CS Interview Coach

Lead Ethical Hacking Penetration Tester (£57,515 - £82,430)

Driver and Vehicle Licensing Agency

Department
Driver and Vehicle Licensing Agency
Location
Swansea
Openings
1 post
Grade
Grade 7
Salary
£57,515 to £82,430
Closing
Closes today
Profession
DDaT, Finance
Contract
Permanent
Security clearance
SC
Working pattern
Flexible working, Full-time, Job share, Part-time
Apply on Civil Service Jobs

Job summary

Can you Lead and deliver complex penetration testing and ethical hacking activities across a large and diverse IT estate?

Do you thrive in a fast-paced environment where your expertise helps protect critical public services?

Have you led penetration testing, vulnerability management or IT health checking programmes?

If so, we’d love to hear from you!

Join our Ethical Hacking Services team and play a pivotal role in protecting critical digital services. You'll provide expert cyber security assurance, lead penetration testing and vulnerability management activities, and help ensure our systems remain resilient against current and emerging threats. You'll also have the opportunity to influence security strategy, develop talent and contribute to cyber security best practice across government.

Joining our department comes with many benefits, including:

  • Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
  • 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays and a privilege day for the King’s birthday
  • Flexible working options where we encourage a great work-life balance.

Read more in the Benefits section below!

Find out more about what it's like working at DVLA - Driver and Vehicle Licensing Agency – Civil Service Careers.

What they’re looking for

  • Required Experience
  • To be successful in this role you will need to have the following experience:
  • Leading penetration testing and ethical hacking activities within complex enterprise environments.
  • Designing and delivering vulnerability management and security testing programmes.
  • Assessing and communicating cyber security risks to both technical and non-technical audiences.
  • Influencing senior stakeholders and driving remediation activity.
  • Leading, coaching and developing teams.
  • Working with security standards, frameworks and industry best practice
  • Expert knowledge of penetration testing methodologies and tools.
  • Strong understanding of vulnerability management and cyber security operations.
  • Knowledge of threat intelligence, threat assessment and threat mitigation techniques.
  • Strong understanding of security technologies, networks, infrastructure and application security.
  • Ability to diagnose security weaknesses and recommend practical solutions.
  • Understanding of legal, regulatory and compliance requirements relating to cyber security
  • Additional Information
  • The role is part of the Government Security Profession Career Framework and utilises an enhanced Capability–Based Pay Framework which provides access to a Digital and Data allowance.
  • The base pay is £57,515. In addition to this the role includes a Digital and Data allowance of up to £24,915.
  • The value of allowance awarded will be based on an assessment of your skills and experience as demonstrated through the selection process. Here are more details on the pay framework.
  • Working for the DVLA Digital Team
  • At DVLA, licensing is just the start. Every project you implement, touch and deliver has a ripple effect that’ll wash across the nation. Here the work you’re doing has the capacity to change the way 53 million people interact with our services. As we aim to keep our roads some of the safest in the world, our innovative, transformative digital-led services help optimise a nation of individuals and business every single day.
  • To see how our people are transforming our digital services, head over to our DVLA Digital Services Blog and, to understand more about the great opportunities and benefits of working at DVLA read our Inside DVLA blog.
  • Working hours, office attendance and travel requirements
  • Full time roles consist of 37 hours per week. Whilst we welcome applications from those looking to work with us on a part time basis, there is a business requirement for the successful candidate to be able to work at least 35 hours per week.
  • This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
  • The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (the location cited in the advert) or, when required for business reasons, in another office/work location. There may be occasions where you are required to attend above the minimum expectation.
  • If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
  • Security Check
  • Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check. To allow for meaningful checks to be carried out, candidates will be required to have at least 5 years continuous residency in the UK. All applicants for this role must ensure that they meet this minimum residency requirement - if you do not, your application will be withdrawn.
  • Visa Sponsorship
  • Please note that we do not hold a UK Visa & Immigration (UKVI) Skilled Worker Licence sponsor and are unable to sponsor any individuals for Skilled Worker Sponsorship. Candidates must ensure they have the appropriate rights to work in the UK before application.

Behaviours you’ll be assessed on

This advert says the panel will score you against these behaviours at Grade 7 level. Each one links to worked examples.

Job description

As the Lead Ethical Hacking Penetration Tester, you will be the senior technical specialist responsible for leading penetration testing and vulnerability management activities across a diverse technology landscape. You will help shape security testing strategy, identify and assess risks, and ensure effective remediation of vulnerabilities.

