Назад
Company hidden
5 дней назад

Manager, Security Posture Validation (Cybersecurity)

208 800 - 438 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Security Posture Validation (Cybersecurity): Building a continuous security-control validation platform and executive-facing posture dashboard for cloud infrastructure, web resources, and mobile applications with an accent on adversary emulation, automated testing, and measurable control efficacy. Focus on leading red and purple teams, converting attack paths into repeatable validation content, and proving remediation across AWS, Azure, OCI, Kubernetes, serverless, and mobile environments.

Location: San Jose, United States; fully in-person schedule up to 5 days a week

Base salary: $208,800–$438,000 annually, with potential additional bonuses, incentives, and restricted stock units.

Company

USDS Joint Venture operates a data privacy and cybersecurity program designed to protect U.S. user data, applications, algorithms, and the content ecosystem.

What you will do

  • Lead, mentor, and grow a specialized team of offensive security and privacy engineers.
  • Own the strategy, roadmap, and delivery of an in-house continuous security-control validation platform and posture dashboard.
  • Run red-team, adversary-emulation, and purple-team exercises across AWS, Azure, and OCI, converting attack paths and TTPs into automated validation content.
  • Design CI/CD-integrated and on-demand validation pipelines for controls such as HIDS and WAF across cloud, web, mobile, Kubernetes, and serverless environments.
  • Translate technical vulnerabilities and validation results into business risks, coverage metrics, SLA/SLI compliance, and remediation priorities for executive leadership, Legal, Risk & Compliance, and Engineering.
  • Define testing methodologies, SOPs, and Rules of Engagement while remaining hands-on with exploitation, reverse engineering, and custom tooling.

Requirements

  • 8+ years of experience in offensive security or privacy disciplines, including at least 3 years in formal people management or a lead role.
  • Expertise in cloud, mobile, and web application security across AWS, Azure, OCI, iOS, and Android.
  • Experience building adopted security tooling, automation, or platforms; knowledge of ISO 27001, NIST 800-53, PCI-DSS, adversary emulation, breach-and-attack simulation, and MITRE ATT&CK mapping.
  • Proficiency in at least two programming or scripting languages, such as Python, Golang, C++, Bash, or Java.
  • Advanced knowledge of Windows, Unix-like systems, and macOS, plus understanding of privacy-enhancing technologies and privacy-control bypasses.
  • Bachelor’s degree in Computer Science, Information Security, Computer Engineering, or a related technical field.

Nice to have

  • Security and privacy certifications such as OSCP, OSEP, GXPN, CIPP, CIPT, or CIPM.
  • Experience with Burp Suite Pro, Cobalt Strike, Frida, Objection, MobSF, SQLMap, or Nessus.
  • Security and privacy community contributions, including CVEs, bug bounty recognition, whitepapers, or conference presentations.
  • Experience with highly regulated or national-security-focused environments, including USDS or FedRAMP.

Culture & Benefits

  • Fully in-person work supports rapid decision-making, alignment, team development, and integrated execution.
  • Medical, dental, and vision insurance from day one, plus a 401(k) plan with company match.
  • Paid parental leave, short- and long-term disability coverage, life insurance, and wellbeing benefits.
  • 10 paid holidays, 10 paid sick days, and 17 days of paid personal time, with accrual increasing by tenure.
  • Work in a security-focused organization protecting U.S. user data and the content ecosystem.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →