Manager – Offensive Cybersecurity, Penetration Testing
RegionUSA
Job description
Job Description: - Lead and oversee penetration testing engagements across enterprise applications, systems, networks, cloud platforms, and other in-scope environments
- Define testing scope, methodology, and priorities based on business risk, threat intelligence, and organizational objectives
- Validate vulnerabilities and attack paths through manual testing, proof-of-concept development, and adversary emulation techniques
- Partner with engineering, infrastructure, and application teams to communicate findings, support remediation, and improve overall security posture
- Lead, mentor, and develop team members to strengthen offensive security capabilities and technical depth
- Establish and mature offensive security processes, methodologies, reporting standards, and quality controls
- Develop metrics and reporting to communicate testing coverage, findings trends, remediation progress, and program effectiveness to leadership
- Collaborate with cross-functional stakeholders to prioritize testing activities and support secure design and remediation efforts
- Develop or adapt proof-of-concept exploits to validate vulnerabilities and assess potential business impact
- Create repeatable assessment and reporting processes supporting audit, compliance, and governance requirements
Requirements: - Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience
- OSCP, OSEP, CRTP, CEH, CPT, CEPT, GPEN or other experienced industry standard penetration testing certification(s) required
- 7+ years of combined IT and security work experience with broad exposure to systems analysis, application development, database design, networking, administration, identity, or other responsibilities preferred
- 5+ years’ experience in information security required
- 3+ years’ experience performing penetration testing required
- Ability to work independently and troubleshoot technical and business process related issues
- Subject matter expertise in the entire information security stack
- Ability to develop technical testing solutions for internal consumption
- Ability to analyze and scope vulnerability disclosures and CVEs
- Expertise in OWASP
- Experience leading penetration testing programs or engagements in a large enterprise environment
- Excellent understanding of threat vectors and containment methods
- Knowledge of Active Directory discovery, enumeration and exploit methods
- Experience assessing cloud environments (AWS, Azure, GCP), including common misconfigurations, attack paths, and defensive controls
- Excellent written and verbal communication skills, with ability to present technical findings to technical and non-technical audiences
- Experience with multiple and current Endpoint Detection and Response solutions
- Experience with Vulnerability Management concepts and best practices
- Knowledge of Windows, Linux, Mac OS, and mobile operating systems
- Expertise in networking concepts, protocols and encryption
- Expertise in application security practices and tools
- Expertise in programming/scripting languages such as Python, PowerShell, Bash, C/C++/C#
- Expertise in Metasploit or similar tooling
- Expertise in penetration testing security tooling such as Kali Linux
- Expertise in Burp Suite or similar tooling
- Purple team experience
Benefits: - Discretionary annual bonus
- Group health insurance benefits (medical, vision, dental)
- FSA and HSA healthcare accounts
- Life and accident insurance
- Adoption and fertility assistance
- Paid parental leave of up to 6 weeks
- Short/long term disability
- Paid time off for vacation, personal needs, and sick time
- Up to 17 days of Choice Time Off (CTO) per calendar year for new hires
- Up to 11 paid holidays per calendar year
- 401(k) savings and investment plan or deferred compensation plan (if eligible)
- Employer match of 100% on the first 3% of contributions for eligible employees
- Reasonable accommodation assistance for applicants with disabilities
first seen 2026-09-22 05:30:01 · last verified 2026-09-22 13:30:01
pentestcareers.com // breach the job market