
Cyber Testing Director
4 weeks ago
Job Description :
Qualification and Minimum Entry Requirements :
- Bachelor or Master degree in computer science with a minimum of 10 years in cyber security domain
- Technical background in networking/system administration, security testing or related fields
- In-depth knowledge of TCP/IP
- Good knowledge of Perl, Python, Bash, or C experience
- Operating System Configuration and Security experience (Windows, HP-UX, Linux, Solaris, AIX, etc.)
- Configuration and Security experience with firewalls, switches, routers, VPNs
- Experience with security and architecture testing and development frameworks, such as the Open Web Application Security Project (OWASP), Open Source Security Testing Methodology Manual (OSSTMM), the Penetration Testing Execution Standard (PTES), Information Systems Security Assessment Framework (ISSAF), and NIST SP800-115
- Familiar with security testing techniques such as threat modeling, network discovery, port and service identification, vulnerability scanning, network sniffing, penetration testing, configuration reviews, firewall rule reviews, social engineering, wireless penetration testing, fuzzing, and password cracking and can perform these techniques from a variety of adversarial perspectives (white-, grey-, black-box)
- Commercial Application Security tools experience (Nessus, Nexpose, Qualys, Appdetective, Appscan, etc.)
- Open source and free tools experience (Kali Linux suite, Metasploit, nmap, airsnort, Wireshark, Burp Suite, Paros, etc.)
- One or more of the following testing certifications: Certified Ethical Hacker (CEH); GIAC Certified Penetration Tester (GPEN); Offensive Security Certified Professional (OSCP); or equivalent development or testing certification (ECSA, CEPT, CPTE, CPTS, etc)
- In addition, one or more of the following governance certifications is preferred : Certified Information Systems Security Professionals- (CISSP- ); Certified Information Systems Auditor- (CISA- ); Certified Information Security Manager- (CISM- )
- Strong leadership and communication skills, technical knowledge, and the ability to write at a "publication" quality level in order to communicate findings and recommendations to the client's senior management
- Must possess a high degree of integrity and confidentiality, as well as the ability to adhere to both company policies and best practices
Technical Requirements :
- Web application penetration testing experience - familiarity with Burp, OWASP Top 10, etc
- Ability to recognize and validate significant findings past initial scanning/recon
- Web Services penetration testing (RESTful, CURL and SOAP)
- API penetration testing experience
- Conducts periodic scans of networks to find and detect vulnerabilities
- Lead scoping engagements by clearly articulating various penetration approaches and methodologies to audiences ranging from highly technical to executive personnel
- Report generation that clearly communicates testing and assessment details, results, and remediation recommendations to clients
- Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements
- Conduct IT application testing, cybersecurity tool and systems analysis, system and network administration, and systems engineering support for the sustainment of information technology systems (mobile application testing, penetration testing, application, security, and hardware testing)
- Conduct cloud penetration testing engagements to assess specific workloads (i.e., AWS, GCP, Azure, containers, or other PaaS and SaaS instances) for vulnerabilities and subsequently attempt to exploit identified weakness after receiving permission from client stakeholders
- Provide recommendations to clients on specific security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks including response and recovery of a data security breach
- Maintain a firm grasp on the industry and anticipate trends and movements while balancing maturity and timing
- Performs client penetration testing to find any vulnerabilities or weaknesses that might be exploited by a malicious party, using open-source, custom, and commercial testing tools
- Expert knowledge of tools used for wireless, web application, and network security testing
- Working knowledge of CI/CD and SDLC deployment lifecycles and mechanisms
- Motivated self-starter who loves to solve challenging problems and feels comfortable working directly with customers
- Excellent oral, written communication, and presentation skills with an ability to present client security sessions and security workshops to C-Level Executives and non-technical audience
- Highly organized, detail-oriented, excellent time management skills, and able to effectively prioritize tasks in a fast-paced, high-volume, and evolving work environment
- Ability to approach customer and sales requests with a proactive and consultative manner; listen and understand user requests and needs and effectively deliver
- Comfortable managing multiple and changing priorities, and meeting deadlines in an entrepreneurial environment
Nice to have :
- Mobile application penetration testing experience
- Cloud penetration testing experience (AWS and Azure)
Soft Skills Requirement :
- Ability to work independently under minimal supervision and within a team.
- Manage project tasks and deadlines within a multi-time zone remote culture.
- 5- 10 years of customer-facing consulting experience
- Ability to communicate complex vulnerability results and demonstrate proof of concepts for diverse audiences.
- 5+ years of experience managing a diverse team of technical testers
- Proven experience improving technical quality of the team
- Report regularly to management on improvements and team challenges
- 7-10 years of experience working in a global environment with multiple time zones and adjusting to client needs in other countries
- Ability to train others and improve technical skills of a team
Key Takeaways :
1. Role Scope & Responsibilities :
- The Cyber Testing Director will be a highly technical leader with strong team management capabilities.
- The role requires someone who can either bring their own team or effectively track and manage existing teams.
- This individual will oversee client-level projects (not just internal cyber security work).
