Senior Manager Offensive Security

Asurion

Nashville (TN)

On-site

USD 170,000 - 230,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Asurion seeks a Senior Manager, Offensive Security to lead our offensive testing program across web, mobile, APIs, cloud, and infrastructure. This leader balances hands-on direction with people management, driving risk-based testing, reporting, and remediation with cross-functional partners in engineering and security.

You will scale a high‑performing team, set engagement standards, and evolve testing through AI-enabled methods while preserving rigorous analysis and actionable outcomes for

Qualifications

  • Bachelor's degree in information security, computer science, IT, engineering, or equivalent practical experience.
  • 8+ years in information security, with 5+ years in penetration testing or red team.
  • 3+ years leading technical teams or engagements with direct people management.

Responsibilities

  • Own end-to-end penetration testing intake and delivery pipeline; triage based on risk and timelines.
  • Oversee execution of tests across web, API, cloud, network, and infrastructure; ensure quality and actionable remediation guidance.
  • Lead, coach, and grow a team of testers and offensive security engineers.
  • Produce clear, decision-oriented reporting on findings, trends, and remediation progress.
  • Partner with development, DevOps, cloud, and infrastructure teams to prioritize and remediate findings.
  • Explore, pilot, and mature agentic AI-enabled testing while maintaining human judgment.
  • Maintain testing standards and documentation; align with broader security program and audit needs.

Skills

Penetration testing
Offensive security
Team leadership
Cloud security
API testing
NIST SP 800-115

Education

Bachelor's degree in Information Security

Tools

Burp Suite
Nmap
Metasploit
Cobalt Strike

Job description

The Senior Manager, Offensive Security leads Asurion's offensive security testing function. Reporting to the Director of Application & Offensive Security, this leader is accountable for the intake, prioritization, execution, and quality of penetration testing across web and mobile applications, APIs, cloud environments, internal and external infrastructure, and supporting business services. This position balances hands‑on technical leadership with people management, ensuring engagements are scoped effectively, delivered on schedule, and reported with findings that drive measurable risk reduction. The Senior Manager translates technical results into clear business risk for engineering, product, and security leadership, and partners closely with development, cloud, and infrastructure teams to ensure findings are understood and remediated.

