
Cybersecurity Lead, Pentesting
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Develop and implement the cybersecurity strategy for both corporate and client needs.
• Evaluate risks, identify control deficiencies, assess technology exposure, and determine security maturity levels.
• Organize and conduct penetration testing across web, API, mobile, infrastructure, cloud, wireless networks, and internal environments.
• Establish rules of engagement, define scope, obtain necessary authorizations, set risk criteria, and manage evidence handling.
• Create executive and technical reports that include reproducible findings, impacts, evidence, and prioritized recommendations.
• Deliver presentations of results to senior management and clients.
• Oversee purple team activities, threat hunting, and validation exercises using the MITRE ATT&CK framework.
• Evaluate risks associated with artificial intelligence and machine learning utilizing the MITRE ATLAS framework.
• Execute and assess cybersecurity controls.
• Manage vulnerabilities, develop treatment plans, handle exceptions, and track remediation efforts.
• Define capabilities for monitoring, incident response, business continuity, and recovery.
• Assist in audits, certifications, commercial processes, and client engagements.
• Maintain methodologies, templates, playbooks, evidence, and a knowledge base.
• Foster a culture of security through both technical and executive-level training.
• A professional degree in Systems Engineering, Telecommunications, Cybersecurity, or a related field.
• Over 5 years of experience in offensive security, risk management, or security architecture.
• Proven experience in leading client assessments and presenting findings to senior management.
• Familiarity with networks, operating systems, cloud technologies, APIs, DevSecOps, IAM, cryptography, and application security.
• Experience with PTES, OWASP Testing Guide, OWASP ASVS, and CVSS methodologies.
• Proficient in frameworks such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001/27002, MITRE ATT&CK, and MITRE ATLAS.
• Experience in leading cybersecurity teams.
• Knowledge of international standards and regulations.
• Continuing Education Campus: an in-house platform offering courses, training, and certifications across various IT disciplines.
• Partnerships with healthcare providers for prepaid and in-home medical care, providing preferential rates.
• Recognition for performance and tenure.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.