Security Testing Consultant (Penetration Tester) Hybrid

Company: BAE Systems
Apply for the Security Testing Consultant (Penetration Tester) Hybrid
Location: Frimley
Job Description:

Overview

In this role you will conduct security testing across web, infrastructure, cloud, and external surfaces to identify and remediate vulnerabilities. You will work with cross-functional teams within a threat intelligence and security consulting context to deliver high-quality assessments and actionable reports. The position offers exposure to government and critical infrastructure work, with opportunities to shape testing methodologies and tooling. A clear path to CHECK Team Member status and international travel add variety and growth potential.

Pay / Benefits

  • Hybrid working
  • Diversity and inclusion culture
  • Opportunity to work on government and critical infrastructure projects
  • Global collaboration across security functions
  • Potential for career progression and certifications
  • Flexible travel opportunities (UK and international)

Responsibilities

  • Deliver security testing engagements across web applications, infrastructure, cloud environments, and external attack surfaces
  • Conduct independent and complex assessments following methodologies and customer requirements
  • Identify, validate, and document vulnerabilities with remediation guidance and professional reporting
  • Utilise and apply security testing tools per standards and customer needs
  • Collaborate with Security Testing, Threat Intelligence, Incident Response, and Security Consulting teams to ensure quality outcomes
  • Contribute to internal tooling, automation, and research initiatives
  • Maintain awareness of emerging threats, vulnerabilities, and security technologies
  • Participate in technical training and certification to progress towards CHECK Team Member status

Key requirements

  • Experience in penetration testing, vulnerability assessment, or related security roles
  • Solid understanding of testing methodologies, tools, and techniques across web, infrastructure, cloud, API, and mobile security
  • Practical experience with Burp Suite, Nmap, Nessus, Metasploit, BloodHound or similar tools
  • Ability to clearly communicate technical findings in reports and discussions
  • Self-motivated with a focus on continuous development and progression toward CHECK status within 6 months
  • Willingness to travel within the UK and internationally
  • Clear written and verbal communication
  • Collaborative mindset and team-oriented
  • Self-motivated and proactive
  • Web Application Security
  • Infrastructure Security
  • Cloud Security

Posted: September 19th, 2026