Penetration Testing as a Service (PTaaS) program
RegionUSA
Job description
Penetration Testing as a Service (PTaaS) Business Analyst The PTaaS Business Analyst supports the Penetration Testing as a Service (PTaaS) program by translating business needs into actionable requirements, optimizing workflows, and providing visibility into testing coverage, risk trends, and remediation progress. This role partners with security engineering, product owners, infrastructure teams, and PTaaS vendors to ensure penetration testing activities are well scoped, tracked, governed, and reported.
Key Responsibilities
- Requirements Process Management: Gather and refine requirements for PTaaS engagements; define standardized intake, scoping, and approval workflows; support playbooks and SOPs.
- Stakeholder Coordination: Act as liaison between security teams, application owners, infrastructure, and vendors; facilitate intake discussions, status updates, and governance forums.
- Metrics Reporting: Develop dashboards and metrics (coverage, findings trends, SLA compliance, remediation aging); translate technical outcomes into business readable insights; support executive and audit reporting.
- Tracking Execution: Manage PTaaS work items in Jira; track dependencies, risks, and blockers; monitor remediation progress and coordinate retests.
- Continuous Improvement: Identify process gaps and automation opportunities; integrate PTaaS with vulnerability management and risk platforms; contribute to roadmap planning and maturity improvements.
Required Qualifications
- 4+ years as a Business Analyst, Security Analyst, or Program Analyst in cybersecurity or IT.
- Experience with penetration testing, vulnerability management, or security assurance programs.
- Strong skills in requirements gathering, documentation, and stakeholder facilitation.
- Experience with Jira, ServiceNow, Confluence, or similar tools.
- Strong analytical, communication, and reporting skills.
Preferred Qualifications
- Familiarity with PTaaS delivery models and penetration testing lifecycle.
- Understanding of OWASP Top 10, CVSS, and risk prioritization.
- Experience in regulated or enterprise environments.
- Exposure to vulnerability management platforms (Tenable, Qualys, Rapid7).
- Certifications such as CBAP, PMI PBA, or security fundamentals.
Core Competencies
- Business to technical translation, process optimization, data analysis, stakeholder management, and a risk based mindset.
first seen 2026-10-05 09:30:01 · last verified 2026-10-08 09:30:01
pentestcareers.com // breach the job market