Manager – Security Testing

Posted 5 Days Ago
Be an Early Applicant
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
In-Office
Senior level
Cybersecurity
The Role
Lead and scale a Red Team/offensive security practice while executing advanced adversary-emulation and network penetration engagements. Responsibilities include team leadership, methodology and quality assurance, C2 and payload development, social engineering and physical red team operations, wireless and AD attack techniques, OSINT/dark-web reconnaissance, cloud offensive testing (preferred), and producing detailed reports and purple-team collaboration.
Summary Generated by Built In

About the Role

We're looking for a hands-on leader to run our Red Team and offensive security practice — someone who can still execute the hardest engagements while building, mentoring, and scaling a high-performing testing team. You'll own delivery quality, set the methodology bar, and act as the senior technical authority on complex adversary-emulation and network penetration testing engagements.

Key Responsibilities

Team Leadership & Management

  • Lead, mentor, and grow a team of penetration testers and red teamers — including hiring, onboarding, skill development, and performance evaluation.

  • Plan capacity and allocate resources across concurrent engagements; monitor utilization, productivity, and delivery timelines.

  • Define and maintain testing methodologies, playbooks, SOPs, and quality standards aligned to MITRE ATT&CK and industry frameworks.

  • Own quality assurance — review and sign off on all deliverables before client release.

  • Drive continuous improvement: internal tooling, R&D on new TTPs, and process efficiency.

  • Act as senior technical escalation point and the offensive-security point of contact for key accounts; support scoping, effort estimation, and pre-sales conversations.

Red Team & Offensive Operations

  • Execute advanced Red Team engagements and Black Box / Grey Box assessments that simulate real-world threat actors.

  • Run the full cyber-attack lifecycle: reconnaissance, attack-surface mapping, weaponization, exploitation, credential access, privilege escalation, lateral movement, persistence, and post-exploitation.

  • Design and operate C2 infrastructure (redirectors, OPSEC, egress) and develop payloads with AV/EDR evasion in mind.

  • Social Engineering: design and execute full-scope simulations — phishing, spear-phishing, vishing, smishing, and pretexting — including campaign design, payload delivery, and success/detection metrics.

  • Physical Red Team: plan and conduct operations — reconnaissance, tailgating, badge cloning/RFID attacks, lock bypass, and physical access to restricted areas and network drops, executed safely and within agreed rules of engagement.

  • Wireless / Wi-Fi: perform security assessments — rogue AP and evil-twin attacks, WPA2/WPA3 and PMKID/handshake capture and cracking, and wireless segmentation testing.

  • Dark Web & OSINT: conduct reconnaissance to surface leaked credentials, exposed assets, and threat-actor chatter to inform attack paths and report on organizational exposure.

  • Conduct advanced Network Penetration Testing, including firewall/segmentation bypass and attack-path chaining.

  • Execute Active Directory attacks — misconfigurations, Kerberoasting/AS-REP roasting, delegation and trust abuse, ADCS abuse (ESC1–8), DCSync, and domain/forest compromise.

  • Perform password and credential attacks using cracking and harvesting techniques.

  • Chain low/medium-severity issues into multi-stage, high-impact compromises.

  • (Preferred) Identify and exploit cloud attack paths across Azure AD/Entra ID, AWS, or GCP.

Reporting & Collaboration

  • Produce detailed Red Team reports with attack narratives, MITRE ATT&CK mapping, business impact, and actionable remediation guidance.

  • Collaborate with Blue Team/SOC in purple-team exercises to validate detections and strengthen defensive controls.

  • Work with cross-functional teams to integrate security measures and coordinate remediation.



Requirements

Required Skills & Technical Expertise

  • 5+ years in offensive security, Red Teaming, and Network Penetration Testing, with prior experience leading or mentoring a team.

  • Deep understanding of network architecture, TCP/IP, DNS, routing, segmentation, firewalls, and enterprise environments.

  • Strong Active Directory attack expertise across on-prem and hybrid environments.

  • Hands-on with C2 frameworks — Cobalt Strike, Sliver, Mythic, or Havoc.

  • Expertise in the Metasploit Framework (exploit development, payloads, chaining).

  • Proficiency with offensive tooling such as BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, Certipy, Mimikatz, Nmap, and Burp Suite.

  • Hands-on wireless attack tooling — Aircrack-ng suite, hcxdumptool/hcxtools, Hashcat, and rogue-AP frameworks (e.g., WiFi Pineapple/EAPHammer).

  • Social engineering campaign tooling and pretext development (e.g., GoPhish, Evilginx, or equivalent).

  • Scripting/automation ability in Python, PowerShell, Bash, and ideally C# or Go.

  • Working knowledge of AV/EDR evasion and OPSEC principles.

  • Strong report-writing and client-facing communication skills.

Good to Have

  • Certifications such as OSCP, OSEP, OSED/OSCE³, CRTO/CRTO II, CRTP/CRTE, GXPN, or GPEN.

  • Physical red teaming experience (RFID/badge attacks, covert entry) — with any relevant training/certification (e.g., a physical/covert-entry course).

  • Dark web monitoring / threat-intelligence and OSINT tooling experience.

  • Cloud offensive experience (Azure/Entra ID, AWS, GCP).

