
How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Contract Type: Permanent
Location: Alderley Park (Wilmslow) or Glasgow
Working Style: Hybrid - 50% from home / 50% office based
The Penetration Tester role, working within the Attack Surface Management function, plays a key role in helping Royal London identify, assess and address security vulnerabilities across computer systems, networks and applications. The role supports the delivery of penetration testing across the Group, helping to simulate real-world cyber attacks and strengthen Royal London’s defences against current and emerging threats.
You will work closely with the wider Cyber Testing team to scope, deliver and report on penetration tests, applying ethical hacking principles and responsible testing practices. You’ll use your knowledge of network protocols, infrastructure, operating systems, security tooling and common application vulnerabilities to provide clear, practical insight that helps technical and non-technical stakeholders understand and remediate risk.
More About the Role:
- Scope, deliver and report on penetration tests across Royal London’s systems, networks and applications.
- Simulate cyber attacks in a controlled and responsible way to identify vulnerabilities and help strengthen Royal London’s Attack Surface.
- Work closely with the Penetration Testing Technical Lead to define testing scope, objectives and rules of engagement.
- Apply penetration testing methodologies across the full lifecycle, from pre-test definition through to reporting, remediation support and closure.
- Use tools and techniques for scanning, reconnaissance, exploitation and analysis, including awareness of tools such as Burp, Metasploit, Wireshark and Nmap.
- Assess vulnerabilities across Linux, Windows, networks, infrastructure and web applications, including common issues such as SQL injection and cross-site scripting.
- Document findings clearly and communicate security risks, impacts and remediation guidance to both technical and non-technical stakeholders.
- Maintain auditable records to support penetration test results, management information and remediation requirements.
- Contribute to the development of penetration testing practices, methods and quality measures across the Attack Surface Management function.
- Bring an external view of penetration testing threats, techniques and good practice to team discussions and management information.
- Support the wider Operational Resilience function through consultation, advice, challenge and independent review of activities and proposals.
- Help scope, arrange and deliver external penetration tests with our 3rd party provider, assessing and validating and findings and reporting these to business owners with SME guidance and advice.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What You Will Bring to the Role:
- A credible penetration testing professional with strong knowledge and operational experience of penetration testing methodology.
- Experience assessing large, complex networks and infrastructure environments, ideally within an enterprise-scale organisation.
- Strong understanding of network protocols, architecture and security mechanisms.
- Practical experience across operating systems including Linux and Windows, with the ability to identify and exploit vulnerabilities across platforms.
- Knowledge of common web application vulnerabilities and how they can be identified, assessed and explained.
- Familiarity with cyber security and penetration testing tooling used for scanning, reconnaissance and exploitation.
- Ability to define penetration test scope, objectives and rules of engagement, preferably in a large company environment.
- Strong written and verbal communication skills, with the ability to document findings clearly and communicate security risks to both technical and non-technical audiences.
- Analytical and methodical approach to demanding technical and business challenges, with a high level of accuracy and focus.
- Positive, service-oriented mindset, with the ability to work collaboratively and represent Cyber professionally across the Group.
- Proactive approach to personal development, staying current with the latest threats, techniques and security measures.
- Qualifications such as OSCP, OSCE, CRT, GPEN, GXPN, CHECK Team Member or similar are beneficial.
- Experience working in financial services or another regulated industry would be beneficial.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
If you feel you’d be a great fit for Royal London but don’t meet every requirement, we’d still love to hear from you. Research shows some candidates are less likely to apply unless they meet 100% of the criteria - if you meet most requirements and are keen to learn, we encourage you to apply!
About Royal London
We’re the UK’s largest mutual life, pensions and investment company, offering protection, long-term savings and asset management products and services.
Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve.
We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance.
Inclusion, Diversity and Belonging
We’re an inclusive employer. We celebrate and value different backgrounds and cultures across Royal London. Our diverse people and perspectives give us a range of skills which are recognised and respected – whatever their background.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills