Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
A leading company in cybersecurity compliance is seeking an experienced Director of Penetration Testing to lead their team. The role includes strategic leadership and overseeing all penetration testing operations, requiring extensive experience and specific certifications. This position offers a competitive salary, professional development opportunities, and a flexible work environment.
Insight Assurance is considered one of the fastest-growing companies focusing on cybersecurity compliance. The company is a Florida-registered and licensed CPA firm, PCI Qualified Security Assessor (QSA), and ISO 27001 Certification Body founded by former Big-4 professionals (Former EY), looking to simplify the world of IT compliance. With over 20 years of professional experience working with hundreds of organizations from startups to Fortune 500 companies on a variety of engagements, the team at Insight Assurance partners with organizations looking to meet their organizational and compliance goals.
JOB PURPOSE
We are seeking a highly experienced and strategic Director of Penetration Testing to lead our penetration testing department. This leadership role is responsible for overseeing all aspects of the team’s operations, strategy, and technical delivery. The ideal candidate will bring over 5 years of professional experience in penetration testing, including at least 3 years in a leadership or managerial role. The Director will be responsible for building and mentoring a high-performing team, developing testing methodologies, ensuring service excellence, and aligning the team's objectives with broader organizational goals.
KEY RESPONSIBILITIES
Strategic & Team Leadership
Lead and manage the penetration testing department, including hiring, mentoring, performance management, and resource planning
Define departmental goals and key performance indicators in alignment with company objectives
Establish and continuously improve testing methodologies, quality assurance standards, and operational workflows
Serve as the primary point of contact for executive leadership on penetration testing matters
Technical Leadership & Execution
Oversee and participate in complex penetration tests on enterprise networks, systems, applications, and cloud environments
Lead red team engagements, social engineering campaigns, and simulated real-world attacks
Ensure technical accuracy and completeness of all team deliverables and reports
Stay up to date with evolving threat landscapes, attack vectors, and security technologies to continuously innovate service offerings
Stakeholder Communication
Deliver clear, impactful reports and presentations for both technical teams and executive stakeholders
Translate findings into actionable recommendations and risk mitigation strategies
Collaborate with IT, GRC, SOC, and security operations teams to guide remediation efforts
Compliance & Risk
Ensure the team's activities align with industry standards and regulatory frameworks such as PCI-DSS, HIPAA, and NIST
Develop, maintain, and enforce penetration testing policies and procedures
REQUIREMENTS
Education & Experience
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field
At least 5 years of hands-on penetration testing experience, including web, network, social engineering, and red team assessments
Minimum 3 years of experience managing or leading technical teams in a cybersecurity context
Proven track record of successfully delivering enterprise-level security testing projects
Experience with exploit development and advanced attack simulation is a plus
Certifications (Required or Strongly Preferred)
OSCP (required)
OSCE, OSWE, OSEP, or similar advanced certifications (preferred)
TECHNICAL SKILLS
Expert-level knowledge of penetration testing tools (e.g., Metasploit, Burp Suite, OWASP ZAP, Cobalt Strike)
Deep understanding of network protocols, operating systems (Windows, Linux), and cloud infrastructure (AWS, Azure, GCP)
Strong command of scripting and programming (Python, Bash, PowerShell, etc.)
Experience with risk analysis and vulnerability management
Exceptional written and verbal communication skills, including the ability to write detailed technical reports for diverse audiences
OTHER REQUIREMENTS
U.S. Citizenship or eligibility to obtain necessary security clearances (if applicable)
Ability to travel up to 25% if needed
Demonstrated leadership, strategic thinking, and ability to operate in a fast-paced environment
High level of integrity and discretion when handling sensitive information
Benefits
- Competitive Salary
- Flexible Paid Time Off and paid holidays
- Performance Bonuses
- Flexible remote work environment
- Opportunities for professional development and growth
- Supportive team culture
Privacy Notice CCPA :
Privacy Notice GDPR:
This notice informs you about the categories of Personal Data/ Information and the Purpose and Scope of Processing Activities to be undertaken by Insight Assurance (we, us, our), under its job application and recruitment process.
We resort to Greenhouse.com as the platform that supports our recruitment process, and therefore your Personal Data/ Information will be Processed on this tool (hosted, shared with, cross-referenced, accessed by our team); we have in place contractual terms and the commitment of Greenhouse.com that ensures the Security and Confidentiality plus Purpose limitation with regards to the Processing of your Personal Data.
When you reply to one of your job postings, you voluntarily and freely submit your Personal Data to us; this, allied with the fact that the Processing by us (and over Greenhouse.com) of that Personal Data has the sole Purpose of validating your application and proceeding with the inherent scrutiny and decision, allows us to argue having Legitimate Interest as the applicable Legal Basis to undertake the Processing of your Personal Data under this scope.
We are a U.S. based company, hence some or all Personal Data pertaining to you will be hosted in the U.S.
The categories of Personal Data under Processing consist of:
You may exercise several Rights as determined under applicable Personal Data Protection legislation, in short:
*
indicates a required field
First Name *
Last Name *
Email *
Phone *
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Education
School * Select...
Degree * Select...
Select...
LinkedIn Profile
Fiscal or Tax Residency * Select...
Which country do you currently reside in? * Select...
Years of experience relevant to the position * Select...
Do you have any certifications? *
What is your salary expectation in USD? *