Senior Manager Offensive Security

Posted 2 Days Ago
Be an Early Applicant
Headquarters, AZ, USA
In-Office
Senior level
Insurance
In a world made up of devices, screens, and power buttons, when something breaks, Asurion steps in to help.
The Role
Leads the offensive security and penetration testing function across applications, APIs, mobile, cloud, networks, infrastructure, and business services. Manages testing intake, prioritization, delivery quality, reporting, remediation tracking, governance, and continuous improvement. Directly manages and develops penetration testers and offensive security engineers while translating technical findings into business risk. Partners with engineering and infrastructure teams on secure development and remediation, and evaluates AI-enabled and agentic testing capabilities.
Summary Generated by Built In
The Senior Manager, Offensive Security leads Asurion's offensive security testing function. Reporting to the Director of Application & Offensive Security, this leader is accountable for the intake, prioritization, execution, and quality of penetration testing across web and mobile applications, APIs, cloud environments, internal and external infrastructure, and supporting business services. This position balances hands-on technical leadership with people management, ensuring engagements are scoped effectively, delivered on schedule, and reported with findings that drive measurable risk reduction. The Senior Manager translates technical results into clear business risk for engineering, product, and security leadership, and partners closely with development, cloud, and infrastructure teams to ensure findings are understood and remediated.
Key Responsibilities
  • Penetration Testing Operations and Queue Management: Own the end-to-end penetration testing intake and delivery pipeline. Manage the testing queue, triage and prioritize incoming requests based on risk, business criticality, regulatory drivers, and release timelines, and balance workload across the team to meet commitments. Establish and maintain a repeatable engagement lifecycle covering scoping, rules of engagement, execution, reporting, retesting, and closure.
  • Technical Delivery and Quality Assurance: Oversee the execution of application, API, mobile, cloud, network, and infrastructure penetration tests. Set standards for testing rigor, evidence collection, exploit validation, and finding reproducibility. Review deliverables for technical accuracy, clarity, and actionable remediation guidance, and personally lead or contribute to complex, high-sensitivity engagements when needed.
  • People Leadership and Team Development: Manage, coach, and grow a team of penetration testers and offensive security engineers. Set clear goals and performance expectations, provide regular feedback, support career development and technical skill growth, and cultivate a culture of curiosity, integrity, and continuous learning. 
  • Risk Reporting and Stakeholder CommunicatiSenior Manager, Offensive Securityon: Produce clear, decision-oriented reporting on penetration testing outcomes, trends, systemic weaknesses, and remediation progress. Translate technical findings into business risk language for engineering leaders, product owners, and security leadership. Track findings to closure, support risk acceptance and exception decisions where appropriate, and contribute to consolidated security reporting and metrics that demonstrate the program's impact.
  • Remediation Partnership and Secure Development Enablement: Partner with application development, DevOps, cloud, and infrastructure teams to ensure findings are understood, prioritized, and remediated. Provide guidance on root cause and durable fixes rather than one-off patches, and feed recurring patterns back into secure SDLC practices, threat modeling, and developer education.
  • Agentic and AI-Enabled Testing (Emerging Focus): Explore, pilot, and progressively develop an agentic penetration testing capability. Evaluate AI-assisted and autonomous offensive security tooling, define where automation can safely and effectively extend coverage, establish guardrails and validation processes for AI-generated findings, and build a roadmap that matures this capability over time while preserving the judgment and depth of human testers. Stay current on the evolving offensive AI landscape and represent Asurion's forward-looking approach to internal stakeholders.
  • Program Governance and Continuous Improvement: Maintain testing standards, tooling, and documentation, and continuously improve throughput, coverage, and quality. Ensure the program supports audit, compliance, and regulatory requirements, and coordinate with vulnerability management, exposure management, and incident response functions to align offensive testing with the broader security program.

Education and Experience
  • Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 8+ years of experience in information security, with 5+ years focused on penetration testing, offensive security, or red team operations.
  • 3+ years of experience leading technical teams or engagements, including direct people management, workload prioritization, and delivery accountability.
  • Demonstrated experience scoping and executing penetration tests across multiple domains such as web and mobile applications, APIs, cloud platforms, and internal/external network infrastructure.
  • Experience translating technical findings into executive- and business-level risk communications and driving remediation with engineering partners.
  • Preferred: Experience building or scaling a penetration testing function; familiarity with AI-assisted, autonomous, or agentic security tooling; regulated industry experience (e.g., financial services, insurance, healthcare, technology, or critical infrastructure); and contribution to secure SDLC and developer enablement initiatives.

