Penetration Tester
BAE Systems ·
- Employment
- Contract
- Category
- Security
- Experience
- 5+ years
Senior Penetration Testing Analyst on BAE Systems' internal Active Defence Red Team (Cyber Operations), conducting infrastructure and web application penetration tests, simulated attacks, and vulnerability assessments to protect BAE Systems, then producing graded reports for internal resolver groups. Requires Crest CRT or CSTM certification and tools like Burp Suite, Nmap, and Metasploit.
Job Title\: Senior Penetration Testing Analyst
Location\: Preston or Frimley
We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role
Grade\: GG10
You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.
We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.
If you don’t feel you can talk to your Line Manager, you can contact your HRBP.
PLEASE NOTE\: Should you be invited for interview, you will be giving consent for the Recruitment Team to contact you and your line manager regarding your application for this opportunity.
This vacancy is open to permanent and fixed-term BAE Systems employees only.
While agency workers have access to relevant permanent opportunities, this role has been designated as an internal opportunity and therefore only permanent and fixed-term employees of BAE Systems are eligible to apply.
Job Description\:
This role will sit under the Active Defence, Red Team who are responsible for delivering the following capabilities in support of Cyber Operations\: Red Teaming, Purple Teaming, Security Critical Control Testing, Threat Advisory Simulation and Penetration Testing.
Core duties\:
- Conducting both a combination of Infrastructure and Web Application Penetration testing across BAE System
- Develop comprehensive and accurate reports for internal audiences, ensuring the grading of vulnerabilities within the context of BAE Systems, and passing onto resolver groups for resolution
- Ensuring resolution is being conducted in line with documented process
- Conduct simulated attacks and vulnerability assessments to support Red and Purple Team operations, identifying security weaknesses and enhancing defensive capabilities
- Contributes to the development of Active Defence, Red Team capabilities through people, process, and technology where appropriate
- Maintains a broad understanding of the external threat environment and attacker tactics, techniques, and procedures
Essential Skills\:
- Demonstrable experience in penetration testing
- Proficient in penetration testing tools such as Burp Suite, Nmap, Metasploit etc
- Either Crest Certified Registered Tester (CRT) or Cyber Scheme Team Member (CSTM) qualifications
- The ability to clearly communication both verbally and written
The Cyber Operations Team
Cyber Operations is responsible for protecting BAE Systems from Cyber Attacks by various threat actors. Not only do we protect BAE systems and its employees, indirectly we protect those who protect us – who serve in our military and rely on the products and services we create. Across Threat Intelligence, Threat Detection, Incident Response and Active Defence we work to evolve cyber operations as a world class capability.
Why BAE Systems?
Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work, this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family, support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.
A place where everyone can thrive\:
We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.
We welcome applications from all suitably qualified people who are BAE Systems employees and have been in their current role for 12 months or longer.
Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.
Closing Date\: 23rd October 2026