Senior Manager, Attack Surface Reduction

Posted Yesterday
Be an Early Applicant
Hyderabad, Telangana, IND
In-Office
Senior level
Information Technology • Software • Consulting • Cybersecurity
The Role
Leads an offensive security team within an MSSP, overseeing attack surface discovery, application security testing, red teaming, adversarial simulations, vulnerability assessments, and ransomware resilience testing. Develops cybersecurity services, guides research and automation, and presents technical findings to executives. Requires deep expertise in offensive security, cloud and container security, CI/CD testing, exploit development, attack surface management, and security tooling, plus substantial leadership experience.
Summary Generated by Built In

As a Senior Manager of the Attack Surface Reduction (ASR) Team, you will lead an elite squad of highly technical security researchers and penetration testers. In the high-stakes environment of a Managed Security Service Provider (MSSP), this team is the frontline of defence and offense for our global clients.

You will be responsible for the end-to-end delivery of advanced security assessments, ranging from automated attack surface discovery to manual "Red Team" operations. This is a leadership role that requires technical depth, as you will guide experts in breaking into some of the most complex environments in the world to ensure they are unshakeable.



Key Responsibilities

  • Team Leadership: Lead, mentor, and scale a high-performance team of technical specialists. Foster a culture of continuous research, curiosity, and ethical hacking excellence.
  • Full-Spectrum Assessments: Oversee the execution of comprehensive security evaluations, both internally and externally for our client portfolio:
    • Application Security: DAST, SAST, SCA, both Black Box and Grey Box and deep-dive API security testing.
    • Offensive Operations: Red Teaming, Adversarial Simulations, and Breach & Attack Simulation (BAS).
    • Vulnerability Management: Advanced VAPT (Vulnerability Assessment & Penetration Testing)
    • Defensive Validation & Resiliency Testing: Ransomware Resiliency testing to ensure clients can withstand and recover from modern extortion tactics.
  • Attack Surface Discovery: Direct the continuous mapping of known and unknown digital assets to identify shadow IT and exposed entry points.
  • Service Innovation: Develop and refine the MSSP service catalogue. Identify emerging threats and translate them into new testing methodologies and cybersecurity services.
  • Stakeholder Management: Act as the technical authority during high-level client briefings, translating complex technical findings into actionable executive risk reports.



Requirements

Technical Requirements

  • Experience: 10+ years in Offensive Security, with at least 3–5 years in a formal leadership/management role.
  • Expertise: Deep technical mastery of the "Attacker Mindset." You should be comfortable discussing advanced exploitation techniques, CI/CD pipeline vulnerabilities, and hybrid or cloud-native lateral movement in the same breath.
  • Tooling & Frameworks: Proficiency in modern toolkits (Burp Suite, Metasploit, Cobalt Strike, etc.).
  • Expertise in BAS platforms and Attack Surface Management (ASM) tools.
  • Experience with Cloud Security (AWS/Azure/GCP) and container security (Docker/K8s).
  • Firm grasp of the MITRE ATT&CK framework.
  • Certifications: Preferred: OSCE, OSEP, GXPN, or CISSP/CCSP/CISM.

Required Development & Automation Skills

  • Security Tooling Development: Proficiency in Python or Go (Golang) to build custom scanners, exploit wrappers, and automation scripts.
  • Infrastructure as Code (IaC): Solid understanding of Terraform or Ansible to rapidly spin up (and tear down) complex "range" environments for Red Team simulations and Ransomware Resiliency testing.
  • Dev-Sec-Ops & CI/CD Integration: Deep knowledge of how to integrate SAST/DAST/SCA tools directly into GitLab, GitHub Actions, or Jenkins pipelines without breaking the developer workflow.
  • API Mastery: Advanced ability to interact with, test, and develop against RESTful and Graph-QL APIs. This includes writing custom scripts to automate mass API vulnerability discovery.
  • Cloud-Native Development: Familiarity with Serverless (AWS Lambda/Azure Functions) and Containerization (Docker/Kubernetes) to identify and exploit misconfigurations in modern microservices architectures.
  • Exploit Development Basics: Understanding of low-level languages like C/C++ or Rust to oversee the team when they are performing deep-dive binary analysis or bypass research.
  • Data Engineering for Security: Ability to work with SQL/NoSQL and ELK stacks (Elasticsearch, Logstash, Kibana) to aggregate and analyse the massive amounts of data generated during Attack Surface Discovery.


Soft Skills & Leadership

  • Candor & Clarity: The ability to give direct, constructive feedback to a highly technical team while maintaining high morale.
  • Strategic Vision: Moving beyond "finding bugs" to helping clients build long-term Resilience Frameworks.

·       Technical Depth: You must be able to "speak the language" of highly technical researchers to earn their respect and provide valid guidance.

·       Pressure Management: Thriving in the fast-paced, 24/7 nature of an MSSP.





Benefits

Why Join Us?

You aren't just managing a team; you are architecting the future of offensive security. You will have access to diverse environments, cutting-edge "Advanced Technologies," and you’ll drive red-team strategies and emulate real-world adversaries to ensure clients stay ahead of the global threat landscape.



Skills Required

  • 10+ years of experience in offensive security
  • 3-5 years of formal leadership or management experience
  • Advanced offensive security and attacker-mindset expertise
  • Proficiency with Burp Suite, Metasploit, Cobalt Strike, or comparable security toolkits
  • Experience with breach and attack simulation platforms and attack surface management tools
  • Cloud security experience across AWS, Azure, or GCP
  • Container security experience with Docker and Kubernetes
  • Strong understanding of the MITRE ATT&CK framework
  • Proficiency in Python or Go for security tooling and automation
  • Understanding of Terraform or Ansible for infrastructure as code
  • Deep knowledge of integrating SAST, DAST, and SCA into GitLab, GitHub Actions, or Jenkins pipelines
  • Advanced REST and GraphQL API testing and development skills
  • Familiarity with serverless platforms and cloud-native microservices
  • Understanding of C, C++, or Rust for binary analysis and exploit research oversight
  • Experience with SQL or NoSQL and ELK stacks for security data analysis
  • OSCE, OSEP, GXPN, CISSP, CCSP, or CISM certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
99 Employees
Year Founded: 2022

What We Do

NopalCyber provides integrated offensive and defensive cybersecurity solutions for organizations seeking resilience and compliance. Its offerings include managed extended detection and response, attack surface management, breach and attack simulation, advisory services, and 24/7 security operations. AI-driven products such as Nopal360°, NopalGo, and Cyber Intelligence Quotient help clients quantify, visualize, and reduce cyber risk across their IT environments while tailored service packages broaden access to enterprise-grade protection.

Similar Jobs

CSC Logo CSC

Database Administrator

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
8500 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees

Yext Logo Yext

Treasury Analyst

Artificial Intelligence • Information Technology • Internet of Things • Marketing Tech • Social Media • Software • SEO
Easy Apply
In-Office
Hyderabad, Telangana, IND
1100 Employees

Wells Fargo Logo Wells Fargo

Consultant

Fintech • Financial Services
Hybrid
Hyderabad, Telangana, IND
205000 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account