26996607 Application Pentest Manager
The Info Security Ops Group Manager is a senior management level position responsible for providing strategic leadership, operational oversight, and people management for application security testing services. This role ensures the delivery of high-quality Application Vulnerability Assessment and Management (AVA/AVM) services while maintaining operational excellence, service continuity, and adherence to cybersecurity standards. The position plays a critical role in defining and executing the organization's perimeter testing strategy, helping protect critical business applications from emerging cyber threats. As a people leader, the Manager develops and leads a team of cybersecurity professionals, drives continuous service improvement, and partners with senior stakeholders to enhance the firm's overall security posture. Key Responsibilities Strategic Leadership Define and execute the long-term strategy and roadmap for Application Vulnerability Management services.
Lead the evolution of perimeter testing capabilities to address emerging threats and business requirements.
Partner with senior cybersecurity leaders, technology organizations, and business stakeholders to align security testing initiatives with enterprise risk management objectives.
Drive innovation, automation, and process improvements to enhance service effectiveness and efficiency.
Service Delivery & Operations Oversee day-to-day AVA/AVM pentest operations, ensuring consistent delivery of high-quality vulnerability assessment services.
Maintain service continuity, operational resilience, and compliance with established service level expectations.
Establish and monitor key performance indicators, quality metrics, and reporting to measure program effectiveness.
Ensure timely identification, assessment, prioritization, and remediation tracking of application vulnerabilities.
Team Leadership & Development Lead, mentor, and develop a team of cybersecurity specialists responsible for application security testing and vulnerability management activities.
Foster a culture of accountability, collaboration, innovation, and continuous learning.
Support workforce planning, talent development, succession planning, and employee engagement initiatives.
Provide technical guidance and strategic direction to ensure consistent execution across the team.
Risk Management & Governance Ensure AVA/AVM services operate in alignment with organizational cybersecurity policies, standards, and regulatory requirements.
Identify and manage security, operational, and compliance risks associated with application security testing activities.
Communicate risk insights and remediation priorities to senior management and key stakeholders.
Support internal and external audit activities and demonstrate effective security governance practices.
Stakeholder Engagement Build strong relationships with technology, engineering, application development, and cybersecurity teams.
Act as the primary management representative for AVA/AVM services.
Present program performance, risk trends, and strategic initiatives to senior leadership.
Qualifications 10+ years of extensive experience in application security, vulnerability assessment, vulnerability management, penetration testing, or related cybersecurity domains.
Demonstrated experience leading cybersecurity teams and managing large-scale security operations.
Strong understanding of application security testing methodologies, vulnerability management practices, and secure software development principles.
Experience managing stakeholder relationships across technology and business organizations.
Excellent leadership, communication, and organizational skills.
Experience building and executing enterprise-scale application security programs.
Knowledge of cloud security, DevSecOps practices, and modern application architectures.
Experience driving cybersecurity transformation and service modernization initiatives.
Education: Bachelor’s degree/University degree or equivalent experience
Holding relevant professional cybersecurity certifications such as CISSP, CISM, GWAPT, GPEN, OSCP, or equivalent.