JobRaahGet matched free

Jobs

Manager – Security Testing

kratikal · Noida, Uttar Pradesh, India · On-site

Posted Jul 10, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

About the Role We're looking for a hands-on leader to run our Red Team and offensive security practice — someone who can still execute the hardest engagements while building, mentoring, and scaling a high-performing testing team. You'll own delivery quality, set the methodology bar, and act as the senior technical authority on complex adversary-emulation and network penetration testing engagements. Key Responsibilities Team Leadership & Management Lead, mentor, and grow a team of penetration testers and red teamers — including hiring, onboarding, skill development, and performance evaluation. Plan capacity and allocate resources across concurrent engagements; monitor utilization, productivity, and delivery timelines. Define and maintain testing methodologies, playbooks, SOPs, and quality standards aligned to MITRE ATT&CK and industry frameworks. Own quality assurance — review and sign off on all deliverables before client release. Drive continuous improvement: internal tooling, R&D on new TTPs, and process efficiency. Act as senior technical escalation point and the offensive-security point of contact for key accounts; support scoping, effort estimation, and pre-sales conversations. Red Team & Offensive Operations Execute advanced Red Team engagements and Black Box / Grey Box assessments that simulate real-world threat actors. Run the full cyber-attack lifecycle: reconnaissance, attack-surface mapping, weaponization, exploitation, credential access, privilege escalation, lateral movement, persistence, and post-exploitation. Design and operate C2 infrastructure (redirectors, OPSEC, egress) and develop payloads with AV/EDR evasion in mind. Social Engineering: design and execute full-scope simulations — phishing, spear-phishing, vishing, smishing, and pretexting — including campaign design, payload delivery, and success/detection metrics. Physical Red Team: plan and conduct operations — reconnaissance, tailgating, badge cloning/RFID attacks, lock bypass, and physical access to restricted areas and network drops, executed safely and within agreed rules of engagement. Wireless / Wi-Fi: perform security assessments — rogue AP and evil-twin attacks, WPA2/WPA3 and PMKID/handshake capture and cracking, and wireless segmentation testing. Dark Web & OSINT: conduct reconnaissance to surface leaked credentials, exposed assets, and threat-actor chatter to inform attack paths and report on organizational exposure. Conduct advanced Network Penetration Testing, including firewall/segmentation bypass and attack-path chaining. Execute Active Directory attacks — misconfigurations, Kerberoasting/AS-REP roasting, delegation and trust abuse, ADCS abuse (ESC1–8), DCSync, and domain/forest compromise. Perform password and credential attacks using cracking and harvesting techniques. Chain low/medium-severity issues into multi-stage, high-impact compromises. (Preferred) Identify and exploit cloud attack paths across Azure AD/Entra ID, AWS, or GCP. Reporting &…