National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Lead Penetration Tester

SITA
Reading
1 month ago
Create job alert

Overview

WELCOME TO SITA

We're the team that keeps airports moving, airlines flying smoothly, and borders open. Our tech and communication innovations are the secret behind the success of the world's air travel industry.

You'll find us at 95% of international hubs. We partner closely with over 2,500 transportation and government clients, each with their own unique needs and challenges. Our goal is to find fresh solutions and cutting-edge tech to make their operations run like clockwork. Want to be a part of something big?

Are you ready to love your job? The adventure begins right here, with you, at SITA.

PURPOSE

As a Lead Penetration Tester, part of the SITA Enterprise Information Security Office, you will assess SITA infrastructure and products to identify information security weaknesses and provide remediation strategies. You will also contribute to the automation of security testing as part of the product development lifecycle.

KEY RESPONSIBILITIES

Conduct authorized assessment of infrastructure and applications to proactively identify security weaknesses. Verify weaknesses by leveraging attacker techniques to evaluate the difficulty and effectiveness of potential attack from various threat actors. Provide comprehensive and actionable recommendations to counter the threat posed by identified security weaknesses, given the applicable threat landscape. Bring an offensive mindset to the design of internal solutions and provide input to the selection of countermeasures and security controls through technical risk assessment. Report findings to technical audiences (e.g.: product development teams, IT, operations), and to business management and leadership, indicating the impact to the business of verified weaknesses found. Research and develop testing tools, techniques and processes. Assist incident response and security threat surveillance functions to advise on current attacker tools, techniques and procedures. Contribute to the continuous improvement of security processes, tools and techniques to counter threats faced by SITA and our customers.  Contribute to the automation of security activities as part of the DevOps lifecycle.  Provide guidance on secure product design: Threat Modelling, architecture reviews.

Qualifications

EXPERIENCE

5-7 years' experience in at least three of the following fields:

Network penetration testing Web and mobile application assessments Cloud penetration testing (Azure, AWS,) Mastery of Unix/Linux/Windows operating systems, including bash and PowerShell, shell scripting or automation of simple tasks using Python, Ruby or Perl  Developing security test automation as part of a DevOps CI/CD pipeline

KNOWLEDGE & SKILLS

Excellent ability to think laterally and solve problems in unique ways Ability to relate work to the business, understanding the impact to business processes, not just technical impact Strong knowledge of attacker tools, techniques and procedures Strong understanding of network technologies such as TCP/IP, routing, switching, NAT, Wireless/WiFi, etc. Strong ability to research and maintain currency with the latest approaches to penetration testing, including learning new tools and technologies Good understanding of security compliance frameworks (e.g. ISO/IEC 27001, PCI DSS, etc.) Good understanding of common business applications (e.g. content management systems, application servers, databases, etc.) and how to leverage them in an assessment Good understanding of web technologies and how they are commonly subverted (e.g. OWASP Top 10) At least a basic understanding of development frameworks (.NET, Java,) Ability to remain calm and methodical under pressure

PROFESSION COMPETENCIES

Adversarial Thinking Cloud Security Assessment Exploitation Techniques Vulnerability Analysis Security pen-testing tool mastery Threat Modeling Network & Active Directory Security Testing Application Security Testing Privilege Escalation Post-Exploitation Techniques Red Team Operations Security Standards & Compliance Incident Simulation & Reporting Scripting & Automation Risk-Based Assessment Security Advisory Research & Innovation Technical Writing & Documentation

CORE COMPETENCIES

Collaboration & Teamwork Ethics & Professional Integrity Analytical & Critical Thinking Communication Creativity & Innovation Resilience & Adaptability Results-Oriented Execution Stakeholder Influence

EDUCATION & QUALIFICATIONS

Masters degree in a technical discipline such as Information Security, Computer Science, Engineering, Telecommunications, Mathematics, Physics, or enough work experience to demonstrate proficiency at this level Penetration Testing certification (e.g. OSCP, GPEN) is considered a strong advantage Professional security certification (e.g. CISSP, CISA) is a plus

WHAT WE OFFER

We're all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We're really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

Flex Week:Work from home up to 2 days/week (depending on your team's needs)

Flex Day:Make your workday suit your life and plans.

Flex-Location:Take up to 30 days a year to work from any location in the world.

Employee Wellbeing:We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs.

Professional Development:Level up your skills with our training platforms, including LinkedIn Learning!

Competitive Benefits:Competitive benefits that make sense with both your local market and employment status.

SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.

Related Jobs

View all jobs

Lead Penetration Tester

Penetration Tester

Penetration Tester

Penetration Tester

Penetration Tester

Penetration Tester

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.

How to Find Hidden Cyber Security Jobs in the UK Using Professional Bodies like BCS, CIISec & More

The demand for skilled cyber security professionals in the UK has never been higher. With threats increasing in sophistication and frequency, organisations are urgently hiring ethical hackers, threat analysts, GRC specialists, and security architects. But many of the most valuable roles—particularly in government, defence, and critical infrastructure—are never publicly advertised. Instead, these jobs are shared behind the scenes through trusted networks, private communities, and professional bodies. In this article, we explore how to uncover hidden cyber security jobs in the UK using organisations like the BCS (The Chartered Institute for IT), CIISec (The Chartered Institute of Information Security), ISACA, and ISC² UK Chapter. We’ll show you how to use membership directories, special interest groups, CPD events and informal networks to gain early access to roles most people never see.

How to Get a Better Cyber Security Job After a Lay-Off or Redundancy

Redundancy is never easy—especially in a fast-moving field like cyber security, where your skills and experience are constantly evolving. But if you’ve recently been made redundant from a cyber security role, know this: the UK cyber workforce remains in high demand, and your expertise is more valuable than ever. Whether you’re a SOC analyst, penetration tester, incident responder, security architect or GRC specialist, there are still thousands of opportunities across sectors including finance, defence, government, retail, and critical infrastructure. This guide will help you turn redundancy into a career relaunch, with a clear action plan tailored to the UK cyber security job market.