Assistant manager - Vulnerability Management
Core
Offensive Security Assistant Manager executing and maturing Unilever's offensive security program through hands-on penetration testing, red teaming support, and MSSP governance.
Role type
Senior IC offensive security engineer (penetration testing & red teaming)
Builds
Offensive security program, attacker-driven insights, External Attack Surface Management (EASM), Deception technologies, and Decoys
Domain
Cybersecurity, Offensive Security, Cloud Security, OT Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
manual penetration testing (web, API, mobile), OWASP Top 10, API security, authentication/authorization flaws, business logic issues, MITRE ATT&CK, red teaming techniques, cloud security vulnerabilities (Azure/AWS/GCP), vulnerability management, risk-based prioritization, AI security risks, OT concepts
Preferred skills
red teaming or adversary simulations, external pentest vendors/MSSPs management, cloud environments, modern application architectures, frameworks (OWASP, MITRE ATT&CK, NIST), OSCP/GPEN/GWAPT/CEH certifications
Technologies
Azure, AWS, GCP
Responsibilities
Perform penetration testing across web, APIs, mobile, and cloud environments; Support red teaming and adversary simulation activities; Drive pentest lifecycle execution – scoping, planning, access coordination, tracking, and closure; Coordinate with external vendors/MSSPs; Review and challenge pentest findings for accuracy, severity, and business impact; Support risk-based prioritization and remediation tracking; Oversee AI, OT and other factory related offensive testing; Manage deception tech platform
Seniority
Senior, hands-on IC