Posted in

Senior Manager – Offensive Security – Penetration Tester

Senior Manager – Offensive Security – Penetration Tester

CompanyCapital One
LocationPlano, TX, USA, McLean, VA, USA, Richmond, VA, USA, New York, NY, USA
Salary$204900 – $280600
TypeFull-Time
Degrees
Experience LevelSenior

Requirements

  • High School Diploma, GED, or equivalent certification
  • At least 6 years of experience working in cybersecurity or information technology
  • At least 4 years of experience in Penetration Testing
  • At least 3 years of experience in People Management
  • At least 2 years of experience with public cloud environments (AWS, Azure, GCP)
  • At least 1 year of experience scripting with Python, Golang, or C#

Responsibilities

  • Leading and overseeing penetration testing of enterprise networks, services, applications, and infrastructure.
  • Contributing to the development of a comprehensive penetration testing strategy that aligns with the organization’s overall security objectives.
  • Analyzing penetration testing results and providing actionable insights to relevant stakeholders to drive remediation efforts and improve the organization’s security posture.
  • Staying abreast of emerging threats and attack techniques to ensure that the team’s strategy and techniques remain relevant and effective.
  • Providing mentorship and guidance to foster professional development and enhance the team’s overall capabilities.
  • Working with developers on remediation guidance and improvements throughout the Software CI/CD pipeline.
  • Clearly and effectively conveying technical information and results to diverse audiences, including senior management and those without a technical background.

Preferred Qualifications

  • Bachelor’s Degree
  • 6+ years of security testing experience​ (red teaming, cloud security, application security, or network security)
  • 6+ years of experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE)
  • Experience developing Offensive Security tools
  • Experience with code review and secure coding standards
  • OSCP, OSWA, OSWE, OSCE3, GPEN, GXPN, CRTO certification