Pentesting Operations Lead
- Hiring from
- United Kingdom
- Work type
- Remote
- Posted
Show job descriptionHide job description
Atos is the Atos Group brand dedicated to AI-powered, secure, end-to-end digital services. Atos designs, develops, and operates critical digital environments that drive performance, resilience and sovereignty, helping public and private organizations worldwide retain control over their data and infrastructures, while meeting regulatory requirements.
With more than 52,000 employees serving over 4,500 clients across 54 countries, Atos helps modernize core IT systems, accelerate cloud and data transformation, strengthen cybersecurity, and deliver secure digital workplace environments to support its clients, its employees and society. Atos also provides consulting and advisory services through its Atos Amplify brand.
A trusted partner in operating complex and mission-critical environments, Atos supports organizations across highly regulated and sovereign contexts.
About Atos Group
Atos Group is a global leader in digital transformation with c. 54,000 employees and annual revenue of c. €7.2 billion, operating in 54 countries under two brands - Atos for services and Eviden for products and systems. European number one in cybersecurity and a leader in cloud, Atos Group is committed to a secure and decarbonized future and provides tailored AI-powered, end-to-end solutions for all industries. Atos Group is listed on Euronext Paris.
Who we are
We are a team of passionate experts with a clear ambition: applying digital technology to advance what matters for our clients and society. Together, we create reliable and responsive digital foundations for the world’s businesses, institutions and communities.
Our Cyber Advisory & Assurance Services team helps organisations understand cyber risk, strengthen resilience and confidently embrace digital transformation. Through specialist expertise, trusted partnerships and innovative service delivery, we provide practical cyber security solutions that create measurable value for our clients.
Job in a nutshell
As our UK&I Pentesting Operations Lead, you will be responsible for the operational leadership, governance and continuous improvement of our penetration testing services across the United Kingdom and Ireland.
You will oversee the end-to-end lifecycle of penetration testing engagements delivered through a combination of internal teams and trusted specialist partners, ensuring that engagements are effectively scoped, scheduled, delivered, quality assured and commercially managed.
Working closely with clients, account teams, delivery teams and third-party penetration testing providers, you will help create a scalable, repeatable and high-quality service that supports growth across the UK&I.
This role could suit an experienced penetration testing lead seeking a broader operational leadership position, or an operations, PMO or service-delivery professional working within a penetration testing or offensive security organisation who is ready to take the next step in their career.
Hands-on penetration testing expertise is beneficial but not essential. We are primarily seeking someone with a strong understanding of penetration testing delivery, service operations, stakeholder management and supplier governance. Over time, you will also help shape the evolution of offensive security services, including AI-assisted testing, AI red teaming and security assurance for AI-enabled systems.
What will you be doing?
Lead the UK&I penetration testing service
- Own the operational delivery framework for penetration testing services across the UK & Ireland.
- Re-engineer and simplify operational processes to improve consistency, efficiency and scalability.
- Establish and maintain service governance, operating procedures, controls, metrics and reporting.
- Manage service demand, delivery pipelines, capacity constraints and operational priorities.
- Promote high standards of delivery quality, client experience and continuous improvement.
Coordinate and orchestrate testing engagements
- Act as the central coordination point for penetration testing engagements.
- Schedule testing activities across internal teams and multiple third-party providers.
- Coordinate clients, account teams, delivery stakeholders and testing partners throughout the engagement lifecycle.
- Track dependencies, risks, actions and delivery milestones from initiation through to closure.
- Resolve scheduling conflicts, operational issues and delivery challenges, escalating where appropriate.
Support engagement scoping
- Support clients and account teams in clarifying testing requirements and desired outcomes.
- Work with specialist providers to define suitable scopes, assumptions, testing methods and rules of engagement.
- Help ensure engagements are appropriately sized, planned, scheduled and commercially viable.
- Maintain consistent scoping templates and acceptance criteria across different categories of testing.
- Help stakeholders understand the most suitable testing approach for their systems, risks and assurance needs.
Manage external testing partners
- Manage day-to-day operational relationships with third-party penetration testing providers.
- Coordinate the allocation of work across approved suppliers according to capability, availability and commercial requirements.
- Monitor delivery performance, quality, responsiveness and adherence to agreed service expectations.
- Support supplier onboarding, due diligence and periodic service reviews.
- Act as the operational escalation point and drive constructive improvement across the partner ecosystem.
Assure quality and client outcomes
- Oversee the quality and completeness of engagement outputs before they are issued to clients.
- Confirm that reports are clear, consistent and aligned with the agreed scope and expected professional standards.
- Coordinate the clarification of findings between clients and testing providers.
- Capture lessons learned and convert them into improvements to processes, templates and supplier performance.
- Support effective communication of technical findings and associated business risk.
Maintain commercial and financial control
- Track engagements from initial request through delivery, acceptance and commercial closure.
- Maintain visibility of pipeline, revenue, costs, margins and delivery forecasts.
- Coordinate purchase orders, supplier invoices, client billing and internal approvals.
- Work with finance, account and delivery teams to support timely and accurate commercial administration.
- Identify operational or commercial leakage and implement proportionate corrective action.
Develop the capability
- Create standardised methods, templates, governance artefacts and delivery playbooks.
- Support bids, proposals, client workshops, statements of work and service presentations.
