Source description
About the role
Role Overview: As the Principal Penetration Tester/ Offensive Security Team Lead, you will lead and scale the organization's offensive security and penetration testing practice within a lean and fast-growing cybersecurity company. This player-coach role requires you to remain deeply hands-on, actively conducting and contributing to penetration testing engagements. Alongside this, you will be responsible for leadership, delivery oversight, team mentorship, and business growth. Key Responsibilities: - Personally conduct and contribute to penetration testing engagements across various domains including web applications, APIs, cloud environments, networks, mobile applications, wireless infrastructure, and enterprise systems. - Take direct ownership of complex, high-risk, or sensitive engagements requiring deep technical expertise. - Perform adversary simulation, exploit development, and advanced attack chain construction on client engagements. - Author and review high-quality technical reports with detailed findings, evidence, risk ratings, and actionable remediation guidance. - Stay current with offensive tooling, exploitation techniques, CVE research, and emerging attack vectors through personal practice and research. - Establish and continuously evolve testing methodologies, quality standards, reporting frameworks, and operational best practices. - Ensure timely, high-quality delivery of all client engagements while managing resource allocation and competing priorities. - Drive continuous improvement in offensive security capabilities, tooling, automation, and assessment approaches. - Lead internal research, proof-of-concept development, and red team innovation initiatives. - Serve as the practice's foremost technical authority on offensive security, adversary simulation, and vulnerability assessment. - Guide and personally support advanced exploitation scenarios, novel attack surface assessments, and high-complexity engagements. - Track and operationalize emerging attack techniques, vulnerability disclosures, and threat trends relevant to client environments. - Contribute to the development of new service offerings and scalable assessment models aligned with market demand. - Build, mentor, and manage a small but high-performing pentesting team. - Conduct hands-on technical reviews, pair-testing sessions, and skill development initiatives for consultants. - Foster a collaborative, learning-oriented, and accountable team culture suited to a fast-paced environment. - Support hiring, onboarding, and technical capability development of new team members. Qualification Required: - Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical discipline or equivalent demonstrated experience. - 10+ years in cybersecurity with a focus on hands-on penetration testing and offensive security. - Proven track record of executing penetration tests across multiple technology domains and leading penetration testing teams. - Experience engaging directly with enterprise clients and executive stakeholders. - Prior experience in fast-paced, lean, or startup-oriented environments preferred. Role Overview: As the Principal Penetration Tester/ Offensive Security Team Lead, you will lead and scale the organization's offensive security and penetration testing practice within a lean and fast-growing cybersecurity company. This player-coach role requires you to remain deeply hands-on, actively conducting and contributing to penetration testing engagements. Alongside this, you will be responsible for leadership, delivery oversight, team mentorship, and business growth. Key Responsibilities: - Personally conduct and contribute to penetration testing engagements across various domains including web applications, APIs, cloud environments, networks, mobile applications, wireless infrastructure, and enterprise systems. - Take direct ownership of complex, high-risk, or sensitive engagements requiring deep technical expertise. - Perform adversary simulation, exploit development, and advanced attack chain construction on client engagements. - Author and review high-quality technical reports with detailed findings, evidence, risk ratings, and actionable remediation guidance. - Stay current with offensive tooling, exploitation techniques, CVE research, and emerging attack vectors through personal practice and research. - Establish and continuously evolve testing methodologies, quality standards, reporting frameworks, and operational best practices. - Ensure timely, high-quality delivery of all client engagements while managing resource allocation and competing priorities. - Drive continuous improvement in offensive security capabilities, tooling, automation, and assessment approaches. - Lead internal research, proof-of-concept development, and red team innovation initiatives. - Serve as the practice's foremost technical authority on offensive security, adversary simulation, and vulnerability assessment
More at BreachLock, Inc.