technical leadership across a broad programme of offensive security assessments. In this role, you will plan, manage and deliver penetration tests covering web applications, APIs, mobile platforms, networks, cloud environments, wireless infrastructure and security devices. You will define testing approaches, establish scope and rules of engagement, assess risk, and ensure that engagements are delivered to a consistently high standard. You will also review findings, validate remediation activity and communicate clear, practical recommendations to technical and non-technical stakeholders. You will lead and support a team of penetration testers, helping to allocate...

Learn more

Senior Penetration Testing Consultant

Added 09/09/2026

We are seeking a Senior Penetration Testing Consultant to deliver high-quality security assessments across a diverse range of technologies, applications, infrastructure, and cloud environments. In this role, you will plan and execute penetration tests, identify vulnerabilities, assess business impact, and provide clear, practical remediation guidance. You will work closely with clients and internal stakeholders to understand security objectives, agree testing scopes, manage expectations, and communicate findings effectively to both technical and non-technical audiences. Your responsibilities will include conducting web application, mobile application, API, network, wireless, cloud, and infrastructure penetration tests; performing vulnerability validation and exploit development where appropriate; producing detailed...

Learn more

Penetration Testing Lead

Added 01/09/2026

We are seeking an experienced Penetration Testing Lead to drive the delivery of high-quality offensive security assessments across applications, infrastructure, cloud environments, networks and emerging technologies. You will lead engagements from scoping and planning through to execution, reporting and remediation validation, ensuring that testing is technically rigorous, risk-focused and aligned with recognised industry standards. The role will involve working closely with security, engineering, technology and business stakeholders to identify meaningful vulnerabilities and translate technical findings into clear, actionable business risk. Key responsibilities include leading and mentoring penetration testers, allocating work, reviewing methodologies and ensuring consistent quality across all engagements. You...

Learn more

Penetration Testing Lead

Added 01/09/2026

We are seeking an experienced Penetration Testing Lead to oversee and deliver high-quality security assessments across applications, infrastructure, cloud environments, networks, and emerging technologies. You will lead engagements from scoping and planning through to testing, reporting, remediation support, and client or stakeholder presentations. The role requires a hands-on security professional who can combine strong technical capability with effective leadership, clear communication, and a consistent focus on business risk. Responsibilities will include defining testing methodologies and standards, reviewing rules of engagement, allocating resources, and providing technical guidance to penetration testers. You will perform and oversee manual and automated testing, validate vulnerabilities,...

Learn more

Senior Penetration Testing Consultant

Added 26/08/2026

We are seeking a Senior Penetration Testing Consultant to lead and deliver high-quality security assessments across complex technical environments. You will work with clients and internal stakeholders to identify vulnerabilities, assess business risk, and provide practical recommendations that strengthen security resilience. The role will involve planning and scoping engagements, defining testing methodologies, managing timelines, and presenting clear findings to both technical and non-technical audiences. Your responsibilities will include conducting penetration tests across web applications, APIs, mobile applications, networks, cloud platforms, wireless environments and infrastructure. You will perform reconnaissance, vulnerability analysis, exploitation and post-exploitation activities using a combination of commercial tools,...

Learn more

Cyber Security Consultant - Penetration Testing

Added 18/08/2026

Are you passionate about cyber security and eager to put your penetration testing skills to the test? An exciting opportunity awaits for a Cyber Security Consultant specializing in Penetration Testing. In this role, you will be responsible for conducting thorough security assessments, identifying vulnerabilities, and simulating real-world attacks on networks, applications, and infrastructure. You will collaborate closely with clients to understand their security landscapes, deliver detailed reports, and provide actionable recommendations to strengthen their defences. The ideal candidate will have hands-on experience in penetration testing, vulnerability assessment, and exploitation techniques. You should be proficient in using industry-standard tools such as...

Learn more

Security Program Manager, Exam and Audit

Added 18/09/2026

We are seeking a Security Program Manager, Exam and Audit to lead the planning, coordination, and continuous improvement of security assessment activities across the organisation. This role will manage examination and audit programmes, ensuring that internal controls, policies, procedures, and operational practices are prepared for review and aligned with applicable regulatory, contractual, and industry requirements. You will act as a central point of contact for auditors, examiners, control owners, and senior stakeholders, coordinating evidence collection, interview schedules, responses, and remediation tracking. Responsibilities include maintaining the security assessment calendar; defining programme milestones, deliverables, and dependencies; assessing audit readiness; and identifying risks...

Learn more

Senior Security Technical Program Manager

Added 26/08/2026

We are seeking a Senior Security Technical Program Manager to lead complex, cross-functional initiatives that strengthen security, privacy, resilience and risk management across a fast-paced technology environment. You will work closely with engineering, infrastructure, product, legal, compliance and business teams to define strategic priorities, translate security objectives into actionable programmes, and deliver measurable outcomes. This role requires strong technical understanding, excellent programme leadership and the ability to influence stakeholders at all levels. Responsibilities will include managing multiple security programmes from strategy and planning through execution, tracking dependencies, risks, milestones, budgets and benefits. You will establish governance frameworks, operating rhythms and...

Learn more

Senior Technical Program Manager (InfoSec), London

Added 26/08/2026

We are seeking a Senior Technical Program Manager to lead complex information security initiatives across a global technology environment in London. This role will be responsible for driving programmes that strengthen security capabilities, improve operational resilience and support the delivery of strategic risk and compliance objectives. You will work closely with engineering, infrastructure, privacy, legal, risk and business teams to establish clear priorities, coordinate delivery and ensure that security considerations are embedded throughout the organisation. You will define programme scope, objectives, milestones, dependencies and success measures, while managing delivery from planning through to implementation and review. Responsibilities will include maintaining...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.