Job Title: Manager - Penetration Testing
Job Summary
The Penetration Testing Manager is a pivotal role within our cybersecurity team, responsible for overseeing all penetration testing activities and managing a team of skilled professionals. This position requires a blend of technical expertise and leadership capabilities to shape and implement effective cybersecurity strategies across the organization. The ideal candidate will possess a deep understanding of security frameworks and methodologies, as well as the ability to communicate complex security risks to stakeholders at all levels. The Penetration Testing Manager will play a crucial role in enhancing the organization's security posture by leading large-scale testing projects and fostering a culture of security awareness and compliance.
Key Responsibilities
- Manage a team of penetration testers and security analysts, providing guidance and mentorship to enhance their skills and performance.
- Plan, oversee, and execute large-scale penetration testing projects, ensuring thorough assessments of the organization's security vulnerabilities.
- Develop and refine security testing strategies and methodologies to align with industry best practices and emerging threats.
- Coordinate red team exercises and adversary emulation campaigns to simulate real-world attack scenarios and improve incident response capabilities.
- Ensure compliance with security standards and regulatory requirements, conducting regular audits and assessments to identify gaps.
- Collaborate with stakeholders across the organization to improve the enterprise security posture, providing actionable insights and recommendations.
- Develop and implement security training programs for internal teams to promote a culture of cybersecurity awareness and best practices.
Skills and Knowledge Required
- Strong leadership and project management skills, with a proven track record of successfully leading security teams and initiatives.
- Expertise in penetration testing, vulnerability management, and threat intelligence, with hands-on experience in various testing methodologies.
- Deep understanding of security frameworks such as NIST, MITRE ATT&CK, and CIS, and their application in real-world scenarios.
- Experience with security operations, incident response, and forensic analysis, demonstrating the ability to handle security incidents effectively.
- Strong business acumen and the ability to communicate security risks and strategies to executives and non-technical stakeholders.
Educational Qualifications
- Bachelor’s or Master’s degree in Cybersecurity, Computer Science, or a related field.
- Preferred certifications include CISSP, CISM, OSCP, OSCE, CRTP, and LPT Master.
Key Focus Areas
- Security governance and risk management, ensuring alignment with organizational objectives.
- Offensive security strategies to proactively identify and mitigate potential threats.
- Team leadership and cybersecurity training to cultivate a skilled and knowledgeable workforce.
Experience
- 8+ years of experience in penetration testing and security leadership roles, demonstrating a strong understanding of the cybersecurity landscape.
Tools and Equipment
- Proficiency with enterprise security platforms such as Splunk, Tenable, Qualys, and Rapid7.
- Experience with advanced red teaming tools and frameworks to conduct comprehensive security assessments.
Other Requirements
- Strong ability to interact with executives and technical teams, fostering collaboration and understanding across departments.
- Experience leading large-scale security initiatives, demonstrating effective project management and strategic planning skills.