Offensive Security Manager
CurrentPenetration and Security testing across teams and systems− Identify critical BU, sites and systems which are at highest risk in terms of security.− Create a plan for performing security testing on those BU.− For each test, create a scoping document with network, application and scenario scoping. − Support and execute the testing (whether in-house or external).− Create comprehensive and clear reports on tests output.− Validate all finding with the BU and agree on action items for fixing.Automate possibilities for security testing by implementing security tools− Application level (web application scanners, mobile application scanners, dynamic analysis). − System level (OS vulnerability scanners, TLS/SSL scanners).− Network level (port scanning, network security scanners, wireless security).− End users level (social engineering campaign platform).Provide hands-on training to technical staff on offensive techniques as part of their role− Security team (engineering roles).− QA engineers (application security).− IT administrators (system and network security).Tracking, reviewing, and assuring the mitigation of security vulnerabilities as a result of the penetration testing− Setting up ticketing system for security purposes.− Following up and linking security internal tickets with BU tickets for mitigation. − Providing statistics for mitigation timelines.Provide consultation for different BU in topics of offensive security when needed and based on capacity− Regulator based security testing and scans. − Customers security tests and scans.