Senior Manager, Offensive Security
Vanguard•19h ago
United StatesHybridFull-timeManager Level5+ yrs exp
Top focus
Security EngineerSecurity Architect
The Senior Manager, Offensive Security leads our advanced offensive security program within the Offensive Security & Fraud Testing (OSFT) team. This role oversees all offensive security operations – including full-scope Red Team engagements , targeted penetration testing , AI-augmented offensive security initiatives – with the mission of proactively identifying vulnerabilities and strengthening the organization’s defenses.
Success in this role is measured by the maturity and impact of our offensive security program: meaningful risk reduction, improved detection & response capabilities, strong stakeholder trust, and continuous team development
Key Responsibilities
- Offensive Security Program Leadership: Define and drive the strategic vision for offensive security testing, translating high-level cyber risk objectives into actionable testing plans and operations .
- Establish annual roadmaps for red teaming, and pen testing exercises aligned with emerging threats and business priorities.
- Team Management & Development: Lead and coach a geographically distributed team of offensive security professionals.
- Oversee hiring, performance management, and skill development , ensuring a high-performing, collaborative culture.
- Foster innovation within the team by encouraging the adoption of new techniques (e.g., AI-driven tools ) and by mentoring staff in advanced offensive tradecraft.
- Operational Oversight & Execution: Plan, scope, and approve complex offensive engagements such as Red Team operations ensuring they are conducted safely, ethically, and with clear goals.
- Oversee GenAI-enabled offensive security projects , setting guidelines for responsible use of AI/automation as force multipliers in our operations.
- Provide hands-on guidance when needed, leveraging your own red team experience to support critical operations or complex exploit development.
- Purple Team & Cross-Functional Collaboration: Coordinate Purple Team exercises that bring together our offensive team with CSOC Team and fraud teams to test and improve detective controls.
- Serve as the primary liaison with defensive stakeholders, ensuring findings are immediately actionable and bridging gaps between offense and defense .
- Champion a partnership approach – sharing threat intelligence, aligning on TTPs (Tactics, Techniques, Procedures) to emulate, and jointly prioritizing remediation efforts.
- Reporting & Program Governance: Ensure comprehensive documentation and communication of all offensive testing activities and outcomes.
- Review and finalize detailed reports for each engagement, highlighting identified vulnerabilities, their business impact, and recommended fixes.
- Present program results and risk insights to senior security leadership and risk governance forums.
- Continuously refine methodologies , enforce adherence to frameworks (e.g., MITRE ATT&CK , internal policies)
- track metrics to measure program effectiveness (coverage of attack surface, detection rates, time-to-remediation, stakeholder satisfaction).
- Strategic Improvement & Innovation: Identify opportunities to expand or enhance the program – such as integrating new offensive techniques, improving automation
- refining Purple Team processes – and drive these initiatives to increase program maturity.
- Stay current on industry trends and ensure our team remains at the forefront of offensive security practices , especially regarding AI augmentation, cloud security, and evolving threat landscapes .
- Required Qualifications: Offensive Security Expertise: 10+ years in penetration testing, red teaming, or adversary simulation , with proven success as a hands-on operator delivering high-impact engagements.
- Deep knowledge of network, application, and cloud security vulnerabilities, exploitation techniques, and attacker methodologies (MITRE ATT&CK, kill chain, etc.).
- Leadership & Program Management: 3+ years of experience leading offensive security teams or programs .
- Demonstrated ability to manage and develop high-performing teams , including setting goals, mentoring senior engineers, and attracting top talent.
- Skilled in strategic planning and multi-project management – able to prioritize and allocate resources to meet objectives across simultaneous operations AI & Automation Familiarity: Exposure to or strong interest in AI/ML technologies and security automation .
- While not a data scientist, you understand how generative AI and tools like LLMs can be leveraged in offensive security (e.g. for recon or automating tasks).
- Experience overseeing or implementing innovative solutions (like advanced scripting, C2 frameworks, or integrating AI agents) in security testing is a plus.
- Stakeholder Engagement & Communication: Excellent communication skills with both technical and executive audiences.
- Able to clearly articulate risk and influence senior stakeholders to take action on security findings.
- Experience collaborating with defensive security teams, fraud/risk teams, and engineering groups to drive remediation and improve security posture.
- A track record of building trust and credibility through transparency and consistency in execution.
- Education & Certifications: Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
- Relevant certifications (e.g., OSCP,CISSP , GIAC GPEN, CRTO) that demonstrate both offensive technical depth and security management knowledge are strongly preferred.
- Special Factors Sponsorship Vanguard is not offering visa sponsorship for this position.
- About Vanguard At Vanguard, we don't just have a mission—we're on a mission.
- To work for the long-term financial wellbeing of our clients.
- To lead through product and services that transform our clients' lives.
- To learn and develop our skills as individuals and as a team.
- From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
- How We Work Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection.
- We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.
Required skills
LLMSecurity