Senior Manager, Attack Surface Reduction

NopalCyber

Hyderabad

On-site

INR 2,600,000 - 3,800,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NopalCyber is seeking a Senior Manager for the Attack Surface Reduction (ASR) Team to lead a highly technical squad of security researchers and testers within an MSSP framework. You will drive end-to-end security assessments from automated discovery to Red Team operations, shaping service offerings for global clients.

This leadership role demands deep technical depth, mentoring, and the ability to translate complex findings into actionable executive risk reports.

Qualifications

  • ;10+ years in Offensive Security with 3–5 years in leadership or management.;Deep mastery of Attacker Mindset and advanced exploitation techniques.;Proficiency with modern toolkits: BurpSuite, Metasploit, Cobalt Strike.;Experience with BAS platforms and ASM tools.;Cloud security across AWS/Azure/GCP and container security (Docker/K8s).;Familiarity with MITRE ATT&CK framework;Certifications: OSCE, OSEP, GXPN, CISSP/CCSP/CISM preferred.

Responsibilities

  • Lead and scale a high-performance team of security researchers and testers.
  • Oversee end-to-end security assessments: DAST, SAST, SCA, Red Team, BAS, VAPT.
  • Map attack surfaces and shadow IT to expose entry points.
  • Translate technical findings into executive risk reports for clients.
  • Develop and refine MSSP service catalogue and testing methodologies.

Skills

Offensive Security
Leadership
Attacker Mindset
BurpSuite
Metasploit
Cobalt Strike
BAS
ASM
Cloud Security
Docker/K8s
MITRE ATT&CK
Certifications

Tools

BurpSuite
Metasploit
Cobalt Strike
Terraform
Ansible
GitLab
GitHub Actions
Jenkins

Job description

Job Description

As a Senior Manager of the Attack Surface Reduction (ASR) Team ,you will lead an elite squad of highly technical security researchers andpenetration testers. In the high-stakes environment of a Managed SecurityService Provider (MSSP), this team is the frontline of defence and offense forour global clients.

You will be responsible for the end-to-end delivery of advanced securityassessments, ranging from automated attack surface discovery to manual"Red Team" operations. This is a leadership role that requires technicaldepth, as you will guide experts in breaking into some of the most complexenvironments in the world to ensure they are unshakeable.

Key Responsibilities

  • TeamLeadership: Lead, mentor, and scale ahigh-performance team of technical specialists. Foster a culture ofcontinuous research, curiosity, and ethical hacking excellence.
  • Full-SpectrumAssessments: Oversee the execution of comprehensivesecurity evaluations, both internally and externally for our clientportfolio:
    • Application Security: DAST, SAST, SCA, bothBlack Box and Grey Box and deep-dive API security testing.
    • Offensive Operations: Red Teaming, AdversarialSimulations, and Breach & Attack Simulation (BAS).
    • Vulnerability Management: Advanced VAPT(Vulnerability Assessment & Penetration Testing)
    • Defensive Validation & Resiliency Testing: Ransomware Resiliency testing to ensure clients can withstand and recoverfrom modern extortion tactics.
    • AttackSurface Discovery: Direct the continuous mapping of knownand unknown digital assets to identify shadow IT and exposed entry points.
    • ServiceInnovation: Develop and refine the MSSP service catalogue.Identify emerging threats and translate them into new testingmethodologies and cybersecurity services.
    • StakeholderManagement: Act as the technical authority duringhigh-level client briefings, translating complex technical findings intoactionable executive risk reports.
Requirements

Technical Requirements

  • Experience: 10+years in Offensive Security, with at least 3–5 years in a formalleadership/management role.
  • Expertise: Deeptechnical mastery of the "Attacker Mindset." You should becomfortable discussing advanced exploitation techniques, CI/CD pipelinevulnerabilities, and hybrid or cloud-native lateral movement in the samebreath.
  • Tooling& Frameworks: Proficiency in modern toolkits (BurpSuite, Metasploit, Cobalt Strike, etc.).
  • Expertisein BAS platforms and Attack Surface Management (ASM) tools.
  • Experience with Cloud Security (AWS/Azure/GCP) and container security(Docker/K8s).
  • Firm grasp of the MITRE ATT&CK framework.
  • Certifications: Preferred: OSCE, OSEP, GXPN, or CISSP/CCSP/CISM.

Required Development & Automation Skills

  • Security ToolingDevelopment: Proficiency in Python or Go (Golang) to build customscanners, exploit wrappers, and automation scripts.
  • Infrastructure as Code(IaC): Solid understanding of Terraform or Ansible to rapidly spin up (andtear down) complex "range" environments for Red Team simulationsand Ransomware Resiliency testing.
  • Dev-Sec-Ops & CI/CDIntegration: Deep knowledge of how to integrate SAST/DAST/SCA toolsdirectly into GitLab, GitHub Actions, or Jenkins pipelines withoutbreaking the developer workflow.
  • API Mastery: Advancedability to interact with, test, and develop against RESTful and Graph-QLAPIs. This includes writing custom scripts to automate mass APIvulnerability discovery.
  • Cloud-NativeDevelopment: Familiarity with Serverless (AWS Lambda/Azure Functions) andContainerization (Docker/Kubernetes) to identify and exploitmisconfigurations in modern microservices architectures.
  • Exploit DevelopmentBasics: Understanding of low-level languages like C/C++ or Rust to overseethe team when they are performing deep-dive binary analysis or bypassresearch.
  • Data Engineering forSecurity: Ability to work with SQL/NoSQL and ELK stacks (Elasticsearch,Logstash, Kibana) to aggregate and analyse the massive amounts of datagenerated during Attack Surface Discovery.
  • Candor& Clarity: The ability to give direct, constructivefeedback to a highly technical team while maintaining high morale.
  • StrategicVision: Moving beyond "finding bugs" to helping clients buildlong-term Resilience Frameworks .
Key Traits
  • Technical Depth: You must be able to "speak the language" ofhighly technical researchers to earn their respect and provide valid guidance.
  • PressureManagement: Thriving in the fast-paced, 24/7 nature of anMSSP.

Why Join Us?

You aren't just managing a team; you are architecting the future of offensivesecurity. You will have access to diverse environments, cutting-edge"Advanced Technologies," and you’ll drive red-team strategies and emulatereal-world adversaries to ensure clients stay ahead of the global threatlandscape.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Sr Offensive Security Engineer
Sr Offensive Security Engineer

First Advantage • India

On-site
INR 2,000,000 - 2,800,000
Security Lead- Red Teaming and Application Security
Security Lead- Red Teaming and Application Security

Security Brigade • Navi Mumbai

On-site
INR 4,000,000 - 7,000,000
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Mumbai

On-site
INR 1,200,000 - 2,000,000
Lead Security Specialist
Lead Security Specialist

Skillmine Technology • Mumbai

On-site
INR 4,000,000 - 7,000,000
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Mumbai

On-site
INR 800,000 - 1,400,000
Job Role : Manager/ Assistant Manager – Offensive Security Expert- Red Team
Job Role : Manager/ Assistant Manager – Offensive Security Expert- Red Team

Multi Commodity Exchange Clearing Corporation Limited (MCXCCL • Mumbai

On-site
INR 1,500,000 - 2,800,000
239939-Manager
239939-Manager

EXL • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000