Cybersecurity Advisors Network (CyAN) logo
Cybersecurity Advisors Network (CyAN)

An international community of cyber advisors from various disciplines and background, who want to build a better future

Senior Manager – Offensive Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1-10Since 2015H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

8 days ago

Salary

$150K - $185K / year

Seniority

Senior

Bachelor Degree5 yrs expExperience acceptedEnglishCyber SecurityFirewallsLinuxUnix

Job Description

Senior Manager – Offensive Security

Cybersecurity Advisors Network (CyAN)

• mature, lead and deliver the firm’s service offerings around system-wide views of threat-driven risks and applying them to the testing of systems and services that the firm delivers. • Partner with sales and delivery teams to support pre-sales engagements, scope assessments, and solution development efforts • Mentor and develop managers, leads, and senior consultants • Influence hiring standards, interview calibration, and onboarding for senior technical roles within the practice • Define and maintain practice playbooks, severity models, and exploitation guidelines • Lead offensive security team members for Cyber Advisors, maximizing the efforts and satisfaction of all offensive security team members. • Mature the program and methodology that shapes how Cyber Advisors approaches Threat Emulation, to include defining the rules and parameters for ethical hacking of systems, software and networks to identify and mitigate potential vulnerabilities • Set direction and oversee the performance of penetration tests and Threat Emulation simulations on targets across all Cyber Advisors partners and customers • Assisting in the sales process with potential or existing clients, and acting as a client’s primary program contact for projects delivered by Cyber Advisors’ Threat Emulation team • As necessary, perform scoped and open-ended assessments on internal and external facing systems • Perform threat and vulnerability research to identify new ways of achieving the program’s mission and act as a source for innovation within the cybersecurity industry • Participate and contribute to Cyber Advisors’ social media presence on various platforms

Job Requirements

  • Bachelor’s degree or equivalent in Computer Engineering, Computer Science or a related field of study or at least 5 years of progressively responsible experience performing network and application security assessments and/or Cyber Red Team operations.
  • prior experience performing application and network penetration tests, vulnerability assessments, infrastructure security reviews for web applications and their supporting network infrastructure and red team assessments that have tested security processes and controls.
  • Work collaboratively with a variety of internal and external stakeholders (security consultants, project managers, service managers, development teams, technical SME’s, vendors) to deliver high quality assessments.
  • Strong understanding of and experience with Windows/Linux/Unix operating systems
  • Networking fundamentals (all OSI layers, protocols, etc.)
  • Operating system and software vulnerabilities and exploitation techniques
  • Web and mobile application vulnerabilities and exploitation techniques
  • Malware packing, obfuscation, persistence, exfiltration techniques
  • Security technologies such as Firewalls, IDS/IPS, Web Proxies and DLP amongst others
  • Commercial or open-source offensive security tools for reconnaissance, scanning, exploitation and post-exploitation (e.g. Nmap, Nessus, Metasploit, Burp Suite, etc.)
  • Project Management
  • Demonstrated leader with team-oriented interpersonal skills, with the ability to interface effectively upper management, IT leadership and technology vendors.
  • Develop and implement processes and/or tools that assist with execution of security assessments, including custom tools and automation
  • Ability to collaborate and build positive relationships across multiple stakeholders
  • Agile thinking and analysis that leads to win-win and innovative solutions
  • Strong written and verbal communication skills.
  • Calmness and clarity of thought under pressure and ability to maintain confidentiality.
  • Ability to prepare and present project ideas and proposals to senior management
  • Understanding of financial sector, or other large organization, security and IT infrastructures
  • Willingness to work non-standard hours, if necessary

Benefits

  • PTO and 8 Paid Holidays
  • Employer-paid Health and Dental Insurance for CA employees
  • Great opportunities for career advancement
  • 401k with employer matching
  • Disability and Life Insurance

