Assistant Vice President Cybersecurity - Offensive Security Lead

EXL

Jersey City (NJ)

On-site

USD 125,000 - 150,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Comprehensive health benefits
Flexible work environment

Job summary

A leading operations management company is seeking an AVP Cybersecurity to lead offensive security engagements, including red team operations and vulnerability assessments. The ideal candidate will have over 8 years of experience in cybersecurity, along with recognized qualifications in red teaming and strong knowledge of cloud platforms. This role emphasizes collaboration with multiple teams to enhance security measures and client recommendations. Join us at our location in Jersey City to push the envelope in cybersecurity practices.

Qualifications

  • 8+ years of work experience in cybersecurity.
  • Recognized certifications in Red Teaming or Penetration Testing.
  • Expertise in Windows Active Directory and cloud security.

Responsibilities

  • Lead red team operations and engagement planning.
  • Conduct offensive security assessments against multiple environments.
  • Collaborate with cross-functional teams to drive remediation efforts.

Skills

Red Team operations
Adversarial simulation
Cyber risk assessments
Technical communication

Education

Bachelor’s degree or higher in IT or related field
Master's degree in Information Systems or related field

Tools

AWS
Azure
Docker
Kubernetes

Job description

About EXL: EXL (NASDAQ:EXLS) is a leading operations management and analytics company that helps businesses enhance growth and profitability in the face of relentless competition and continuous disruption. Using our proprietary, award-winning methodologies, that integrate advanced analytics, data management, digital, BPO, consulting, industry best practices and technology platforms, we look deeper to help companies improve global operations, enhance data-driven insights, increase customer satisfaction, and manage risk and compliance. EXL serves the insurance, healthcare, banking and financial services, utilities, travel, transportation and logistics industries. Headquartered in New York, New York, EXL has more than 60,000+ professionals in locations throughout the United States, Europe, Asia (primarily India and Philippines), Latin America, Australia and South Africa.

AVP Cybersecurity on the Offensive Security lead is focused on assessing and challenging the security posture across a comprehensive portfolio of products, services and infrastructure. The individual will utilize a variety of tools developed and act as a key team member and leader in testing engagements. They will advocate for cybersecurity best practices and will provide strong recommendations in this domain

  • Conduct red team operations by serving either the red team lead or the secondary operator on engagements. As an engagement red team lead, you'll strategically plan scenario execution, orchestrate team resources and timelines, and make critical technical decisions that drive successful outcomes in complex, high-stakes environments
  • Conduct offensive security engagements, including Red Team operations, threat-based evaluations, and vulnerability research and exploitation against both internal and external facing system
  • Design, scope, and lead complex technical assessments, Purple Team Engagements, and other security initiatives to test attack detection and prevention effectiveness
  • Automate portions of assessments, scoping, or other offensive security work to inform and drive our engagement
  • Incorporate Threat Intelligence research to track APT trends and help partners test their environments against new and emerging threat
  • Collaborate with cross-functional teams, including Incident Response, Product Security, and other security partners, to align remediation efforts and drive fixes after testing cycle
  • Develop and maintain relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work
  • Influence and align the team’s strategy, and collaboratively prioritize and deliver specific multi-year roadmaps and projects
  • Leverage deep technical expertise in operating systems, network architecture, and infrastructure fundamentals to execute sophisticated attack chains and navigate complex enterprise environments during red team operations
  • Pioneer cutting-edge offensive security capabilities in coordination with our dedicated malware and capability developers by researching, developing, and operationalizing innovative techniques, proprietary tools, and advanced methodologies that push the boundaries of adversarial simulation and red team effectiveness
  • Offer mentorship or coaching to growing team members, while sharing knowledge externally through blogs, webinar presentations, or presenting at conferences
  • Collaborate with cross-functional teams on key activities, including scoping initiatives, providing subject matter expertise in high-stakes sales presentations, and contributing strategic technical insights to marketing campaigns that showcase our capabilities
  • Help define, document, and continuously refine internal technical processes, service methodologies, and tactical procedures (TTPs) that standardize excellence across all engagements
  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations
  • Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience
  • 8+ years of work experience performing adversarial simulation related engagements, with overall experience of 10-15 year
  • Recognized Red Team or Penetration testing specific qualifications such as CCSAS, CCSAM, CRTO, OSED, OSCE (GXPN, GPEN, OSCP, GWAPT or similar certifications may also be considered
  • Working knowledge of Windows, Linux and MacOS operating systems
  • Extensive understanding of the MITRE ATT&CK framework, OWASP Top 10, and other security frameworks
  • Expertise in Windows Active Directory exploitation and lateral movement
  • Working knowledge of cloud platforms (AWS/Azure/GCP and O365/Google Workspace) and container technologies (Kubernetes/Docker)
  • Able to conduct cyber risk assessments using frameworks or standards like NIST CSF, ISO 27001/2, PCI, CIS Top 20, CMMC, or other industry measurement tool
  • Conduct cloud penetration testing engagements to assess specific workloads (i.e., AWS, GCP, Azure, containers, or other PaaS and SaaS instances) for vulnerabilities and subsequently attempt to exploit identified weaknesses after receiving permission from client stakeholder
  • Provide recommendations to clients on specific security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks including response and recovery of a data security breach
  • Familiarity with offensive tools, based on applicable skillset
  • Deep technical familiarity with offensive and defensive IT concepts and protocol
  • Research and evaluate emerging privacy technologies from academia and industry, contributing to open-source tools and AI privacy standards
  • Act as consultant and advocate for privacy best practices as central to our mission of Responsible A