Key Responsibilities
  • Penetration Testing Operations and Queue Management: Own the end‑to‑end penetration testing intake and delivery pipeline. Manage the testing queue, triage and prioritize incoming requests based on risk, business criticality, regulatory drivers, and release timelines, and balance workload across the team to meet commitments. Establish and maintain a repeatable engagement lifecycle covering scoping, rules of engagement, execution, reporting, retesting, and closure.
  • Technical Delivery and Quality Assurance: Oversee the execution of application, API, mobile, cloud, network, and infrastructure penetration tests. Set standards for testing rigor, evidence collection, exploit validation, and finding reproducibility. Review deliverables for technical accuracy, clarity, and actionable remediation guidance, and personally lead or contribute to complex, high‑sensitivity engagements when needed.
  • People Leadership and Team Development: Manage, coach, and grow a team of penetration testers and offensive security engineers. Set clear goals and performance expectations, provide regular feedback, support career development and technical skill growth, and cultivate a culture of curiosity, integrity, and continuous learning.
  • Risk Reporting and Stakeholder CommunicatiSenior Manager, Offensive Securityon: Produce clear, decision‑oriented reporting on penetration testing outcomes, trends, systemic weaknesses, and remediation progress. Translate technical findings into business risk language for engineering leaders, product owners, and security leadership. Track findings to closure, support risk acceptance and exception decisions where appropriate, and contribute to consolidated security reporting and metrics that demonstrate the program's impact.
  • Remediation Partnership and Secure Development Enablement: Partner with application development, DevOps, cloud, and infrastructure teams to ensure findings are understood, prioritized, and remediated. Provide guidance on root cause and durable fixes rather than one‑off patches, and feed recurring patterns back into secure SDLC practices, threat modeling, and developer education.
  • Agentic and AI‑Enabled Testing (Emerging Focus): Explore, pilot, and progressively develop an agentic penetration testing capability. Evaluate AI‑assisted and autonomous offensive security tooling, define where automation can safely and effectively extend coverage, establish guardrails and validation processes for AI‑generated findings, and build a roadmap that matures this capability over time while preserving the judgment and depth of human testers. Stay current on the evolving offensive AI landscape and represent Asurion's forward‑looking approach to internal stakeholders.
  • Program Governance and Continuous Improvement: Maintain testing standards, tooling, and documentation, and continuously improve throughput, coverage, and quality. Ensure the program supports audit, compliance, and regulatory requirements, and coordinate with vulnerability management, exposure management, and incident response functions to align offensive testing with the broader security program.
Education And Experience
  • Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 8+ years of experience in information security, with 5+ years focused on penetration testing, offensive security, or red team operations.
  • 3+ years of experience leading technical teams or engagements, including direct people management, workload prioritization, and delivery accountability.
  • Demonstrated experience scoping and executing penetration tests across multiple domains such as web and mobile applications, APIs, cloud platforms, and internal/external network infrastructure.
  • Experience translating technical findings into executive- and business-level risk communications and driving remediation with engineering partners.
  • Preferred: Experience building or scaling a penetration testing function; familiarity with AI‑assisted, autonomous, or agentic security tooling; regulated industry experience (e.g., financial services, insurance, healthcare, technology, or critical infrastructure); and contribution to secure SDLC and developer enablement initiatives.
Knowledge, Skills, And Abilities
  • Deep technical fluency in offensive security across application security and secure SDLC, cloud security, API and integration security, network and infrastructure testing, identity and access exploitation, and post‑exploitation techniques.
  • Working command of recognized testing methodologies and standards, including NIST SP 800-115, PTES, the OWASP testing guides (including the OWASP Top 10 and API Security Top 10), and MITRE ATT&CK.
  • Strong understanding of detection engineering, EDR bypass, and purple teaming to improve control efficacy.
  • Familiarity with the NICE Workforce Framework for Cybersecurity (NIST SP 800-181) to help define penetration testing competencies, role expectations, and skill development paths for the team.
  • Hands‑on proficiency with common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Cobalt Strike or equivalent, cloud‑native testing tools) and comfort scripting and automating with languages such as Python.
  • Strong risk judgment and the ability to distinguish theoretical weaknesses from material, exploitable business risk, and to recommend pragmatic, prioritized remediation.
  • Effective people leadership, including coaching, performance management, capacity planning, and the ability to attract, grow, and retain highly skilled technical talent.
  • Clear written and verbal communication skills, with the ability to produce concise, decision‑oriented reporting and influence engineering and security stakeholders without direct authority.
  • Curiosity and adaptability to evaluate emerging capabilities, including AI‑enabled and agentic testing, and to responsibly integrate new methods into an established program.
  • Ownership mindset to drive engagements and findings to closure, maintain quality under resource constraints, and ensure transparent, well‑documented risk decisions.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager Offensive Security
Senior Manager Offensive Security

Asurion • Smyrna (GA)

On-site
USD 150,000 - 190,000
Health insurance
Paid time off
Senior Offensive Security Lead & Pen Testing
Senior Offensive Security Lead & Pen Testing

Asurion • Nashville (TN)

On-site
USD 170,000 - 230,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Application Offensive Security Consultant
Application Offensive Security Consultant

Pipe Recruit • Jersey City (NJ)

Hybrid
USD 83,000 - 165,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Lead Penetration Tester
Lead Penetration Tester

Infinite Ranges • United States

Remote
USD 138,000 - 248,000
Senior Manager, Offensive Security
Senior Manager, Offensive Security

Vanguard • Dallas (TX)

Hybrid
USD 180,000 - 240,000
Sr Application Security Engineer - AI-First Development
Sr Application Security Engineer - AI-First Development

Las Vegas Sands Corp. • United States

On-site
USD 120,000 - 150,000
Offensive Security Consultant / Penetration Tester
Offensive Security Consultant / Penetration Tester

HALOCK Security Labs • Schaumburg (IL)

On-site
USD 120,000 - 180,000