About the Role
We are seeking an experienced CTL/CTM Penetration Tester to join a large Public Sector client delivering high-assurance security testing.
This role offers the opportunity to work on complex infrastructure, cloud, containerised, and enterprise environments, helping clients identify vulnerabilities and strengthen their security posture. You will be responsible for leading and delivering penetration testing engagements while providing expert guidance, coaching, and technical leadership to colleagues and clients.
Essential Requirements/Certifications
- Crest Certified Simulated Attack Team Leader (CSTL) or Crest Certified Simulated Attack Manager (CSTM) - Essential
- Relevant NCSC-recognised qualifications and experience
- Security Cleared
Experience
- Demonstrable experience conducting penetration testing and security assessments within:
- Public Sector organisations
- Critical National Infrastructure (CNI)
- Large enterprise environments
- Experience delivering advanced penetration testing engagements
- Strong understanding of current attack techniques, threat actors, and defensive controls
Technical Skills
- Manual penetration testing across:
- Internal and external infrastructure
- Web applications
- Networks and operating systems
- Cloud security testing:
- Microsoft Azure
- Amazon Web Services (AWS)
- On-premises infrastructure security assessments
- Container and orchestration platform security:
- Docker
- Kubernetes
- Identity and Access Management (IAM) security
- CI/CD pipeline security assessments
- Cloud-native and hybrid environment testing
- Security architecture and security control reviews
Key Responsibilities
- Lead and perform penetration testing engagements across infrastructure, applications, cloud services, and containerised environments.
- Deliver detailed technical reports and executive-level findings.
- Conduct security assessments of Azure, AWS, Kubernetes, IAM, and CI/CD environments.
- Work directly with stakeholders to communicate complex technical risks clearly and effectively.
- Provide mentorship, coaching, and skills development to junior penetration testers.
- Support the continuous improvement of testing methodologies, tooling, and service offerings.
- Contribute to client workshops, security awareness sessions, and technical training activities.