Senior Manager Offensive Security

Summary

Lead Asurion's offensive security function, managing the end-to-end penetration testing pipeline across web, mobile, and API applications, cloud platforms, and network infrastructure. Combines hands-on testing expertise with people management, AI/agentic tooling evaluation, and partnership with engineering and DevOps teams to drive remediation.

The Senior Manager, Offensive Security leads Asurion's offensive security testing function. Reporting to the Director of Application & Offensive Security, this leader is accountable for the intake, prioritization, execution, and quality of penetration testing across web and mobile applications, APIs, cloud environments, internal and external infrastructure, and supporting business services. This position balances hands-on technical leadership with people management, ensuring engagements are scoped effectively, delivered on schedule, and reported with findings that drive measurable risk reduction. The Senior Manager translates technical results into clear business risk for engineering, product, and security leadership, and partners closely with development, cloud, and infrastructure teams to ensure findings are understood and remediated.

Key Responsibilities
  • Penetration Testing Operations and Queue Management: Own the end-to-end penetration testing intake and delivery pipeline. Manage the testing queue, triage and prioritize incoming requests based on risk, business criticality, regulatory drivers, and release timelines, and balance workload across the team to meet commitments. Establish and maintain a repeatable engagement lifecycle covering scoping, rules of engagement, execution, reporting, retesting, and closure.
  • Technical Delivery and Quality Assurance: Oversee the execution of application, API, mobile, cloud, network, and infrastructure penetration tests. Set standards for testing rigor, evidence collection, exploit validation, and finding reproducibility. Review deliverables for technical accuracy, clarity, and actionable remediation guidance, and personally lead or contribute to complex, high-sensitivity engagements when needed.
  • People Leadership and Team Development: Manage, coach, and grow a team of penetration testers and offensive security engineers. Set clear goals and performance expectations, provide regular feedback, support career development and technical skill growth, and cultivate a culture of curiosity, integrity, and continuous learning.
  • Risk Reporting and Stakeholder CommunicatiSenior Manager, Offensive Securityon: Produce clear, decision-oriented reporting on penetration testing outcomes, trends, systemic weaknesses, and remediation progress. Translate technical findings into business risk language for engineering leaders, product owners, and security leadership. Track findings to closure, support risk acceptance and exception decisions where appropriate, and contribute to consolidated security reporting and metrics that demonstrate the program's impact.
  • Remediation Partnership and Secure Development Enablement: Partner with application development, DevOps, cloud, and infrastructure teams to ensure findings are understood, prioritized, and remediated. Provide guidance on root cause and durable fixes rather than one-off patches, and feed recurring patterns back into secure SDLC practices, threat modeling, and developer education.
  • Agentic and AI-Enabled Testing (Emerging Focus): Explore, pilot, and progressively develop an agentic penetration testing capability. Evaluate AI-assisted and autonomous offensive security tooling, define where automation can safely and effectively extend coverage, establish guardrails and validation processes for AI-generated findings, and build a roadmap that matures this capability over time while preserving the judgment and depth of human testers. Stay current on the evolving offensive AI landscape and represent Asurion's forward-looking approach to internal stakeholders.
  • Program Governance and Continuous Improvement: Maintain testing standards, tooling, and documentation, and continuously improve throughput, coverage, and quality. Ensure the program supports audit, compliance, and regulatory requirements, and coordinate with vulnerability management, exposure management, and incident response functions to align offensive testing with the broader security program.


Education and Experience
  • Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 8+ years of experience in information security, with 5+ years focused on penetration testing, offensive security, or red team operations.
  • 3+ years of experience leading technical teams or engagements, including direct people management, workload prioritization, and delivery accountability.
  • Demonstrated experience scoping and executing penetration tests across multiple domains such as web and mobile applications, APIs, cloud platforms, and internal/external network infrastructure.
  • Experience translating technical findings into executive- and business-level risk communications and driving remediation with engineering partners.
  • Preferred: Experience building or scaling a penetration testing function; familiarity with AI-assisted, autonomous, or agentic security tooling; regulated industry experience (e.g., financial services, insurance, healthcare, technology, or critical infrastructure); and contribution to secure SDLC and developer enablement initiatives.


Knowledge, Skills, and Abilities
  • Deep technical fluency in offensive security across application security and secure SDLC, cloud security, API and integration security, network and infrastructure testing, identity and access exploitation, and post-exploitation techniques.
  • Working command of recognized testing methodologies and standards, including NIST SP 800-115, PTES, the OWASP testing guides (including the OWASP Top 10 and API Security Top 10), and MITRE ATT&CK.
  • Strong understanding of detection engineering, EDR bypass, and purple teaming to improve control efficacy.
  • Familiarity with the NICE Workforce Framework for Cybersecurity (NIST SP 800-181) to help define penetration testing competencies, role expectations, and skill development paths for the team.
  • Hands-on proficiency with common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Cobalt Strike or equivalent, cloud-native testing tools) and comfort scripting and automating with languages such as Python.
  • Strong risk judgment and the ability to distinguish theoretical weaknesses from material, exploitable business risk, and to recommend pragmatic, prioritized remediation.
  • Effective people leadership, including coaching, performance management, capacity planning, and the ability to attract, grow, and retain highly skilled technical talent.
  • Clear written and verbal communication skills, with the ability to produce concise, decision-oriented reporting and influence engineering and security stakeholders without direct authority.
  • Curiosity and adaptability to evaluate emerging capabilities, including AI-enabled and agentic testing, and to responsibly integrate new methods into an established program.
  • Ownership mindset to drive engagements and findings to closure, maintain quality under resource constraints, and ensure transparent, well-documented risk decisions.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available