About this role
Job Description
WHAT YOU'LL DO:
Vulnerability Assessment & Management
- Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.
- Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.
- Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.
- Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.
Penetration Testing & Red Teaming
- Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.
- Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.
- Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.
Threat Intelligence & Threat Hunting
- Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).
- Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.
- Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.
Stakeholder Management & Strategic Leadership
- Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.
- Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.
- Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).
Team Leadership and Development
- Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers.
- Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.
- Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.
WHO YOU ARE:
- 10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.
- Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling
- Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.
- Bachelor's degree in Computer Science, Information Security, or a related technical field.
- Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.
- Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.