delinea - Senior Manager, Offensive Security
Requirements
• · Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field. • · Minimum 7+ years of demonstrated, hands-on experience with internal and external web application, API, and network penetration testing to include writing and reviewing formal penetration test reports, documenting the test details and vulnerabilities, identifying risks, and noting strengths discovered. • · 3+ years of demonstrated experience building and leading technical product or offensive security teams, setting team objectives, and developing junior talent • · Understanding of penetration testing methodology and frameworks (MITRE ATT&CK, OWASP, PTES) and hands-on experience with industry-standard offensive tooling, including Burp Suite, command-and-control frameworks such as Cobalt Strike or Sliver, and attack-path analysis tools such as BloodHound. • · Skill in illustrating and explaining security vulnerabilities, including proof-of-concept demonstrations, to audiences with minimal expertise in security. • · Experience in the areas of vulnerability identification, malware analysis, and current & emerging exploitation techniques. • · Experience testing identity infrastructure and privileged access attack paths, including Active Directory, Entra ID, Kerberos abuse, and credential and secrets exposure. • · Proficiency in source code review, leveraging findings to execute targeted attacks. • · Proficiency in at least one scripting or programming language, such as Python, Go, or PowerShell, for tooling, automation, and exploit development. • · Experience with Azure and AWS cloud-based infrastructure. • · Experience testing containerized and cloud-native environments, including Kubernetes, infrastructure-as-code, and CI/CD pipeline security. • We'd Love to See: • · One or more of the following certifications: ARTE, eCPPT, eWPT, CARTS, CRTL, CRTO, CRTP, GPEN, GWAPT, OSCP, OSEP, OSWE, Pentest+, PNPT. • · Experience working with high-security environments subject to regulations such as FedRAMP or ITAR. • · Excellent analytical and problem-solving skills with keen attention to detail. • · Experience assisting in CAPEC markups for threat models. • · Experience both using AI and LLM-based agents and tooling in testing methodologies and testing AI and LLM-based features and agents, including prompt injection and the OWASP Top 10 for LLM Applications. • For this Job, Delinea is not considering candidates that need any type of US work authorization now or in the future. This includes, but is not limited to: F1-OPT, F1-CPT, H-1B, TN, L-1, J1, etc.
Responsibilities
• · Lead the effort to define and mature Delinea’s Offensive Security function. Provide technical expertise and shape the procedural and programmatic structure of our Penetration Testing and Red Teaming activities. • · Lead a team of penetration test and offensive security engineers, setting expectations on performance, goals, and objectives, and providing mentorship and guidance to team members. • · Lead internal and external penetration testing engagements from beginning to end, including (where needed) vendor selection, statements of work, budget ownership, planning, kickoff, testing, documentation, reporting, remediation, and follow-up. • · Use real-world adversarial TTPs and tooling to test the security controls protecting Delinea’s enterprise and product environments by performing red/purple team assessments, including assumed breach tests and social engineering assessments. • · Manage the operation of Delinea’s Product Security testing environments for use with internal and external resources and develop a framework in that environment for using frontier AI models in the evaluation of product sources and attack paths. • · Develop comprehensive and actionable reports and presentations, including end-to-end exploit reproductions and attack chains, to technical and executive audiences. • · Act as a subject matter expert on penetration testing methodologies, techniques, and procedures. • · Build relationships across organizational boundaries to ensure that identified weaknesses are remediated and lessons learned are captured. • · Ensure that the Offensive Security program meets Delinea’s compliance and customer commitments, such as SOC 2, ISO 27001, PCI DSS, and FedRAMP, and act as the offensive security point of contact for auditors and assessors. • · Communicate effectively with stakeholders at all levels, translating technical findings into actionable insights and recommendations for both technical and non-technical audiences. • · Work with Cybersecurity Program Management to define the metrics that measure program effectiveness, including testing coverage, finding severity trends, and time to remediate, and report to executive leadership on a regular cadence.
Benefits
• We're passionate problem-solvers helping the world's largest organizations protect what matters most: their human and machine identities. • We invest in people who are smart, self-motivated, and collaborative. • What we offer in return is meaningful work, a culture of innovation and great career progression. • At Delinea, our core values are STRONG and guide our behaviors and success: • Spirited - We bring energy and passion to everything we do • Trust - We act with integrity and deliver on our commitments • Respect - We listen, value different perspectives, and work as one team • Ownership - We take initiative and follow through • Nimble - We adapt quickly in a fast-changing environment • Global - We embrace diverse people and ideas to drive better outcomes • We believe weaving these core values into our day-to-day actions, and our process for hiring, evaluating, and promoting employees, helps us cultivate a work environment that embraces collaboration and camaraderie. • We take care of our employees. We offer competitive salaries, a meaningful bonus program, and excellent benefits, including healthcare insurance, as well as pension/retirement matching, comprehensive life insurance, an employee assistance program, time off plans, and paid company holidays.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT