Penetration Testing Program Governance & Vendor Strategy Manager
We are seeking a Penetration Testing Program Governance & Vendor Strategy Manager to lead the governance, planning and continuous improvement of an enterprise-wide penetration testing programme. In this role, you will establish and maintain standards, policies, procedures and control frameworks that support effective testing across applications, infrastructure, cloud environments, networks and emerging technologies. You will oversee the annual testing roadmap, prioritising activity according to business risk, regulatory expectations, threat intelligence and changes to the technology estate.
You will manage relationships with external penetration testing providers, including supplier selection, due diligence, onboarding, contract management, performance reviews and service-level governance. Responsibilities will include developing statements of work, defining testing requirements, assessing proposals, monitoring delivery quality and ensuring findings are documented, risk-rated and remediated within agreed timeframes. You will partner with cybersecurity, technology, risk, compliance, procurement and business stakeholders to provide clear reporting on programme status, vulnerabilities, exceptions, remediation progress and residual risk. You will also support audits and regulatory reviews, maintain accurate management information and identify opportunities to improve efficiency, coverage and assurance.
The successful candidate will have significant experience in penetration testing, cybersecurity assurance, security governance, third-party risk or a related discipline, with a strong understanding of testing methodologies, vulnerability management and risk assessment. Experience managing specialist security vendors and complex programmes across multiple technology domains is essential. You should be confident interpreting technical reports, challenging results constructively and communicating security risk to both technical and senior non-technical audiences. Strong negotiation, organisation, stakeholder management and analytical skills are required, together with the ability to manage competing priorities in a changing environment. Relevant certifications such as OSCP, CREST, CISSP, CISM, CRISC or equivalent experience are desirable.
Penetration Testing Program Governance & Vendor Strategy Manager
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- Security Consultant
- IT Security Manager
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Cyber SOC Specialist - ESN
- End User Platform Vulnerabilit...
- Lead Security Engineer
- Member of Technical Staff (Sof...
- Cyber Security Consultant - As...
- Cyber Security Analyst - Enter...
- Technical Leader - Splunk Secu...
- Digital & Cyber Resilience – M...
- Data Protection Engineer
- Security Advisor
- Information Security Engineer
- Test Automation Engineer - Sec...
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer