Senior Manager – Offensive Security – Penetration Tester
Company | Capital One |
---|---|
Location | Plano, TX, USA, McLean, VA, USA, Richmond, VA, USA, New York, NY, USA |
Salary | $204900 – $280600 |
Type | Full-Time |
Degrees | |
Experience Level | Senior |
Requirements
- High School Diploma, GED, or equivalent certification
- At least 6 years of experience working in cybersecurity or information technology
- At least 4 years of experience in Penetration Testing
- At least 3 years of experience in People Management
- At least 2 years of experience with public cloud environments (AWS, Azure, GCP)
- At least 1 year of experience scripting with Python, Golang, or C#
Responsibilities
- Leading and overseeing penetration testing of enterprise networks, services, applications, and infrastructure.
- Contributing to the development of a comprehensive penetration testing strategy that aligns with the organization’s overall security objectives.
- Analyzing penetration testing results and providing actionable insights to relevant stakeholders to drive remediation efforts and improve the organization’s security posture.
- Staying abreast of emerging threats and attack techniques to ensure that the team’s strategy and techniques remain relevant and effective.
- Providing mentorship and guidance to foster professional development and enhance the team’s overall capabilities.
- Working with developers on remediation guidance and improvements throughout the Software CI/CD pipeline.
- Clearly and effectively conveying technical information and results to diverse audiences, including senior management and those without a technical background.
Preferred Qualifications
- Bachelor’s Degree
- 6+ years of security testing experience (red teaming, cloud security, application security, or network security)
- 6+ years of experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE)
- Experience developing Offensive Security tools
- Experience with code review and secure coding standards
- OSCP, OSWA, OSWE, OSCE3, GPEN, GXPN, CRTO certification