Associate Manager, Global Offensive Security Lead
Role details
Job location
Tech stack
Job description
Join our Global Information Security (GIS) Operations team to lead and advance our Offensive Security program. As an Associate Manager, Global Offensive Security Lead, you'll design and execute threat-informed breach attack simulations and security assessments designed to identify vulnerabilities before attackers can exploit them, then transform findings into prioritized actions that strengthen our security posture and reduce enterprise risk. This position offers a rare opportunity to blend hands-on offensive security expertise with strategic program leadership while making a measurable impact across a global organization., * Own and evolve SC Johnson's global Offensive Security program, helping the organization proactively identify and reduce risk
- Influence enterprise security strategy by highlighting key reporting metrics, trends, and opportunities for improvement
- Design and run non-destructive attack simulations that emulate real-world adversary behavior on a cadenced basis, creating clear documentation of the attack(s) and result(s)
- Partner with Security Architects, Engineers, and other GIS teams to build thoughtful testing plans and support testing and remediation efforts
- Manage and optimize Offensive Security tools and platforms (e.g., breach attach simulation (BAS)), to continuously validate company security controls
- Create repeatable processes to assess, analysis, group, and prioritize all findings, allowing teams to approach findings in a risk-based manner
- Establish process to assess new technology platforms and provide findings to stakeholders
- Maintain confidentiality as related to security posture, testing activities, and discovered vulnerabilities
Requirements
- Bachelor's degree in Computer Science, Management Information Systems, Engineering, or military experience considered in lieu of education requirement.
- 5+ years of experience in Cyber Security
- 2+ years of experience in at least two of the following areas: Vulnerability Management, Cyber Threat Intelligence, Breach Attack Simulation, Threat Hunting, Offensive Security, SOC, DevSecOps
- Qualified candidates must be legally authorized to work in the United States without the need for current or future sponsorship for full-time employment.
PREFERRED EXPERIENCES AND SKILLS
- Experience working with virtual team members.
- Thought leader in Information Security with ability to align initiatives with company business objectives.
- Cross-functional experience with technical and non-technical multidisciplinary teams.
- Considerable writing proficiency, oral presentation, problem solving and decision-making skills.
- Excellent verbal and written communication skills, including executive-level presentation.
- Ability to facilitate productive meeting and work successfully in a team-oriented environment.
- Relevant industry certifications such as GIAC, CISSP, etc..