Application Penetration Testing Manager
Core
Lead complex application penetration testing engagements, shape service offerings, and develop people within the Network Information Security team to help organizations manage application security risk.
Role type
Manager, Application Penetration Testing
Builds
Application security assessments for web, mobile, API, and cloud-native environments
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security frameworks (OWASP Top 10, API Top 10, MASVS), vulnerability exploitation (SQL injection, XSS, CSRF, SSTI, IDOR, authN/authZ flaws), manual testing techniques (business logic abuse, multi-step workflows), automated testing tools (Burp Suite Pro, ZAP, proxy tools), SAST/DAST/IAST, cloud platforms (AWS, Azure, GCP), microservices/container/serverless architectures, AI-assisted security testing
Preferred skills
Secure SDLC integration, threat modelling, code review, developer training, service development methodologies
Technologies
IIS, Apache, Nginx, Java, .NET, Node.js, REST, SOAP, GraphQL, Windows, Linux, WAFs, load balancers, reverse proxies
Responsibilities
Lead end-to-end application penetration testing engagements from scoping to reporting; manage small to medium-sized teams of testers; review and refine technical reports for clarity and actionable remediation; communicate complex technical concepts to technical and non-technical stakeholders; build and maintain strong client relationships; balance project economics while maintaining quality standards; create a positive team climate by monitoring workloads and supporting team growth.
Seniority
Manager, hands-on leadership