Search by job, company or skills

Offensive Security - Manager

  • Posted 2 days ago
  • Be among the first 10 applicants

Job Description

Summary:

We are seeking an Offensive Security Manager to lead and execute penetration testing and red team engagements. You will plan and execute authorized security assessments — including web applications, APIs, internal/external networks, cloud environments, and full-scope red team engagements — to identify exploitable weaknesses before real adversaries do. You'll work closely with Sec/Ops, detection engineering, application security, and IT teams to translate findings into measurable risk reduction.

Key Responsibilities:

  • Plan, scope, and execute penetration tests and red team engagements across web applications, APIs, internal/external networks and cloud infrastructure (AWS/Azure/GCP).
  • Lead and mentor a team of Red Team and application Security engineers.
  • Support Executive and Leadership Alignment of the application security and red teaming programs with Engineering and Platform teams.
  • Define and execute the offensive security strategy, roadmap, and testing methodologies.
  • Conduct and oversee adversary emulation exercises, red team operations, penetration testing, and security assessments.
  • Evaluate the effectiveness of security controls through realistic attack simulations and threat-informed testing.
  • Partner with Security Operations and Detection Engineering teams to drive purple team exercises and improve detection and response capabilities.
  • Research emerging threats, attacker techniques, and offensive security trends to continuously improve testing capabilities.
  • Simulate real-world adversary tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK, including initial access, privilege escalation, lateral movement, persistence, and exfiltration simulation.
  • Perform manual and automated testing of web apps and APIs (REST/GraphQL/SOAP) for OWASP Top 10, business logic flaws, authentication/authorization bypass, and API-specific abuse cases.
  • Conduct internal network penetration tests: Active Directory attack paths, Kerberoasting, relay attacks, segmentation testing, and post-exploitation.
  • Provide risk-based recommendations and work closely with engineering teams to drive remediation efforts.
  • Communicate security findings, risks, and strategic recommendations to technical and executive stakeholders.
  • Build and scale offensive security programs, processes, and talent within the organization.

Skills/Experience/Qualification:

  • 10+ years of experience in Offensive Security, Red Teaming, Penetration Testing, Security Research, or related cybersecurity disciplines.
  • 3+ years of experience leading and developing high-performing security teams.
  • Strong expertise in adversary emulation, red teaming, penetration testing, and threat-driven security assessments.
  • Hands-on experience with purple teaming, threat hunting, exploit development, or security research.
  • Strong scripting skills to build and maintain test automation, reusable checks, and validation scripts (Python, Bash, PowerShell).
  • Experience assessing cloud platforms (AWS, Azure, GCP), enterprise environments, and cloud-native technologies including containers and Kubernetes.
  • Strong understanding of application security, network security, identity security, and detection engineering concepts.

Tools

Burp Suite pro, OWASP ZAP, Postman, Nmap, Nesus, Wireshark, Nessus, Metasploit, Cobalt Strike, Bloodhound, Impacket, Trivy, Automated scanning/validation tools

Certifications

OSCP, OSWE, CRTP, eWPT, CISSP, or equivalent.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 151613763