Related Categories

Related Job Pages

More Security Engineer Jobs

Docusign logo

Senior Security Risk Manager

Docusign

Bringing Agreements to Life

Full TimeHybridTeam 5,001-10,000Since 2003H1B Sponsor

Title: Senior Security Risk Manager Location: San Francisco United States Job Description: Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign's Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM). What you'll do Docusign is looking for a Senior Security Risk Manager to join our Security Governance, Risk & Compliance (GRC) team. In this hands-on role, you will lead and manage modern, data-driven security risk assessments and play a pivotal role in advancing the maturity of our Security Risk Management program. This position is an individual contributor role reporting to the Director of Security Product Risk Management. Responsibility - Lead end-to-end security risk assessments of applications, systems, and cloud and software environments, across all security domains leveraging advanced risk scoring models such as risk quantification - Identify, assess, monitor, and report on security risks across the enterprise and within specific domains (e.g. Vulnerability Management, Third Party Risk, Product Security, Detection and Response, etc.) - Review holistically Risk, Control, and Issue data to culminate recommendations on top security investments across the enterprise - Analyze risk data to identify trends, root causes, and control gaps, and recommend changes to strengthen controls - Partner with Engineering, Security, and business teams to embed risk insights into planning, prioritization, and decision-making - Develop and maintain risk dashboards and metrics that provide leadership with actionable insights into risk exposure and trends within their portfolio - Maintain and evolve the security control framework, ensuring risks are effectively mapped to controls, and are relevant to the business - Provide recommendations on risk acceptance and mitigation that balances business objectives with security requirements - Leverage modern GRC platforms and automation (e.g., ServiceNow IRM, OneTrust) to scale risk management processes - Serve as a trusted advisor to leadership on security risk posture and decisions - Stay ahead of emerging risks and industry trends to continuously improve risk practices Job Designation Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation) Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring Basic - 8+ years experience in security risk management, GRC, or related fields - Bachelor's degree in Computer Science, Information Security, or related field - Experience with cyber threats and vulnerabilities, with hands-on expertise in one or more security domains (e.g., vulnerability management, insider risk, incident response, identity and access management, application, infrastructure, cloud, product, platform, data and AI security) - Experience with cloud environments (AWS, Azure, GCP) and SaaS platforms - Experience with risk management frameworks, risk quantification models (e.g., FAIR) or building custom risk scoring approaches - Background with security risk assessments, controls, and threat analysis. - Strong experience with GRC platforms and automation tools, preferably ServiceNow IRM. - One or more certifications: CISSP, CRISC, CISM - Excellent communication and stakeholder management skills Preferred - Experience as a security risk SME or security architect - Familiarity with cloud and SaaS environments (AWS, Azure, GCP) - Experience managing or mentoring junior GRC professionals - Experience building risk dashboards and metrics (e.g., Tableau, Power BI) Wage Transparency Pay for this position is based on a number of factors including geographic location and may vary depending on job-related knowledge, skills, and experience. Based on applicable legislation, the below details pay ranges in the following locations: California: $146,400.00 - $235,375.00 base salary This role is also eligible for the following: - Bonus: Sales personnel are eligible for variable incentive pay dependent on their achievement of pre-established sales goals. Non-Sales roles are eligible for a company bonus plan, which is calculated as a percentage of eligible wages and dependent on company performance. - Stock: This role is eligible to receive Restricted Stock Units (RSUs). Global benefits provide options for the following: - Paid Time Off: earned time off, as well as paid company holidays based on region - Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement - Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment - Retirement Plans: select retirement and pension programs with potential for employer contributions - Learning and Development: options for coaching, online courses and education reimbursements - Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events Life at Docusign Working here Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what's right, every day. At Docusign, everything is equal. We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you'll be loved by us, our customers, and the world in which we live. Accommodation Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at accommodations@docusign.com. If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at taops@docusign.com for assistance. Applicant and Candidate Privacy Notice States Not Eligible for Employment This position is not eligible for employment in the following states: Alaska, Hawaii, Maine, Mississippi, North Dakota, South Dakota, Vermont, West Virginia and Wyoming. Equal Opportunity Employer It's important to us that we build a talented team that is as diverse as our customers and where all employees feel a deep sense of belonging and thrive. We encourage great talent who bring a range of perspectives to apply for our open positions. Docusign is an Equal Opportunity Employer and makes hiring decisions based on experience, skill, aptitude and a can-do approach. We will not discriminate based on race, ethnicity, color, age, sex, religion, national origin, ancestry, pregnancy, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, registered domestic partner status, caregiver status, marital status, veteran or military status, or any other legally protected category. EEO Know Your Rights poster #LI-Hybrid

California
$146.4K - $235.4K / year
Full TimeRemoteTeam 51-200H1B No Sponsor

• Develop and manage client relationships, serving as the primary point of contact for key accounts. • Generate new business opportunities by expanding within existing accounts. • Collaborate with clients to understand business challenges and align solutions across physical security and managed services. • Leverage knowledge of CCTV, intrusion, fire, and nurse call systems to design tailored solutions. • Stay current with new security technologies, products, and industry trends to advise clients effectively. • Partner with technical teams to ensure client needs are accurately translated into deliverables • Identify opportunities for up-selling and cross-selling across the security and IT service portfolio.

Michigan
Full TimeRemoteTeam 51-200H1B No Sponsor

• Lead new customer acquisition efforts across Ohio, with a focus on the commercial real estate and multifamily verticals • Build and execute a territory growth plan centered on proactive outreach, discovery, and long-term account development • Own the prospect and customer-facing milestones of the sales lifecycle, from prospecting and discovery to solution positioning, proposal delivery, negotiation, and close • Conduct persuasive product and solution demos, aligning customer needs with cloud, on-prem, or hybrid physical security offerings • Partner closely with Sales Engineering and Technical Account Management to ensure accurate solution design and smooth project transitions • Represent K Group Companies at industry events, networking functions, and regional engagements • Maintain accurate CRM data, pipeline forecasts, and activity reporting • Act as a trusted advisor to prospects, helping them modernize legacy systems and plan long-term technology refresh cycles

Ohio

Senior Go Security

Encora Digital

Encora, a leader in digital engineering, drives innovation by crafting cutting-edge, cloud-first, data-first, and AI-first solutions that redefine industries. Since its inception i

Role Description We at Coforge are hiring a Senior Go Security (#19694) with the following skill set. - Design, develop, and deliver scalable, resilient, and high-performance backend systems for a cybersecurity platform. - Build and maintain microservices, REST APIs, and cloud-native solutions using Golang and GCP. - Collaborate with Product, Operations, and Engineering teams to design scalable technical solutions and improve platform reliability. - Participate in technical discussions, code reviews, CI/CD practices, and mentor junior engineers to promote engineering excellence. Qualifications - 7+ years of experience in backend software engineering and distributed systems. - Strong hands-on experience with Golang (Go) (7+ years preferred). - Expertise in microservices architecture, REST APIs, and gRPC. - Experience with Docker, Kubernetes, and cloud platforms (GCP preferred). - Knowledge of asynchronous messaging technologies such as Google Pub/Sub or Kafka. - Strong understanding of NoSQL and relational databases. - Experience with GitOps, DevOps methodologies, CI/CD, and Infrastructure as Code (IaC). - Experience with unit testing, BDD testing, and clean coding practices. - Familiarity with software design principles, UML, and Domain-Driven Design (DDD). - Strong communication, collaboration, and problem-solving skills. Requirements - Experience or exposure to cybersecurity, penetration testing, or offensive security. - Interest or familiarity with Generative AI and Large Language Models (LLMs). Company Description At Coforge, we hire professionals based solely on their skills and do not discriminate based on age, disability, religion, gender, sexual orientation, socioeconomic status, or nationality.

Bolivia