  • Familiarity with CERT-In and other regulatory/compliance testing requirements.

  • Public contributions — CVEs, tooling, research, blogs, or CTF/leaderboard results.



Benefits

Why You'll Enjoy Working at Kratikal

  1. Get the fast learning and exciting environment of a startup, combined with the stability and strong performance of a bigger company. There's lots of room to learn, grow, and share your ideas.

  2. We provide strong benefits including health insurance, gratuity, and Employees' Provident Fund (a savings plan for your future).

  3. We are an equal opportunity employer, where everyone has a fair chance.

About Us

Kratikal Tech Limited is a leading B2B cybersecurity firm offering cutting-edge cybersecurity solutions and services such as Network Security Audits, Compliance Implementation, IoT Security, and VAPT. Serving over 150+ enterprise customers and 1825+ SMEs across industries — including E-commerce, Fintech, BFSI, NBFC, Telecom, Consumer Internet, Cloud Service Platforms, Manufacturing, and Healthcare — Kratikal is dedicated to helping organizations combat cybercriminals using advanced, technology-driven cybersecurity solutions.

The company also develops in-house cybersecurity products, including AutoSecT, competing with industry giants, alongside TSAT (Threatcop Security Awareness Training), TDMARC (Threatcop DMARC), TLMS (Threatcop Learning Management System), and TPIR (Threatcop Phishing Incident Response). These products have received numerous awards and recognitions for their innovation and effectiveness. Kratikal has been honored as the Top Cyber Security Startup at the 12th Top 100 CISO Awards. With a global reach, Kratikal collaborates with renowned organizations to secure their digital landscapes.

For more information, visit www.kratikal.com and www.threatcop.com.



Skills Required

  • 5+ years in offensive security, Red Teaming, and Network Penetration Testing with prior team leadership or mentoring experience.
  • Deep understanding of network architecture, TCP/IP, DNS, routing, segmentation, firewalls, and enterprise environments.
  • Strong Active Directory attack expertise across on-prem and hybrid environments.
  • Hands-on experience with C2 frameworks (Cobalt Strike, Sliver, Mythic, or Havoc).
  • Expertise in the Metasploit Framework (exploit development, payloads, chaining).
  • Proficiency with offensive tooling: BloodHound, Impacket, CrackMapExec, Responder, Rubeus, Certipy, Mimikatz, Nmap, Burp Suite.
  • Hands-on wireless attack tooling: Aircrack-ng suite, hcxdumptool/hcxtools, Hashcat, rogue-AP frameworks (WiFi Pineapple/EAPHammer).
  • Social engineering campaign tooling and pretext development (e.g., GoPhish, Evilginx, or equivalent).
  • Scripting/automation ability in Python, PowerShell, and Bash (C# or Go ideal).
  • Working knowledge of AV/EDR evasion techniques and OPSEC principles.
  • Experience designing and maintaining testing methodologies, playbooks, SOPs aligned to MITRE ATT&CK.
  • Strong report-writing and client-facing communication skills; ability to sign off on deliverables and support pre-sales scoping.
  • Ability to plan capacity, allocate resources, monitor utilization, and drive continuous improvement and tooling R&D.
  • Experience executing full-scope Red Team engagements including physical red team operations, social engineering, and wireless attacks.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Noida, Uttar Pradesh
130 Employees
Year Founded: 2012

What We Do

Kratikal is an end to end cyber security solutions provider. It is the trusted partner for enterprises and individuals, seeking to protect their brand, business and dignity from baffling cyber attacks. We have been involved in the design, implementation of information security management systems since the time, standards were adopted by the industry. We approach IT security, cyber crime and penetration testing use cases from enterprise risk management perspective. We provide a complete suite of manual and automated VAPT security testing services as well as security audit like SOC 2, PCI DSS, HIPAA and ISO 27001. We have helped 1000+ companies including some Fortune 500 and leading startups across the globe. We are committed to engaging business leaders in developing and implementing cyber security technology with 24X7 support!

Similar Jobs

Clearwater Analytics (CWAN) Logo Clearwater Analytics (CWAN)

Senior Product Manager

Fintech • Software • Financial Services
Hybrid
Block Noida Authority Office, Sector 6, Gautam Buddha Nagar, Uttar Pradesh, IND
1100 Employees

Clearwater Analytics (CWAN) Logo Clearwater Analytics (CWAN)

Reconciliation Associate

Fintech • Software • Financial Services
Hybrid
Block Noida Authority Office, Sector 6, Gautam Buddha Nagar, Uttar Pradesh, IND
1100 Employees

Clearwater Analytics (CWAN) Logo Clearwater Analytics (CWAN)

Team Lead

Fintech • Software • Financial Services
Hybrid
Block Noida Authority Office, Sector 6, Gautam Buddha Nagar, Uttar Pradesh, IND
1100 Employees

Clearwater Analytics (CWAN) Logo Clearwater Analytics (CWAN)

Development Engineer

Fintech • Software • Financial Services
Hybrid
Block Noida Authority Office, Sector 6, Gautam Buddha Nagar, Uttar Pradesh, IND
1100 Employees

Similar Companies Hiring

Copia Automation Thumbnail
Cybersecurity • Industrial
New York, New York
50 Employees
SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account