- They should be able to interact with C-level executives, deliver end-to-end cyber security solutions, and ensure quality assurance in project execution.
2. Technical Expertise Required :
Core Competencies :
- Red Teaming expertise is a must.
- Experience in Web Services, Azure, and various penetration testing methodologies.
- Ability to handle multiple client projects simultaneously.
Security & Penetration Testing :
- Strong expertise in Cloud Security (mandatory).
- Web application penetration testing is a critical skill.
- Hands-on experience in various penetration testing types, including: Mobile, Web, Application, Network
Tools & Techniques :
- Penetration Testing Tools : Burp Suite, OWASP Top 10, REST & SOAP API security testing.
- Security & Open Source Tools : Linux, Wireshark, Nessus, Qualys.
- Security Techniques & Best Practices : BIOS Security, Threat Modeling, Network Discovery, Port & Service Identification, Vulnerability Scanning, Password Cracking, White, Gray, and Black Box Testing
Preferred Certifications :
- Candidates should ideally hold at least one of the following : OSCP, GPEN, CISSP, CISA, CISM
-
Cyber Testing Manager
4 weeks ago
Hyderabad, India Pyramid IT Consulting Pvt Ltd. Full timeJob Title : Cyber Testing Manager Location : Bangalore, KA/ Hyderabad (Hybrid)Job Description :- Bachelor or Master degree in computer science with a minimum of 8 years in cyber security domain- Technical background in networking/system administration, security testing or related fields- In-depth knowledge of TCP/IP- Two or more years of Perl, Python, Bash,...
-
Cyber Crisis Manager
6 days ago
Hyderabad, India Michael Page Full timeCompetetive SalaryPF and GratuityAbout Our ClientOur client is an international professional services brand of firms, operating as partnerships under the brand. It is the second-largest professional services network in the worldJob DescriptionCYBER CRISIS MANAGERThe cybersecurity crisis manager works closely with CSIRT teams.It analyzes the scope of the...
-
Cyber Crisis Manager
2 weeks ago
Hyderabad, India Michael Page Full timeCompetetive Salary PF and Gratuity About Our Client Our client is an international professional services brand of firms, operating as partnerships under the brand. It is the second-largest professional services network in the world Job Description CYBER CRISIS MANAGER The cybersecurity crisis manager works closely with CSIRT teams.It analyzes the scope...
-
Cyber Crisis Manager
2 weeks ago
Hyderabad, India Michael Page Full timeCompetetive Salary PF and Gratuity About Our Client Our client is an international professional services brand of firms, operating as partnerships under the brand. It is the second-largest professional services network in the world Job Description CYBER CRISIS MANAGER The cybersecurity crisis manager works closely with CSIRT teams.It analyzes...
-
Associate Director
2 weeks ago
Hyderabad, Telangana, India S&P Global Market Intelligence Full time ₹ 20,00,000 - ₹ 25,00,000 per yearThe Team:The S&P Global Internal Audit function reports functionally to the S&P Global Audit Committee and administratively to the S&P Global President and CEO. Join our dynamic Internal Audit Team at S&P Global as a seasoned IT Audit and a Cyber Security leader with keen interest in emerging technologies. As an Associate Director, you will lead and manage...
-
Cyber Security Engineer
2 weeks ago
Hyderabad, Telangana, India Bhumi iTech Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description: Cybersecurity Engineer (Cyber Range Engineer)Location:HyderabadJob Type:Full-TimeIndustry: Government, Defense, Critical InfrastructureAre you ready to take on challenging, real-world cybersecurity scenarios that impact governments, defense, and critical infrastructure sectors? We seek a Cyber Range Scenario Developer with a strong Blue/Red...
-
Information Security Officer
4 weeks ago
Hyderabad, India HRmind Full timeJob Overview : The Information Security Officer (ISO) will be responsible for leading the company's information security program and ensuring the confidentiality, integrity, and availability of the company's information assets. The ISO will report directly to the Head Digital Transformation and work closely with the executive team to develop and...
-
Immediate Start: Cyber Crisis Manager
1 week ago
Hyderabad, India Michael Page Full timeJob Description - Competetive Salary - PF and Gratuity About Our Client Our client is an international professional services brand of firms, operating as partnerships under the brand. It is the second-largest professional services network in the world Job Description CYBER CRISIS MANAGER The cybersecurity crisis manager works closely with CSIRT teams. It...
-
Cyber Secuirty
7 days ago
Hyderabad, India Datrax Services Pvt Ltd Full time**Required Skills**: Strong Development experience in Diag /Comms / Boot loader (with HSM knowledge). Strong knowledge & experience on Cyber Security concepts. Strong debugging skills in HW environment. Good experience analyzing Customer requirements and s/w requirements. Experience in CAN/CANFD/Flexray protocols. Knowledge on Infineon Tricore...
-
Cyber Threat Hunter
5 days ago
Hyderabad, India Experian Full timeCompany Description Experian is the world’s leading global information services company. During life’s big moments — from buying a home or a car to sending a child to college to growing a business by connecting with new customers — we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control...