Назад
Company hidden
7 часов назад

Manager, Security Posture Validation (Cybersecurity)

168 336 - 394 200$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Security Posture Validation (Cybersecurity): Building an in-house continuous control-validation platform and executive-facing security posture dashboard with an accent on adversary emulation, automated testing, and measurable control efficacy. Focus on leading red and purple teams, validating controls across cloud, web, and mobile environments, and translating findings into remediation metrics and business risk.

Location: Washington, D.C.; fully in-person schedule up to 5 days per week

Salary: $168,336–$394,200 annually, plus potential discretionary bonuses, incentives, and restricted stock units.

Company

hirify.global operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the content ecosystem.

What you will do

  • Lead, mentor, and grow a specialized team across red teaming, purple teaming, offensive security, and control-validation engineering.
  • Own the strategy, roadmap, and delivery of an in-house continuous control-validation platform with an executive-facing posture dashboard.
  • Convert adversary-emulation exercises, attack paths, and TTPs into automated, repeatable validation content across OCI, AWS, Azure, web, and mobile environments.
  • Design CI/CD-integrated and on-demand validation pipelines for continuous control monitoring and self-service testing.
  • Partner with executive leadership, Legal, Risk & Compliance, Engineering, Blue Teams, and control owners to communicate risk and drive remediation.
  • Define testing methodologies, SOPs, ROEs, coverage mappings, SLAs, efficacy metrics, and remediation-velocity reporting.

Requirements

  • 8+ years of experience in offensive security or privacy disciplines, including at least 3+ years in formal people management or a lead role.
  • Expertise across AWS, Azure, OCI, iOS, Android, and web application security.
  • Experience building adopted security tooling, automation, or platforms; knowledge of ISO 27001, NIST 800-53, PCI-DSS, adversary emulation, breach-and-attack simulation, and MITRE ATT&CK mapping.
  • Understanding of privacy-enhancing technologies and privacy-control bypasses or data leakage risks.
  • Proficiency in at least two programming or scripting languages, such as Python, Golang, C++, Bash, or Java.
  • Advanced knowledge of Windows, *nix, and macOS, plus a bachelor's degree in a related technical field.

Nice to have

  • OSCP, OSEP, GXPN, CIPP, CIPT, or CIPM certifications.
  • Experience with Burp Suite Pro, Cobalt Strike, Frida, Objection, MobSF, SQLMap, or Nessus.
  • Security or privacy community contributions, such as CVEs, bug bounty recognition, whitepapers, or conference speaking.
  • Experience with regulated or national-security-focused environments, including USDS or FedRAMP.

Culture & Benefits

  • Day-one access to medical, dental, and vision insurance.
  • 401(k) savings plan with company match, paid parental leave, disability coverage, and life insurance.
  • 10 paid holidays, 10 paid sick days, and 17 days of paid personal time, with increasing accruals by tenure.
  • Inclusive workplace with reasonable accommodations available during recruitment.
  • In-person collaboration focused on speed, alignment, real-time decision-making, and integrated execution.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →