
Manager – Offensive Cybersecurity, Penetration Testing
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in California.
• Lead and manage penetration testing initiatives across enterprise applications, systems, networks, cloud platforms, and other relevant environments.
• Define the scope, methodology, and priorities for testing based on business risks, threat intelligence, and organizational goals.
• Validate vulnerabilities and attack paths through manual testing, proof-of-concept development, and adversary emulation techniques.
• Collaborate with engineering, infrastructure, and application teams to communicate findings, assist with remediation, and enhance overall security posture.
• Lead, mentor, and develop team members to bolster offensive security capabilities and technical expertise.
• Establish and refine offensive security processes, methodologies, reporting standards, and quality controls.
• Create metrics and reports to convey testing coverage, trends in findings, remediation progress, and program effectiveness to leadership.
• Work with cross-functional stakeholders to prioritize testing activities and support secure design and remediation efforts.
• Develop or modify proof-of-concept exploits to validate vulnerabilities and evaluate potential business impacts.
• Create repeatable assessment and reporting processes that support audit, compliance, and governance requirements.
• Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
• OSCP, OSEP, CRTP, CEH, CPT, CEPT, GPEN or other recognized industry-standard penetration testing certification(s) are required.
• 7+ years of combined IT and security experience with extensive exposure to systems analysis, application development, database design, networking, administration, identity, or related responsibilities preferred.
• 5+ years of experience in information security is required.
• 3+ years of experience in conducting penetration testing is required.
• Ability to work autonomously and troubleshoot technical and business process-related issues.
• Subject matter expertise across the entire information security stack.
• Capability to develop technical testing solutions for internal use.
• Ability to analyze and scope vulnerability disclosures and CVEs.
• Expertise in OWASP.
• Experience leading penetration testing programs or engagements within a large enterprise setting.
• Strong understanding of threat vectors and containment strategies.
• Knowledge of Active Directory discovery, enumeration, and exploitation methods.
• Experience assessing cloud environments (AWS, Azure, GCP), including common misconfigurations, attack vectors, and defensive controls.
• Exceptional written and verbal communication skills, with the ability to present technical findings to both technical and non-technical audiences.
• Experience with various up-to-date Endpoint Detection and Response solutions.
• Knowledge of Vulnerability Management concepts and best practices.
• Familiarity with Windows, Linux, Mac OS, and mobile operating systems.
• Expertise in networking concepts, protocols, and encryption.
• Proficiency in application security practices and tools.
• Expertise in programming/scripting languages such as Python, PowerShell, Bash, C/C++/C#.
• Proficiency in Metasploit or similar tools.
• Expertise in penetration testing security tools such as Kali Linux.
• Proficiency in Burp Suite or similar tools.
• Experience working in a purple team environment.
• Discretionary annual bonus.
• Group health insurance benefits (medical, vision, dental).
• FSA and HSA healthcare accounts.
• Life and accident insurance.
• Adoption and fertility assistance.
• Paid parental leave of up to 6 weeks.
• Short and long-term disability.
• Paid time off for vacation, personal needs, and sick leave.
• Up to 17 days of Choice Time Off (CTO) per calendar year for new hires.
• Up to 11 paid holidays each calendar year.
• 401(k) savings and investment plan or deferred compensation plan (if eligible).
• Employer match of 100% on the first 3% of contributions for eligible employees.
• Reasonable accommodation assistance for applicants with disabilities.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.