> Markdown version of [/jobs/ext/1143988-cloud-security-test-manager](https://www.wearedevelopers.com/jobs/ext/1143988-cloud-security-test-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Test Manager - **Company:** Enphase Energy - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Continuous Integration, Emulators, Identity and Access Management, Python (Programming Language), Key Management, Open Web Application Security, Role-Based Access Control, Web Applications, Scripting, Cloud Platform System, Mitre Att&ck, Multi-Cloud, GWAPT, Kubernetes, Information Technology, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** July 2, 2026 - **Apply:** http://app.jobvite.com/CompanyJobs/Careers.aspx?c=qu49Vfwm&j=o75nAfwT&k=Apply ## About the Role * BE/BTech/MS/MTech in Computer Science, Electrical Engineering, or a related field. * A minimum of 10+ years of experience in application/cloud security testing, with * 5+ years leading security or red-team functions * Strong experience with SAST, DAST, and SCA tooling, CI/CD integration, rule tuning, and triage at scale * Hands-on manual penetration testing of web apps, APIs, microservices, and cloud environments, with exploit/PoC development * Expertise in threat modeling frameworks (STRIDE, PASTA) and attack surface analysis * Strong experience in red-team operations, adversary emulation (MITRE ATT&CK), C2 frameworks, and purple-team collaboration * Deep understanding of cloud security across AWS/GCP/Azure - IAM and identity, network controls, container/Kubernetes (RBAC, escapes), serverless, and secrets management * Knowledge of OWASP Top 10 / API Top 10 and CVE disclosure processes * Familiarity with security standards such as IEC 62443, EU Cyber Resilience Act, SOC 2, ISO 27001 * Excellent leadership, communication, and stakeholder management skills * Proficiency in scripting (Python, Bash) for security automation and custom tooling Nice to have: * Experience in exploit development and custom security tooling * Understanding of IoT to cloud security and trust boundaries * Experience building DevSecOps culture and secure SDLC practices * Relevant certifications such as OSCP, OSCE, GWAPT, or CCSP ## Description As the Cloud Security Test Manager, you will lead the offensive security function protecting Enphase's cloud platform, including Enlighten, Enphase App, and device APIs that connect over 4M homes globally. In this role, you will build and lead the security testing program across SAST, DAST, penetration testing, threat modeling, and red-team operations. You will manage a team of testers while staying hands-on to guide exploitation strategies and validate findings, partnering closely with the CISO's office to manage the vulnerability lifecycle end to end. What you will be doing: * Build and lead the application and cloud security testing roadmap and team * Integrate SAST, DAST, SCA, and secrets scanning into CI/CD pipelines (Jenkins, GitLab, GitHub Actions); tune rules, triage results, and manage false positives to drive shift-left adoption * Conduct and oversee manual penetration testing of web apps, REST/GraphQL APIs, microservices, and cloud platforms against OWASP Top 10 and API Top 10 * Plan and run red-team and purple-team exercises mapped to MITRE ATT&CK - initial access, exploitation, post-exploitation, lateral movement, and detection validation with the SOC * Lead threat modeling (STRIDE/PASTA) for new services and architecture reviews, defining attack surfaces, trust boundaries, and security requirements * Own end-to-end vulnerability lifecycle management - risk-based prioritization, remediation tracking, SLAs, and metrics - from identification through verified closure * Collaborate closely with the CISO's office to report risks, KPIs, and remediation SLAs * Define and enforce security standards and best practices across cloud environments * Perform container, Kubernetes, and cloud-native security testing across multi-cloud (AWS/GCP/Azure) environments * Develop custom exploits, payloads, and automation to validate exploitability and reduce false positives ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)