Your responsibilities will include, but aren’t limited to:

  • Lead and act as a subject matter expert for penetration testing, ethical hacking and vulnerability management services.
  • Design, deliver and oversee programmes of penetration testing, vulnerability assessments and IT health checks across applications, infrastructure and networks.
  • Identify, analyse and assess vulnerabilities, ensuring risks are prioritised using a risk-based approach.
  • Provide clear reporting and recommendations to support remediation and security improvement activities.
  • Monitor emerging threats, attack techniques and vulnerabilities, adapting testing approaches where required.
  • Build effective relationships with suppliers, stakeholders and delivery teams to ensure security objectives are achieved.
  • Lead, mentor and develop team members, supporting performance, capability development and succession planning.
  • Ensure all work complies with relevant security standards, government policies, legislation and organisational requirements.

Great line management is important to us as an organisation, and we will equip and support line managers to develop the skills they need. We aim to empower line managers to create teams where people can flourish and deliver excellent outcomes for the public.

For further information on the role, please read the attached role profile. Please note that the role profile is for information purposes only - whilst all elements are relevant to the role, they may not all be assessed during the recruitment process. This job advert will detail exactly what will be assessed during the recruitment process.

Nationality requirements

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Selection process

This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.

How to Apply

Our selection process ensures a comprehensive assessment of each applicant's qualifications, skills, and potential fit within our organisation.

The selection process for this role will be:

Stage 1: Sift of CV and personal statement

Stage 2: Interview

You must be successful at each stage to progress to the next stage.

Stage 1: Sift

At sift, you will be assessed against the following Success Profile elements:

Experience – you will be asked to provide a CV (unlimited wordcount) and personal statement (750-word count). Please provide evidence of your Experience of the following:

  • Demonstrable experience leading and delivering complex penetration testing and ethical hacking activities across enterprise environments, including web applications, infrastructure, cloud services and networks.
  • Experience providing technical leadership within a Penetration Testing function, applying appropriate Legal and Industry standards, mentoring practitioners and ensuring the quality of security testing outcomes.
  • Ability to translate complex technical findings into clear business risk, providing expert advice and influencing stakeholders to improve organisational security.

The sift will take place week commencing 14/09/2026.

Stage 2: Interview

At interview stage, you will be assessed against the following Success Profile elements:

Behaviours

  • Leadership

Technical

  • Penetration testing (Skill level Expert)
  • Legal and regulatory environment and compliance (Skill level Awareness)
  • Protective security (Skill level Working)
  • Security Technology (Skill level Expert)

These can also be found at Government Digital and Data Profession Capability Framework & Government Security Profession

The interviews will take place week commencing 21/09/206.

This interview will be conducted in person at our Swansea office (DVLA, Longview Road, Morriston, Swansea, SA6 7JL). Further details will be provided to you should you be selected for interview.

Appointments for this position will be made in order of merit. If you are successful in the selection process but there are no further available posts for the advertised role, you may be contacted to discuss an offer for a lower graded role (with similar experience and responsibility requirements). If you are unsuccessful in the selection process, your application may be considered for a lower graded position if your demonstrated skills and experience meet the requirements of the alternative position. Candidates will be considered in order of merit.

You can find out more about our hiring process, how to apply, and application and interview guidance on our careers site (opens in a new window).

Please note that we will try to meet the dates set out in the advert. There may be occasions when these dates will change.

Further information on the selection process

We will also hold a 12-month reserve list for this role, which may lead to potential opportunities beyond the role you applied for.

Reasonable Adjustments

As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes.

Complete the “Assistance required” section in the “Additional requirements” page of your application form to tell us what changes or help you might need during the recruitment process. For instance, you may need wheelchair access at an interview, or if you’re deaf, a Language Service Professional.

If you need a reasonable adjustment so that you can complete your application, you should contact Government Recruitment Service via dftrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.

Document Accessibility

This job advert contains links to the DfT Careers website. Our website provides useful guidance and information that can support you during the application process. If you are experiencing accessibility problems with any attachments on this advert or the information on our website, please contact the email address in the 'Contact point for applicants' section.

Further Information

For more information about how we hire, and for useful tips on submitting your application for this role, visit the How We Hire page of our DfT Careers website. You can find detailed information about the recruitment process and what to expect when applying for a role.

Pre-employment Checking

If your application is successful but you have been dismissed from the Civil Service, your application could be removed at the pre-employment checking stage depending on the nature of the dismissal.

Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5-year period following a dismissal for carrying out internal fraud against government.

All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:

  • Hate speech or discriminatory behaviour
  • Threats or acts of violence
  • Illegal activity or substance misuse
  • Sexually explicit material
  • Extremist views or affiliations

Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. It’s not about judging your personality or lifestyle - it’s about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail what’s being looked at and how your data is handled securely and fairly.

Vetting

For further information on National Security Vetting please visit the Demystifying Vetting website.

Feedback will only be provided if you attend an interview or assessment.

Practise before you apply

Civil Service panels score every answer against the Success Profiles behaviours at Grade 7 level. Practise STAR answers and get them marked against the same framework.

Start practising free

3 free questions · No card needed

Similar vacancies

Interview articles for Grade 7 roles

All articles

Browse more like this