NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Managed extended detection and response (MXDR), attack surface management (ASM), breach and attack simulation (BAS), and advisory services fortify your cybersecurity across both offense and defense. AI-driven intelligence in our Nopal360 platform, our NopalGo mobile app, and our proprietary Cyber Intelligence Quotient (CIQ) lets anyone quantify, track, and visualize their cybersecurity posture in real-time. Our service packages, which are each tailored to a client’s needs and budget, and external threat analysis, which provides critical intelligence at no-cost, help to democratize cybersecurity by making enterprise-grade defenses and security operations available to organizations of all sizes. NopalCyber lowers the barrier to entry while raising the bar for security and service.
Job Description
As a Senior Manager of the Attack Surface Reduction (ASR) Team ,you will lead an elite squad of highly technical security researchers andpenetration testers. In the high-stakes environment of a Managed SecurityService Provider (MSSP), this team is the frontline of defence and offense forour global clients.
You will be responsible for the end-to-end delivery of advanced securityassessments, ranging from automated attack surface discovery to manual"Red Team" operations. This is a leadership role that requires technicaldepth, as you will guide experts in breaking into some of the most complexenvironments in the world to ensure they are unshakeable.
Key Responsibilities
- TeamLeadership: Lead, mentor, and scale ahigh-performance team of technical specialists. Foster a culture ofcontinuous research, curiosity, and ethical hacking excellence.
- Full-SpectrumAssessments: Oversee the execution of comprehensivesecurity evaluations, both internally and externally for our clientportfolio:
- Application Security: DAST, SAST, SCA, bothBlack Box and Grey Box and deep-dive API security testing.
- Offensive Operations: Red Teaming, AdversarialSimulations, and Breach & Attack Simulation (BAS).
- Vulnerability Management: Advanced VAPT(Vulnerability Assessment & Penetration Testing)
- Defensive Validation & Resiliency Testing: Ransomware Resiliency testing to ensure clients can withstand and recoverfrom modern extortion tactics.
- AttackSurface Discovery: Direct the continuous mapping of knownand unknown digital assets to identify shadow IT and exposed entry points.
- ServiceInnovation: Develop and refine the MSSP service catalogue.Identify emerging threats and translate them into new testingmethodologies and cybersecurity services.
- StakeholderManagement: Act as the technical authority duringhigh-level client briefings, translating complex technical findings intoactionable executive risk reports.
Requirements
Technical Requirements
- Experience: 10+years in Offensive Security, with at least 3-5 years in a formalleadership/management role.
- Expertise: Deeptechnical mastery of the "Attacker Mindset." You should becomfortable discussing advanced exploitation techniques, CI/CD pipelinevulnerabilities, and hybrid or cloud-native lateral movement in the samebreath.
- Tooling& Frameworks: Proficiency in modern toolkits (BurpSuite, Metasploit, Cobalt Strike, etc.).
- Expertisein BAS platforms and Attack Surface Management (ASM) tools.
- Experience with Cloud Security (AWS/Azure/GCP) and container security(Docker/K8s).
- Firm grasp of the MITRE ATT&CK framework.
- Certifications: Preferred: OSCE, OSEP, GXPN, or CISSP/CCSP/CISM.
Required Development & Automation Skills
- Security ToolingDevelopment: Proficiency in Python or Go (Golang) to build customscanners, exploit wrappers, and automation scripts.
- Infrastructure as Code(IaC): Solid understanding of Terraform or Ansible to rapidly spin up (andtear down) complex "range" environments for Red Team simulationsand Ransomware Resiliency testing.
- Dev-Sec-Ops & CI/CDIntegration: Deep knowledge of how to integrate SAST/DAST/SCA toolsdirectly into GitLab, GitHub Actions, or Jenkins pipelines withoutbreaking the developer workflow.
- API Mastery: Advancedability to interact with, test, and develop against RESTful and Graph-QLAPIs. This includes writing custom scripts to automate mass APIvulnerability discovery.
- Cloud-NativeDevelopment: Familiarity with Serverless (AWS Lambda/Azure Functions) andContainerization (Docker/Kubernetes) to identify and exploitmisconfigurations in modern microservices architectures.
- Exploit DevelopmentBasics: Understanding of low-level languages like C/C++ or Rust to overseethe team when they are performing deep-dive binary analysis or bypassresearch.
- Data Engineering forSecurity: Ability to work with SQL/NoSQL and ELK stacks (Elasticsearch,Logstash, Kibana) to aggregate and analyse the massive amounts of datagenerated during Attack Surface Discovery.
- Candor& Clarity: The ability to give direct, constructivefeedback to a highly technical team while maintaining high morale.
- StrategicVision: Moving beyond "finding bugs" to helping clients buildlong-term Resilience Frameworks .
Technical Depth: You must be able to "speak the language" ofhighly technical researchers to earn their respect and provide valid guidance.
PressureManagement: Thriving in the fast-paced, 24/7 nature of anMSSP.
Why Join Us?
You aren't just managing a team; you are architecting the future of offensivesecurity. You will have access to diverse environments, cutting-edge"Advanced Technologies," and you’ll drive red-team strategies and emulatereal-world adversaries to ensure clients stay ahead of the global threatlandscape.