Padmi

Manager Security Testing

Delhi NCRPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at Kratikal

Opens the source posting on shine.com

Source description

About the role

View original

About the Role:- We're looking for a hands-on leader to run our Red Team and offensive security practice someone who can still execute the hardest engagements while building, mentoring, and scaling a high-performing testing team. You'll own delivery quality, set the methodology bar, and act as the senior technical authority on complex adversary-emulation and network penetration testing engagements. Key Responsibilities:- Team Leadership & Management: Lead, mentor, and grow a team of penetration testers and red teamers including hiring, onboarding, skill development, and performance evaluation.Plan capacity and allocate resources across concurrent engagements; monitor utilization, productivity, and delivery timelines.Define and maintain testing methodologies, playbooks, SOPs, and quality standards aligned to MITRE ATT&CK and industry frameworks.Own quality assurance review and sign off on all deliverables before client release.Drive continuous improvement: internal tooling, R&D on new TTPs, and process efficiency.Act as senior technical escalation point and the offensive-security point of contact for key accounts; support scoping, effort estimation, and pre-sales conversations.Red Team & Offensive Operations: Execute advanced Red Team engagements and Black Box / Grey Box assessments that simulate real-world threat actors.Run the full cyber-attack lifecycle: reconnaissance, attack-surface mapping, weaponization, exploitation, credential access, privilege escalation, lateral movement, persistence, and post-exploitation.Design and operate C2 infrastructure (redirectors, OPSEC, egress) and develop payloads with AV/EDR evasion in mind.Social Engineering: design and execute full-scope simulations phishing, spear-phishing, vishing, smishing, and pretexting including campaign design, payload delivery, and success/detection metrics.Physical Red Team: plan and conduct operations reconnaissance, tailgating, badge cloning/RFID attacks, lock bypass, and physical access to restricted areas and network drops, executed safely and within agreed rules of engagement.Wireless / Wi-Fi: perform security assessments rogue AP and evil-twin attacks, WPA2/WPA3 and PMKID/handshake capture and cracking, and wireless segmentation testing.Dark Web & OSINT: conduct reconnaissance to surface leaked credentials, exposed assets, and threat-actor chatter to inform attack paths and report on organizational exposure.Conduct advanced Network Penetration Testing, including firewall/segmentation bypass and attack-path chaining.Execute Active Directory attacks misconfigurations, Kerberoasting/AS-REP roasting, delegation and trust abuse, ADCS abuse (ESC18), DCSync, and domain/forest compromise.Perform password and credential attacks using cracking and harvesting techniques.Chain low/medium-severity issues into multi-stage, high-impact compromises.(Preferred) Identify and exploit cloud attack paths across Azure AD/Entra ID, AWS, or GCP.Reporting & Collaboration: Produce detailed Red Team reports with attack narratives, MITRE ATT&CK mapping, business impact, and actionable remediation guidance.Collaborate with Blue Team/SOC in purple-team exercises to validate detections and strengthen defensive controls.Work with cross-functional teams to integrate security measures and coordinate remediation.Required Skills & Technical Expertise: 5+ years in offensive security, Red Teaming, and Network Penetration Testing, with prior experience leading or mentoring a team.Deep understanding of network architecture, TCP/IP, DNS, routing, segmentation, firewalls, and enterprise environments.Strong Active Directory attack expertise across on-prem and hybrid environments.Hands-on with C2 frameworks Cobalt Strike, Sliver, Mythic, or Havoc.Expertise in the Metasploit Framework (exploit development, payloads, chaining).Proficiency with offensive tooling such as BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, Certipy, Mimikatz, Nmap, and Burp Suite.Hands-on wireless attack tooling Aircrack-ng suite, hcxdumptool/hcxtools, Hashcat, and rogue-AP frameworks (e.g., WiFi Pineapple/EAPHammer).Social engineering campaign tooling and pretext development (e.g., GoPhish, Evilginx, or equivalent).Scripting/automation ability in Python, PowerShell, Bash, and ideally C# or Go.Working knowledge of AV/EDR evasion and OPSEC principles.Strong report-writing and client-facing communication skills.Good to Have: Certifications such as OSCP, OSEP, OSED/OSCE3, CRTO/CRTO II, CRTP/CRTE, GXPN, or GPEN.Physical red teaming experience (RFID/badge attacks, covert entry) w .

One address, no account. We’ll tell you when matching roles go live.

More at Kratikal

Related open roles

View all roles