This is a hands-on leadership position for someone who combines offensive-security depth, threat-led thinking, strong operational judgment, and the ability to influence product, engineering, infrastructure, and security stakeholders.
Your responsibilities will include:
Pillar strategy and leadership
Define the Proactive Security strategy, operating model, roadmap, priorities, budget, and success measures in alignment with business objectives and threat profile.
Build, lead, and develop high-performing Red Team, Penetration Testing, Threat Hunting, and Threat Intelligence teams.
Create a unified intelligence-led program in which threat intelligence informs testing and hunting, and findings continuously improve defensive controls.
Prioritize work based on crown jewels, material attack paths, emerging threats, major technology changes, incidents, and business risk.
Establish clear team charters, engagement models, escalation paths, quality standards, and career-development frameworks.
Provide the CISO and senior leadership with clear visibility into adversary exposure, validated weaknesses, emerging threats, and remediation progress.
Red Team and adversary emulation
Lead realistic, intelligence-led adversary simulations across cloud, identity, applications, infrastructure, endpoints, networks, and operational processes.
Design campaigns that evaluate prevention, detection, response, escalation, and recovery capabilities against relevant threat scenarios.
Develop and maintain adversary-emulation plans mapped to relevant threat actors, tactics, techniques, and procedures.
Ensure every engagement operates under documented authorization, rules of engagement, safety controls, deconfliction procedures, and evidence-handling requirements.
Deliver concise technical and executive reporting that explains demonstrated impact, attack paths, root causes, and prioritized improvements.
Extensive cybersecurity experience, including leadership responsibility in offensive security, penetration testing, threat hunting, threat intelligence, detection engineering, or incident response.
Proven experience building or scaling multidisciplinary security teams and programs, including budgets, vendors, and external testing providers.
Strong technical understanding of modern cloud environments, identity systems, applications, APIs, networks, endpoints, containers, and production infrastructure.
Demonstrated experience planning and delivering red-team operations, penetration tests, or adversary-emulation exercises.
Practical knowledge of threat-hunting methodology, telemetry, detection logic, and investigation workflows.
Experience producing and operationalizing strategic, operational, and tactical threat intelligence.
Strong understanding of adversary behavior and frameworks such as MITRE ATT&CK.
Excellent communication and executive-presentation skills, with the ability to translate complex technical findings into clear business risks, decisions, and remediation actions.
Sound judgment regarding authorization, operational safety, confidentiality, evidence handling, and responsible disclosure.

















