Assistant manager - Vulnerability Management
Core
Offensive Security Assistant Manager executing and maturing Unilever's offensive security program through hands-on penetration testing, red teaming support, and MSSP governance.
Role type
Senior IC offensive security engineer (penetration testing & red teaming)
Builds
Offensive security program, attacker-driven insights, External Attack Surface Management (EASM), Deception technologies, and Decoys
Domain
Cybersecurity, Offensive Security, Cloud Security, OT Security
Required skills
manual penetration testing (web, API, mobile), OWASP Top 10, API security, authentication/authorization flaws, business logic issues, MITRE ATT&CK, red teaming techniques, cloud security vulnerabilities (Azure/AWS/GCP), vulnerability management, risk-based prioritization, AI security risks, OT concepts
Preferred skills
red teaming or adversary simulations, external pentest vendors/MSSPs management, cloud environments, modern application architectures, frameworks (OWASP, MITRE ATT&CK, NIST), OSCP/GPEN/GWAPT/CEH certifications
Technologies
Azure, AWS, GCP
Responsibilities
Perform penetration testing across web, APIs, mobile, and cloud environments; Support red teaming and adversary simulation activities; Drive pentest lifecycle execution – scoping, planning, access coordination, tracking, and closure; Coordinate with external vendors/MSSPs; Review and challenge pentest findings for accuracy, severity, and business impact; Support risk-based prioritization and remediation tracking; Oversee AI, OT and other factory related offensive testing; Manage deception tech platform
Seniority
Senior, hands-on IC