Back to search

Lead Ethical Hacking Penetration Tester (57,515 - 82,430)

Civil Service

Job Description

Job summary

Can you Lead and deliver complex penetration testing and ethical hacking activities across a large and diverse IT estate?

Do you thrive in a fast-paced environment where your expertise helps protect critical public services?

Have you led penetration testing, vulnerability management or IT health checking programmes?

If so, wed love to hear from you!

Join our Ethical Hacking Services team and play a pivotal role in protecting critical digital services. You'll provide expert cyber security assurance, lead penetration testing and vulnerability management activities, and help ensure our systems remain resilient against current and emerging threats. You'll also have the opportunity to influence security strategy, develop talent and contribute to cyber security best practice across government.

Joining our department comes with many benefits, including:

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays and a privilege day for the Kings birthday
  • Flexible working options where we encourage a great work-life balance.

Read more in the Benefits section below!

Find out more about what it's like working at DVLA - Driver and Vehicle Licensing Agency Civil Service Careers.

Job description

As the Lead Ethical Hacking Penetration Tester, you will be the senior technical specialist responsible for leading penetration testing and vulnerability management activities across a diverse technology landscape. You will help shape security testing strategy, identify and assess risks, and ensure effective remediation of vulnerabilities.

Your responsibilities will include, but arent limited to:

  1. Lead and act as a subject matter expert for penetration testing, ethical hacking and vulnerability management services.
  2. Design, deliver and oversee programmes of penetration testing, vulnerability assessments and IT health checks across applications, infrastructure and networks.
  3. Identify, analyse and assess vulnerabilities, ensuring risks are prioritised using a risk-based approach.
  4. Provide clear reporting and recommendations to support remediation and security improvement activities.
  5. Monitor emerging threats, attack techniques and vulnerabilities, adapting testing approaches where required.
  6. Build effective relationships with suppliers, stakeholders and delivery teams to ensure security objectives are achieved.
  7. Lead, mentor and develop team members, supporting performance, capability development and succession planning.
  8. Ensure all work complies with relevant security standards, government policies, legislation and organisational requirements.

Great line management is important to us as an organisation, and we will equip and support line managers to develop the skills they need. We aim to empower line managers to create teams where people can flourish and deliver excellent outcomes for the public.

For further information on the role, please read the attached role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.

Person specification

Required Experience

To be successful in this role you will need to have the following experience:

  • Leading penetration testing and ethical hacking activities within complex enterprise environments.
  • Designing and delivering vulnerability management and security testing programmes.
  • Assessing and communicating cyber security risks to both technical and non-technical audiences.
  • Influencing senior stakeholders and driving remediation activity.
  • Leading, coaching and developing teams.
  • Working with security standards, frameworks and industry best practice
  • Expert knowledge of penetration testing methodologies and tools.
  • Strong understanding of vulnerability management and cyber security operations.
  • Knowledge of threat intelligence, threat assessment and threat mitigation techniques.
  • Strong understanding of security technologies, networks, infrastructure and application security.
  • Ability to diagnose security weaknesses and recommend practical solutions.
  • Understanding of legal, regulatory and compliance requirements relating to cyber security

Additional Information

The role is part of the Government Security Profession Career Frameworkand utilises an enhanced CapabilityBased Pay Framework which provides access to a Digital and Data allowance.

The base pay is 57,515. In addition to this the role includes a Digital and Data allowance of up to 24,915.

The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.

Working for the DVLA Digital Team

At DVLA, licensing is just the start. Every project you implement, touch and deliver has a ripple effect thatll wash across the nation. Here the work youre doing has the capacity to change the way 53 million people interact with our services. As we aim to keep our roads some of the safest in the world, our innovative, transformative digital-led services help optimise a nation of individuals and business every single day.

To see how our people are transforming our digital services, head over to our DVLA Digital Services Blog and, to understand more about the great opportunities and benefits of working at DVLA read our Inside DVLA blog.

Working hours, office attendance and travel requirements

Full time roles consist of 37 hours per week. Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 35 hours per week.

This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.

The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (the location cited in the advert) or, when required for business reasons, in another office/work location. There may be occasions where you are required to attend above the minimum expectation.

If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).

Security Check

Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check. To allow for meaningful checks to be carried out, candidates will be required to have at least 5 years continuous residency in the UK. All applicants for this role must ensure that they meet this minimum residency requirement - if you do not, your application will be withdrawn.

Visa Sponsorship

Please note that we do not hold a UK Visa & Immigration (UKVI) Skilled Worker Licence sponsor and are unable to sponsor any individuals for Skilled Worker Sponsorship. Candidates must ensure they have the appropriate rights to work in the UK before application.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application