Preferred Qualifications

  • Strong communicator with the ability to positively influence engineers, developers, architects, and business leaders alike
  • Thoughtful, pragmatic, and able to execute in a high-velocity, agile environment
  • Deeply collaborative and experienced at embedding security into developer culture
  • Track record of reducing risk without slowing down innovation
  • Being articulate and precise to the internal stakeholders who are seeking counsel on what are the risks, why are they impactful, and options on how to resolve them
  • Broad knowledge across the Security domain, with focus in AI security evaluations and in one or more areas of Cybersecurity such as Red Teaming, Purple Teaming, Vulnerability Research, and Exploitation
  • Master's degree (or foreign degree equivalent) in Information Systems Engineering, Computer Science, Engineering, Information Security, Cyber Security, Information Assurance, or related field

Salary Range: 125K-15

For more information on benefits and what we offer please visit us at https://www.exlservice.com/us-careers-and-benefits

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Vice President Cybersecurity (Healthcare & Life Sciences)
Assistant Vice President Cybersecurity (Healthcare & Life Sciences)

EXL • Jersey City (NJ)

On-site
USD 125,000 - 160,000
Comprehensive benefits package
Mentorship opportunities
Senior Assistant Vice President- Application & Cloud Security
Senior Assistant Vice President- Application & Cloud Security

EXL • Jersey City (NJ)

On-site
USD 125,000 - 155,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Senior Account Executive, Offensive Security Services Consulting | New England & Canada
Senior Account Executive, Offensive Security Services Consulting | New England & Canada

UltraViolet Cyber • Rhode Island

On-site
USD 120,000 - 180,000
401(k) with employer match
Medical, Dental, and Vision insurance
Paid holidays
+2
Sales Executive, Offensive Security Services Consulting | Southwest
Sales Executive, Offensive Security Services Consulting | Southwest

UltraViolet Cyber • Arizona

Hybrid
USD 120,000 - 170,000
401(k) with employer match
Medical, Dental, and Vision insurance
11 Paid Holidays Annually
Sales Executive, Offensive Security Services Consulting | Southwest
Sales Executive, Offensive Security Services Consulting | Southwest

UltraViolet Cyber • New Mexico

Remote
USD 120,000 - 190,000
401(k) with employer match
Health, Dental, and Vision insurance
Discretionary Time Off (DTO) Program
+1
Sales Executive, Offensive Security Services Consulting | Southwest
Sales Executive, Offensive Security Services Consulting | Southwest

UltraViolet Cyber • California (MO)

On-site
USD 80,000 - 120,000
401(k) with employer match
Medical, Dental, and Vision insurance
Discretionary Time Off (DTO)
+1
Sales Executive, Offensive Security Services Consulting | Southwest
Sales Executive, Offensive Security Services Consulting | Southwest

UltraViolet Cyber • Colorado

On-site
USD 80,000 - 120,000
401(k) with employer match
Medical, Dental, and Vision insurance
Discretionary Time Off (DTO)
+1
Vice President, Global Cyber Exposure Management & Cyber Engineering and Architecture
Vice President, Global Cyber Exposure Management & Cyber Engineering and Architecture

Wolters Kluwer • Chicago (IL)

On-site
USD 226,000 - 340,000
Medical, Dental, & Vision Plans
401(k)
Tuition Assistance Plan
+1
Vice President, Global Cyber Exposure Management & Cyber Engineering and Architecture
Vice President, Global Cyber Exposure Management & Cyber Engineering and Architecture

Mass Digital Health • Waltham (MA)

On-site
USD 226,000 - 340,000
Medical, Dental, & Vision Plans
401(k)
Tuition Assistance Plan
+1