Penetration Tester
As a Penetration Testing Engineer, you will be conducting security assessments, working within our wider offensive security team, playing a key role in identifying and advising on technical findings across Nationwide’s estate.
You will be joining a growing team of dedicated and like-minded individuals where you will be expected to work independently and proactively to ensure that penetration tests are completed successfully, and the findings are understood by key stakeholders.
You will have demonstrable experience in delivering penetration tests from scoping through to reporting and post-test triage activity. You will be able to perform tests across a wide range of system and software stacks.
Communication skills are vital for the role. You must be comfortable explaining the risks of identified findings to technical and non-technical stakeholders.
We are happy to consider flexible working approaches to help you perform at your best.
At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected.
For this role, you'll be based at your nearest regional office or hub. We value time spent together to connect with colleagues for collaboration so there will be a regular requirement to attend our London site approximately once per quarter. If you are based at an office location, you'll be expected to meet our hybrid working requirement of at least two days a week, or 40% of your working time if part-time, in the office. If your application is successful, your hiring manager will provide further details on how this works.
If we receive a high volume of relevant applications, we may close the advert earlier than the advertised date, so please apply as soon as you can.
What you’ll be doing
The Penetration Test team are united by a single, shared purpose and it’s all about identifying vulnerabilities in systems and technology, to help protect our members. To support this, we are looking for an energetic and experienced security professional with a proven track record of penetration testing, stakeholder management, organisational skills, and prioritising work in high-pressure/high-tempo conditions.
As a Security Engineer (Penetration Tester), you’ll play a hugely important role in our team. Your core responsibilities will be to perform penetration tests of new and existing systems and in doing so you’ll support the business to meet Strategic, Operational and external Compliance objectives.
You will have the freedom to help shape and continuously improve our processes and tooling, and you will be encouraged to obtain and maintain technical certifications to support your personal and professional career goals.
About you
As a minimum requirement, you’ll have:
Hands-on experience delivering penetration tests against complex, business-critical systems, including web application and API testing. Experience in purple or red team testing would also be advantageous to help support the delivery of our wider offensive security objectives
Detailed knowledge of penetration testing tools, techniques and methodologies, with demonstrable understanding of security vulnerabilities and risk reduction approaches
Experience testing cloud services, API-based technologies and modern application architectures, with awareness of common security standards and compliance frameworks such as OWASP, CIS and PCI-DSS
Hold an industry recognised qualification such as the CREST CRT, OSCP, CSTM or equivalent, supported by competence in scripting and/or high-level programming languages such as Python, Shell, C#, Java or JavaScript
Resilient, highly motivated self-starter able to work independently or as part of a close-knit team, building relationships with stakeholders at all levels to support a built-for-security culture
Experience in an equivalent role within a large financial services provider or (organisations within a regulated industry) within the last three years, with a proven ability to produce timely penetration testing reports for both technical and non-technical audiences
Our customer first behaviours put customers and members at the heart of how we work together. They are the set of behaviours that every colleague needs to display, in every role:
Feel what customers feel - We step into our customers’ shoes, using their feedback and insights to empathise with them and to understand their needs, so that every decision we make starts and finishes with our customers in mind
Say it straight - We are brave in speaking out and saying what we think – we’re honest and direct with good intent, openly sharing diverse perspectives to reach the best conclusions and using language everyone can understand
Push for better - We don’t settle for mediocrity, we challenge the status quo, taking responsibility for continuous improvement and personal development
Get it done - We prioritise what will have the greatest impact, we are decisive, and we take accountability for delivering brilliant customer outcomes
You can strengthen your application by showing how our customer first behaviours resonate with you, and where you may have already demonstrated these.
The extras you’ll get
There are all sorts of employee benefits available at Nationwide, including:
25 days holiday, pro rata
Private medical insurance
A highly competitive pension to help you build a strong foundation for retirement
Access to an annual performance-related bonus
Training and development to help you progress your career
A great selection of additional benefits through our salary sacrifice scheme
Life assurance to provide peace of mind for you and your loved ones in the event of your death
Wellhub – access to a range of free and paid options for health and wellness
Up to 2 days of paid volunteering a year
Banking – but fairer, more rewarding, and for the good of society
We forge our own path at Nationwide.
As a mutual, we’re owned by our members - those customers who bank, save or have a mortgage with us. We challenge the financial sector status quo. We don’t see customers as the engine of our own profit. We share our profits with them and put their needs first. Always there when they need us. Supporting them and their lives.
If you’re inspired by fairer finances, passionate about making a meaningful impact, and truly care about our customers, you’re one of us.
At Nationwide, you are challenged to grow and rewarded for doing so. Valued. Recognised. Inspired to be your best. As a community, we want our working lives to count. As a team, we celebrate what we achieve. As a standard-setter, we work for the good of customers, communities, and broader society.
We are purpose-driven. Uncompromisingly customer. Unstoppably Nationwide.
What to do next
If this role is for you, please click the ‘Apply Now’ button. You’ll need to attach your up-to-date CV and answer a few quick questions for us.
We respond to everyone, so we will be in contact shortly after the closing date to let you know the outcome of your application.
Keeping your data and personal information confidential is important to us. To find out more about how we use and process your data, please read our Privacy policy.
If you want to find out more about using AI in our recruitment process, please read more here.
Disability Confident
We’re not just guided by data, we’re driven by the real experiences of our people. We’re a Disability Confident Level 3 Leader, the highest level.
That’s why we’re constantly evolving our policies and practices to make sure everyone feels genuinely supported, valued, and empowered to champion inclusion. Whatever your needs, we’re here to support you. If you need any additional support throughout your application journey, email our team at Recruitment Support.
Apply safely with Nationwide
Recruitment scams can look convincing, so take a moment to check the role is listed on our official careers site and read our guidance on Don’t be conned by a job scam.