Penetration Testing Program Governance & Vendor Strategy Manager
We are seeking a Penetration Testing Program Governance & Vendor Strategy Manager to lead the governance, planning and continuous improvement of an enterprise-wide penetration testing programme. In this role, you will establish and maintain standards, policies, procedures and control frameworks that support effective testing across applications, infrastructure, cloud environments, networks and emerging technologies. You will oversee the annual testing roadmap, prioritising activity according to business risk, regulatory expectations, threat intelligence and changes to the technology estate.
You will manage relationships with external penetration testing providers, including supplier selection, due diligence, onboarding, contract management, performance reviews and service-level governance. Responsibilities will include developing statements of work, defining testing requirements, assessing proposals, monitoring delivery quality and ensuring findings are documented, risk-rated and remediated within agreed timeframes. You will partner with cybersecurity, technology, risk, compliance, procurement and business stakeholders to provide clear reporting on programme status, vulnerabilities, exceptions, remediation progress and residual risk. You will also support audits and regulatory reviews, maintain accurate management information and identify opportunities to improve efficiency, coverage and assurance.
The successful candidate will have significant experience in penetration testing, cybersecurity assurance, security governance, third-party risk or a related discipline, with a strong understanding of testing methodologies, vulnerability management and risk assessment. Experience managing specialist security vendors and complex programmes across multiple technology domains is essential. You should be confident interpreting technical reports, challenging results constructively and communicating security risk to both technical and senior non-technical audiences. Strong negotiation, organisation, stakeholder management and analytical skills are required, together with the ability to manage competing priorities in a changing environment. Relevant certifications such as OSCP, CREST, CISSP, CISM, CRISC or equivalent experience are desirable.
Penetration Testing Program Governance & Vendor Strategy Manager
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...