Point your AI agent at freehire and let it find you a job.

Get the CLI →

CITIBANK N.A.

New

26996607 Application Pentest Manager

Posted Updated 2 views
Discussion

The Info Security Ops Group Manager is a senior management level position responsible for providing strategic leadership, operational oversight, and people management for application security testing services. This role ensures the delivery of high-quality Application Vulnerability Assessment and Management (AVA/AVM) services while maintaining operational excellence, service continuity, and adherence to cybersecurity standards.

The position plays a critical role in defining and executing the organization's perimeter testing strategy, helping protect critical business applications from emerging cyber threats. As a people leader, the Manager develops and leads a team of cybersecurity professionals, drives continuous service improvement, and partners with senior stakeholders to enhance the firm's overall security posture.

Key Responsibilities

Strategic Leadership

  • Define and execute the long-term strategy and roadmap for Application Vulnerability Management services.

  • Lead the evolution of perimeter testing capabilities to address emerging threats and business requirements.

  • Partner with senior cybersecurity leaders, technology organizations, and business stakeholders to align security testing initiatives with enterprise risk management objectives.

  • Drive innovation, automation, and process improvements to enhance service effectiveness and efficiency.

Service Delivery & Operations

  • Oversee day-to-day AVA/AVM pentest operations, ensuring consistent delivery of high-quality vulnerability assessment services.

  • Maintain service continuity, operational resilience, and compliance with established service level expectations.

  • Establish and monitor key performance indicators, quality metrics, and reporting to measure program effectiveness.

  • Ensure timely identification, assessment, prioritization, and remediation tracking of application vulnerabilities.

Team Leadership & Development

  • Lead, mentor, and develop a team of cybersecurity specialists responsible for application security testing and vulnerability management activities.

  • Foster a culture of accountability, collaboration, innovation, and continuous learning.

  • Support workforce planning, talent development, succession planning, and employee engagement initiatives.

  • Provide technical guidance and strategic direction to ensure consistent execution across the team.

Risk Management & Governance

  • Ensure AVA/AVM services operate in alignment with organizational cybersecurity policies, standards, and regulatory requirements.

  • Identify and manage security, operational, and compliance risks associated with application security testing activities.

  • Communicate risk insights and remediation priorities to senior management and key stakeholders.

  • Support internal and external audit activities and demonstrate effective security governance practices.

Stakeholder Engagement

  • Build strong relationships with technology, engineering, application development, and cybersecurity teams.

  • Act as the primary management representative for AVA/AVM services.

  • Present program performance, risk trends, and strategic initiatives to senior leadership.

Qualifications

  • 10+ years of extensive experience in application security, vulnerability assessment, vulnerability management, penetration testing, or related cybersecurity domains.

  • Demonstrated experience leading cybersecurity teams and managing large-scale security operations.

  • Strong understanding of application security testing methodologies, vulnerability management practices, and secure software development principles.

  • Experience managing stakeholder relationships across technology and business organizations.

  • Excellent leadership, communication, and organizational skills.

  • Experience building and executing enterprise-scale application security programs.

  • Knowledge of cloud security, DevSecOps practices, and modern application architectures.

  • Experience driving cybersecurity transformation and service modernization initiatives.

Education:

  • Bachelor’s degree/University degree or equivalent experience

  • Holding relevant professional cybersecurity certifications such as CISSP, CISM, GWAPT, GPEN, OSCP, or equivalent.

Skills

Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available