Security Managed Services Lead (VAPT)
Key Responsibilities
• Lead the planning, execution, and delivery of Vulnerability Assessment and Penetration Testing (VAPT) engagements across network, application, endpoint, cloud, and hybrid environments.
• Execute and support advanced red team operations, adversary emulation exercises, and threat simulations to assess the effectiveness of security controls, detection capabilities, and incident response processes.
• Partner with client stakeholders and internal teams to define engagement scope, objectives, rules of engagement, and risk priorities.
• Identify, validate, and exploit security vulnerabilities using industry-standard methodologies, frameworks, and tools while maintaining high standards of professionalism and ethical conduct.
• Analyze threat intelligence, emerging attack techniques, and adversary tactics aligned with frameworks such as MITRE ATT&CK to enhance the effectiveness and relevance of security assessments.
• Develop clear, accurate, and executive-ready reports that communicate technical findings, business risks, and prioritized remediation actions.
• Mentor junior security practitioners by providing technical guidance, knowledge sharing, and support in offensive security techniques, tooling, and reporting practices.
• Contribute to the continuous improvement of VAPT methodologies, red team playbooks, automation capabilities, and service delivery standards to drive operational excellence and client value.
Required Qualifications
• Bachelor’s degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related discipline.
• Proven experience performing penetration testing, vulnerability assessments, and offensive security engagements across enterprise environments.
• Strong hands-on experience with application security testing, network penetration testing, cloud security assessments, and exploitation techniques.
• Deep understanding of modern attack methodologies, adversary tactics, and security frameworks, including MITRE ATT&CK and OWASP.
• Experience creating technical assessment reports and presenting findings to both technical and non-technical stakeholders.
• Strong problem-solving, analytical, and communication skills, with the ability to manage multiple priorities in a dynamic environment.
• Ability to collaborate effectively across teams and contribute to key security decisions and strategic initiatives.
Preferred Qualifications
• Industry certifications such as OSCP, OSEP, OSWE, CRTO, CREST, GPEN, GWAPT, GXPN, CISSP, or equivalent.
• Experience conducting red team operations, purple team exercises, and threat-led security assessments.
• Knowledge of cloud platforms such as Microsoft Azure, AWS, and Google Cloud Platform (GCP).
• Experience with security automation, scripting, and offensive security tooling.
• Familiarity with Security Operations Center (SOC) processes, threat hunting, and detection engineering.