Find Jobs
Find Jobs Near You – Available Work in Your Location
Red Team Manager
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on New Jersey data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$124,644 / year median in New Jersey
+3% projected growth
Job Description
- Own and continuously evolve the enterprise Red Team program, including adversary emulation, threat informed testing, and advanced offensive security assessments.
- Lead, mentor, and develop a team of Red Team professionals through hiring, performance management, coaching, and career development.
- Design and execute realistic Red Team and Purple Team engagements, including assumed breach scenarios, intelligence driven campaigns, and AI related attack simulations.
- Assess risks introduced by AI, automation, and data driven systems, incorporating those risks into offensive security testing strategies.
- Ensure all Red Team activities are conducted safely, ethically, and within defined operational guardrails to minimize business disruption and risk.
- Partner with Cybersecurity Operations, Detection Engineering, Security Architecture, and Technology teams to strengthen detection capabilities, response procedures, and security controls.
- Define standards, tools, processes, and performance metrics for Red Team operations, balancing custom developed capabilities with commercial platforms and emerging AI security technologies.
- Translate findings into actionable risk mitigation recommendations and communicate results effectively to technical stakeholders and senior leadership.
- Support audit, compliance, risk management, and regulatory activities through threat informed testing and control validation.
- Maintain awareness of evolving threat actor tactics, techniques, and procedures, applying industry best practices to Red Team operations. Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or an equivalent combination of education and experience.
- 8+ years of progressive cybersecurity experience, including at least 5 years in offensive security, Red Team operations, adversary emulation, or penetration testing within a mid to large enterprise environment.
- 3+ years of people leadership experience managing senior security engineers, Red Team practitioners, or offensive security teams.
- Demonstrated experience leading complex Red Team and Purple Team engagements, including intelligence driven campaigns and assumed breach operations.
- Strong understanding of attacker methodologies, enterprise attack paths, and modern offensive security frameworks.
- Experience assessing AI security risks and conducting security testing of AI enabled products, services, applications, or workflows.
- Proven success translating offensive security findings into measurable improvements in detection, response, and overall security posture.
- Experience operating within highly regulated or risk sensitive environments.
- Strong communication, presentation, and stakeholder management skills, including the ability to influence senior leaders and drive cross functional collaboration. Preferred Qualifications
- Experience developing custom offensive security tools, automation, or adversary simulation capabilities.
- Familiarity with cloud security testing across AWS, Azure, and Google Cloud environments.
- Experience testing identity platforms, enterprise SaaS applications, and modern application architectures.
- Knowledge of threat intelligence integration and threat informed defense methodologies. Certifications One or more of the following certifications are preferred:
- OSCP, Offensive Security Certified Professional
- OSCE, Offensive Security Certified Expert
- OSEP, Offensive Security Experienced Penetration Tester
- OSED, Offensive Security Exploit Developer
- CRTO, Certified Red Team Operator
- CRTP, Certified Red Team Professional
GXPN, GIAC
Exploit Researcher and Advanced Penetration Tester- AI security, AI red teaming, or equivalent emerging cybersecurity certifications Success Measures
- Improved detection and response effectiveness resulting from Red Team and Purple Team engagements.
- Demonstrated maturity and effectiveness of the enterprise Red Team program.
- Strong partnership with cybersecurity, technology, and business stakeholders.
- Measurable reduction in critical security gaps through threat informed testing and validation efforts.