Job Description
As a Senior Manager of the Attack Surface Reduction (ASR) Team ,you will lead an elite squad of highly technical security researchers andpenetration testers. In the high-stakes environment of a Managed SecurityService Provider (MSSP), this team is the frontline of defence and offense forour global clients.
You will be responsible for the end-to-end delivery of advanced securityassessments, ranging from automated attack surface discovery to manual"Red Team" operations. This is a leadership role that requires technicaldepth, as you will guide experts in breaking into some of the most complexenvironments in the world to ensure they are unshakeable.
Key Responsibilities
- TeamLeadership: Lead, mentor, and scale ahigh-performance team of technical specialists. Foster a culture ofcontinuous research, curiosity, and ethical hacking excellence.
- Full-SpectrumAssessments: Oversee the execution of comprehensivesecurity evaluations, both internally and externally for our clientportfolio:
- Application Security: DAST, SAST, SCA, bothBlack Box and Grey Box and deep-dive API security testing.
- Offensive Operations: Red Teaming, AdversarialSimulations, and Breach & Attack Simulation (BAS).
- Vulnerability Management: Advanced VAPT(Vulnerability Assessment & Penetration Testing)
- Defensive Validation & Resiliency Testing: Ransomware Resiliency testing to ensure clients can withstand and recoverfrom modern extortion tactics.
- AttackSurface Discovery: Direct the continuous mapping of knownand unknown digital assets to identify shadow IT and exposed entry points.
- ServiceInnovation: Develop and refine the MSSP service catalogue.Identify emerging threats and translate them into new testingmethodologies and cybersecurity services.
- StakeholderManagement: Act as the technical authority duringhigh-level client briefings, translating complex technical findings intoactionable executive risk reports.
Requirements
Technical Requirements
- Experience: 10+years in Offensive Security, with at least 3–5 years in a formalleadership/management role.
- Expertise: Deeptechnical mastery of the "Attacker Mindset." You should becomfortable discussing advanced exploitation techniques, CI/CD pipelinevulnerabilities, and hybrid or cloud-native lateral movement in the samebreath.
- Tooling& Frameworks: Proficiency in modern toolkits (BurpSuite, Metasploit, Cobalt Strike, etc.).
- Expertisein BAS platforms and Attack Surface Management (ASM) tools.
- Experience with Cloud Security (AWS/Azure/GCP) and container security(Docker/K8s).
- Firm grasp of the MITRE ATT&CK framework.
- Certifications: Preferred: OSCE, OSEP, GXPN, or CISSP/CCSP/CISM.
Required Development & Automation Skills
- Security ToolingDevelopment: Proficiency in Python or Go (Golang) to build customscanners, exploit wrappers, and automation scripts.
- Infrastructure as Code(IaC): Solid understanding of Terraform or Ansible to rapidly spin up (andtear down) complex "range" environments for Red Team simulationsand Ransomware Resiliency testing.
- Dev-Sec-Ops & CI/CDIntegration: Deep knowledge of how to integrate SAST/DAST/SCA toolsdirectly into GitLab, GitHub Actions, or Jenkins pipelines withoutbreaking the developer workflow.
- API Mastery: Advancedability to interact with, test, and develop against RESTful and Graph-QLAPIs. This includes writing custom scripts to automate mass APIvulnerability discovery.
- Cloud-NativeDevelopment: Familiarity with Serverless (AWS Lambda/Azure Functions) andContainerization (Docker/Kubernetes) to identify and exploitmisconfigurations in modern microservices architectures.
- Exploit DevelopmentBasics: Understanding of low-level languages like C/C++ or Rust to overseethe team when they are performing deep-dive binary analysis or bypassresearch.
- Data Engineering forSecurity: Ability to work with SQL/NoSQL and ELK stacks (Elasticsearch,Logstash, Kibana) to aggregate and analyse the massive amounts of datagenerated during Attack Surface Discovery.
- Candor& Clarity: The ability to give direct, constructivefeedback to a highly technical team while maintaining high morale.
- StrategicVision: Moving beyond "finding bugs" to helping clients buildlong-term Resilience Frameworks .
Key Traits
- Technical Depth: You must be able to "speak the language" ofhighly technical researchers to earn their respect and provide valid guidance.
- PressureManagement: Thriving in the fast-paced, 24/7 nature of anMSSP.
Why Join Us?
You aren't just managing a team; you are architecting the future of offensivesecurity. You will have access to diverse environments, cutting-edge"Advanced Technologies," and you’ll drive red-team strategies and emulatereal-world adversaries to ensure clients stay ahead of the global threatlandscape.