Key Responsibilities:
Leadership & Strategy
- Develop and execute the organization's Penetration Testing strategy aligned with business objectives.
- Lead, mentor, and develop a high-performing Penetration Testing team.
- Establish KPIs, performance metrics, and quality standards for service delivery.
Penetration Testing Delivery
- Oversee the planning, execution, and reporting of penetration testing engagements.
- Ensure all assessments follow recognized methodologies and industry best practices.
- Review technical reports to ensure accuracy, quality, and actionable remediation recommendations.
Client Engagement
- Build strong relationships with clients and understand their security objectives.
- Present technical findings and executive summaries to both technical and non-technical stakeholders.
- Support pre-sales activities by providing technical expertise during client engagements.
Quality & Continuous Improvement
- Continuously improve penetration testing methodologies, tools, and reporting standards.
- Stay current with emerging threats, attack techniques, and offensive security trends.
- Promote innovation and continuous improvement across the PT practice.
Cross-Functional Collaboration
- Work closely with GRC, Security Operations, Incident Response, Engineering, and Consulting teams.
- Collaborate with technology partners and vendors to enhance service capabilities.
Qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
- Master's degree is preferred.
Experience:
- Minimum of 10 years of experience in Cybersecurity.
- At least 5 years in a leadership role within Penetration Testing, Red Teaming, or Offensive Security.
- Proven experience leading enterprise penetration testing engagements.
- Previous experience within a cybersecurity consulting firm, MSSP, or technology company is highly preferred.
Technical Skills:
- Web Application Penetration Testing
- Network Penetration Testing
- Internal & External Infrastructure Assessments
- Red Team Operations
- Vulnerability Assessment
- Active Directory Security Assessments
- Cloud Security Assessments
- Wireless Security Testing
- Secure Reporting & Risk Prioritization
- Project & Team Management
Preferred Certifications:
- OSCP
- OSEP (Preferred)
- OSWE (Preferred)
- CRTO (Preferred)
- CISSP
- GPEN (Preferred)
Soft Skills:
- Strong leadership and team management skills.
- Excellent communication and presentation abilities.
- Strategic thinking and decision-making skills.
- Client-focused mindset.
- Strong analytical and problem-solving capabilities.