Para estar informado sobre nuestras oportunidades de empleo:
    Únete a nuestra Red de Talentos

    Offensive Security Manager – Penetration & Red Team

    London, England, United Kingdom

    Offensive Security Manager – Penetration & Red Team

    • 202407238
    • London, England, United Kingdom
    • Closing on: Jan 10 2025

    Description

    The Offensive Security Manager is responsible for the provision of penetration & red team testing services to the business, including leading teams, creating processes, and management of technologies & 3rd parties that make up the service. The role reports to the Director of Offensive Security.

    The position does not need to be filled by a hands-on penetration/red tester, as organizational, leadership. relationship and supplier management skills are the key focuses of the role but will need to have a good understanding of security vulnerabilities and testing methodology to be able to understand the subject matter of the service and manage quality.
    The role will work closely alongside the rest of the Cyber Team (e.g. Vulnerability Management), the wider Information & Cyber Security function (e.g. Project Assurance) and leaders in operational IT teams to ensure accurate detection, and the prioritized, timely and appropriate resolution of security vulnerabilities. 

    We are looking for a collaborative team player, with a good technical knowledge and the ability to lead others and experience working with 3rd party service providers. The successful candidate will contribute to and work as part of a global multi-disciplined security community with clear vision and direction, and top-down support across the business. They will help the wider community in fostering a culture which is both security aware and is a great place to come to work.

    Responsibility: 
    •    Create, maintain and execute appropriate security testing processes to enable timely detection, risk-based prioritization, and co-ordinate the remediation of security testing findings.
    •    Penetration Assessments:  To plan and execute complex assessments to identify vulnerabilities, weaknesses and misconfigurations for technologies used within the network environment.
    •    Red Team Assessments:  To plan complex assessments to identify vulnerabilities, weaknesses and misconfigurations for technologies used within the network environment
    •    Work with service providers to conduct the penetration/red team testing activities on time & budget.
    •    Manage the quality-of-service provider output, and work with them to ensure the business receives a reliable and efficient service.
    •    Provide clear, concise and easily consumable communication with key technical and non-technical stakeholders so that findings are understood and appropriately addressed.
    •    Measure and report the maturity, effectiveness and efficiency of Security Testing services
    •    Ensure accurate and clear communication with all stakeholders.
    •    Provide appropriate MI to key stakeholders.
    •    Ethical Approach: Conducting all testing and assessment activities within a legal and ethical framework, ensuring that the organization's systems and data are not compromised or harmed during the process.
    •    Continuous Improvement: Engaging in professional development activities, such as attending conferences, participating in training programs, and obtaining relevant certifications, to enhance knowledge and skills in cyber security.
     

    Qualifications

    The Requirements: 

    •    Demonstrable track record of:
    o    Leading security services within a large organization
    o    Scoping and managing penetration testing activities
    o    Building and leading effective security teams


    •    Excellent technical expertise in:
    o    Application and infrastructure security principles
    o    Frameworks & methodologies such as CVSS, CIS Benchmarking, OWASP 


    •    Beneficial qualifications include:
    o    CISSP
    o    CISA
     

    At WTW, we believe difference makes us stronger. We want our workforce to reflect the different and varied markets we operate in and to build a culture of inclusivity that makes colleagues feel welcome, valued and empowered to bring their whole selves to work every day. We are an equal opportunity employer committed to fostering an inclusive work environment throughout our organisation. We embrace all types of diversity.

    Apply Now

    ¿No tú?

    Gracias

    Contacto no solicitado

    Todos los CV/perfiles de candidatos no solicitados que se presenten a través de nuestro sitio web o de cuentas de correo electrónico personales de empleados de Willis Towers Watson se consideran propiedad de Willis Towers Watson y no pagarán honorarios de agencia. Para poder ser una agencia/compañía de búsqueda de personal para Willis Towers Watson, dicha agencia debe contar con un acuerdo formal existente y por escrito firmado por un agente de selección de personal de Willis Towers Watson y una relación laboral activa con la organización. Los CV se deben presentar de forma tal que cumplan con el proceso de presentación del candidato, que incluye participar activamente en la búsqueda específica. Del mismo modo, para nuestras agencias de selección/búsqueda de personal, si no se cumple con los pasos del proceso de presentación del candidato, Willis Towers Watson no pagará honorarios de agencia. Willis Towers Watson sigue el principio de igualdad de oportunidades en la contratación. Si deseara que la compañía guarde su información de contacto para su consideración en el futuro, envíe un correo electrónico a: Agency.inquiries@willistowerswatson.com .

    Nuestras oficinas

    Nuestros colegas brindan servicios en más de 140 países y mercados en todo el mundo. Esto da una dimensión global a todo lo que hacemos y crea muchas oportunidades interesantes para que colabores y crezcas. Consulta el mapa a continuación para ver a dónde podría llevarte tu carrera.

    Conozca a nuestra gente