- Identify opportunities to improve efficiency through workflow automation and appropriate tooling.
- Use service data and stakeholder feedback to prioritise improvement initiatives.
- Help shape new offensive security propositions and routes to market.
AI and emerging offensive security services
As the service matures, you will help shape future capabilities. This may include:
- AI-assisted penetration testing and the responsible use of automation within testing workflows.
- Security testing of AI-enabled applications and services.
- AI red teaming and adversarial testing approaches.
- Assessment of large language model security risks and abuse cases.
- Testing approaches for agentic AI systems, tools, permissions and trust boundaries.
- Emerging offensive security methods, platforms and assurance services.
Experience and skills
- Experience working within penetration testing, offensive security, security assurance, cyber consulting or a closely related professional-services environment.
- A sound understanding of the end-to-end penetration testing delivery lifecycle.
- Experience coordinating complex activities across clients, delivery teams, suppliers and other stakeholders.
- Experience managing external suppliers, partners or outsourced services.
- Strong operational planning, organisation and prioritisation skills.
- Experience improving processes, governance or service-delivery practices.
- Strong stakeholder-management skills and the confidence to manage competing priorities.
- The ability to balance client outcomes, delivery quality, operational constraints and commercial objectives.
- Clear written and verbal communication, including the ability to explain technical issues to non-technical stakeholders.
- A collaborative, accountable and improvement-focused approach.
Technical understanding
You should have sufficient technical understanding to support scoping, challenge delivery assumptions and oversee the quality of testing engagements. Relevant areas include:
- Infrastructure penetration testing.
- Web application and API security testing.
- Cloud security testing.
- Internal and external security assessments.
- Vulnerability assessment and validation.
- Red teaming and adversary simulation concepts.
- Reporting, risk communication and remediation validation.
Desirable
- Experience leading penetration testing engagements, teams or operational functions.
- Experience working within or alongside a CREST-accredited penetration testing provider.
- Familiarity with CREST, CHECK and relevant NCSC assurance expectations.
- Experience managing a portfolio of work across several testing providers.
- Knowledge of demand management, resource forecasting, PMO or service-management practices.
- Familiarity with ITIL principles and operational service transition.
- Experience supporting bids, proposals, pre-sales discovery or client workshops.
- Relevant cyber security, project, service-management or operational-delivery certifications.
Highly desirable
- Experience with AI security testing or AI red teaming.
- Understanding of large language model risks, adversarial testing and AI application security.
- Knowledge of agentic AI architectures, identity, permissions and attack surfaces.
- Experience developing new security services or implementing automation within offensive security operations.
Who would this role suit?
- A penetration testing lead who wants to move into a broader service leadership and operations role.
- An operations manager or service-delivery lead within a penetration testing provider.
- A senior testing coordinator or PMO professional with strong knowledge of offensive security delivery.
- A cyber security service manager who understands penetration testing and wants greater ownership of a UK&I capability.
Leadership behaviours
- Take ownership of service outcomes and operational performance.
- Build trusted relationships with clients, suppliers and colleagues.
- Balance commercial objectives with quality, integrity and customer experience.
- Promote collaboration across account, advisory, delivery, finance and partner teams.
- Use evidence, service data and lessons learned to drive improvement.
- Encourage innovation while maintaining appropriate governance and human oversight.
- Challenge constructively and communicate decisions clearly.
- Support an inclusive, positive and accountable working environment.
What success looks like
- A consistent, efficient and scalable penetration testing operating model across the UK&I.
- Improved scheduling, governance, management information and operational control.
- Strong, transparent and constructive relationships with testing partners.
- High-quality client outcomes and a positive stakeholder experience.
- Effective financial governance, revenue recognition and supplier invoice management.
- Reduced operational friction and fewer avoidable delays across the engagement lifecycle.
- A healthy pipeline and sustainable growth in penetration testing services.
- A credible roadmap for future AI-enabled and AI-focused offensive security capabilities.
Rewards and benefits
- A visible role with the opportunity to re-engineer and shape a strategically important UK&I cyber security service.
- Varied work across service operations, stakeholder engagement, supplier leadership, commercial governance and innovation.
- Opportunities for professional development, continuous learning and career progression.
- Remote and hybrid working possibilities, subject to business and client requirements.
- The opportunity to participate in volunteering, charity, inclusion and sustainability initiatives.
Benefits:
- Pension Scheme - contributions matched up to 10%
- Private medical cover
- Income Protection
- Life Assurance
- 25 days paid leave + National Holidays
- Flex benefits program
Please note eligibility for SC clearance is essential for this role.
As a Disability Confident employer, we encourage applications from all applicants, especially, differently abled applicants. We aim to ensure that those who meet the minimum criteria for this position will be offered an interview. We are committed and willing to making reasonable adjustments to the application and assessment process to accommodate your needs.
We are a care leaver friendly employer, if you require additional support with your application, please contact our recruiter or send an email to our dedicated mailbox - UK-Recruitment-Support@atos.net. If you have any questions, please contact our recruitment partner Meyeppan M on LinkedIn
Here at Atos, diversity and inclusion are embedded in our DNA. Read more about our commitment to a fair work environment for all.
Atos is a recognized leader in its industry across Environment, Social and Governance (ESG) criteria. Find out more on our CSR commitment.
Choose your future. Choose Atos.