Knowledge, Skills, and Abilities
  • Deep technical fluency in offensive security across application security and secure SDLC, cloud security, API and integration security, network and infrastructure testing, identity and access exploitation, and post-exploitation techniques.
  • Working command of recognized testing methodologies and standards, including NIST SP 800-115, PTES, the OWASP testing guides (including the OWASP Top 10 and API Security Top 10), and MITRE ATT&CK.
  • Strong understanding of detection engineering, EDR bypass, and purple teaming to improve control efficacy.
  • Familiarity with the NICE Workforce Framework for Cybersecurity (NIST SP 800-181) to help define penetration testing competencies, role expectations, and skill development paths for the team.
  • Hands-on proficiency with common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Cobalt Strike or equivalent, cloud-native testing tools) and comfort scripting and automating with languages such as Python.
  • Strong risk judgment and the ability to distinguish theoretical weaknesses from material, exploitable business risk, and to recommend pragmatic, prioritized remediation.
  • Effective people leadership, including coaching, performance management, capacity planning, and the ability to attract, grow, and retain highly skilled technical talent.
  • Clear written and verbal communication skills, with the ability to produce concise, decision-oriented reporting and influence engineering and security stakeholders without direct authority.
  • Curiosity and adaptability to evaluate emerging capabilities, including AI-enabled and agentic testing, and to responsibly integrate new methods into an established program.
  • Ownership mindset to drive engagements and findings to closure, maintain quality under resource constraints, and ensure transparent, well-documented risk decisions.

Skills Required

  • Bachelor's degree in Information Security, Computer Science, Information Technology, Engineering, a related field, or equivalent practical experience
  • 8+ years of experience in information security
  • 5+ years focused on penetration testing, offensive security, or red team operations
  • 3+ years leading technical teams or engagements, including people management, workload prioritization, and delivery accountability
  • Experience scoping and executing penetration tests across web and mobile applications, APIs, cloud platforms, and internal/external network infrastructure
  • Experience translating technical findings into executive- and business-level risk communications and driving remediation with engineering partners
  • Experience building or scaling a penetration testing function
  • Familiarity with AI-assisted, autonomous, or agentic security tooling
  • Regulated industry experience, such as financial services, insurance, healthcare, technology, or critical infrastructure
  • Experience contributing to secure SDLC and developer enablement initiatives

Asurion Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Asurion and has not been reviewed or approved by Asurion.

  • Fair & Transparent Compensation Pay is often described as solid or competitive in certain corporate and technical tracks, with some roles viewed as aligned to market ranges.
  • Strong & Reliable Incentives Short-term incentives and bonus structures are described as a meaningful layer on top of base pay, increasing total compensation when targets are met.
  • Healthcare Strength Medical, dental, and vision offerings are described as inclusive and broad, with additional protections like life/AD&D and disability coverage available.

Asurion Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Nashville, Tennessee
18,000 Employees
Year Founded: 1994

What We Do

We're a global tech care company keeping nearly every device and appliance in your home running smoothly. Trusted by more than 100 leading brands and serving over 230M customers worldwide, we deliver tech support, repair, protection, and replacements at a massive scale. From your neighborhood uBreakiFix by Asurion repair store, to in-home tech support, to global protection plans, we’re the people keeping your tech connected when it matters most.

Why Work With Us

As Asurion, you will work with people who care about you and the work we do together. You can depend on us to care about the work you do.

Gallery

Gallery

Similar Jobs

PwC Logo PwC

Systems Engineer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
62 Locations
370000 Employees
155K-410K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
45 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

CTIO - Product Management - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
63 Locations
370000 Employees
151K-187K Annually

Cloudflare Logo Cloudflare

Senior Director, R&D HR Business Partnering

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
4400 Employees

Similar Companies Hiring

Globe Life Thumbnail
Insurance • Financial Services
McKinney, TX
3000 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account