Cybersecurity & Pentesting Lead
Sign up free to see how well your resume matches this role.
About this role
We are looking for a Cybersecurity & Pentesting Lead to lead the continuous strengthening of the cybersecurity posture of Periferia IT Group and its clients, through risk management, implementation of controls, technical analysis, authorized pentesting, and adoption of frameworks such as NIST, CIS, ISO 27001/27002, MITRE ATT&CK, and MITRE ATLAS.
This role involves designing and executing the corporate and client cybersecurity strategy, coordinating purple team exercises, managing vulnerabilities, and supporting audits and certifications.
✅ Requirements & Experience
Academic Background
Professional degree in Systems Engineering, Telecommunications, Cybersecurity, or related fields.
Required Experience
5+ years of experience in offensive security, risk management, or security architecture.
Experience leading assessments for clients and presenting results to senior management.
Desirable: Experience in regulated sectors and hybrid or multi-cloud environments.
Specific Knowledge
Practical knowledge of networks, operating systems, cloud, APIs, DevSecOps, IAM, cryptography, and application security.
Experience with PTES, OWASP Testing Guide, OWASP ASVS, and CVSS methodologies.
Proficiency in frameworks: NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001/27002, MITRE ATT&CK, MITRE ATLAS.
Technologies
Main: Offensive Security / Pentesting.
Associated: NIST / ISO 27001 / MITRE ATT&CK / MITRE ATLAS / OWASP.
🔧 Main Responsibilities
Cybersecurity Strategy: Design and execute the corporate and client cybersecurity strategy. Assess risks, control gaps, technology exposure, and security maturity.
Pentesting & Technical Assessments: Plan and perform pentesting for web, API, mobile, infrastructure, cloud, wireless networks, and internal environments. Define rules of engagement, scope, authorizations, risk criteria, and evidence handling.
Reporting & Communication: Prepare executive and technical reports with reproducible findings, impact, evidence, and prioritized recommendations. Present results to senior management and clients.
Purple Team & Threat Hunting: Coordinate purple team, threat hunting, and control validation exercises using MITRE ATT&CK. Assess artificial intelligence and machine learning risks using MITRE ATLAS.
Vulnerability & Control Management: Implement and measure controls based on CIS Controls, NIST CSF, NIST SP 800-53, ISO 27001/27002, and OWASP practices. Manage vulnerabilities, treatment plans, exceptions, and remediation tracking.
Monitoring & Response: Define monitoring, incident response, continuity, and recovery capabilities.
Audits & Certifications: Support audits, certifications, commercial processes, and client meetings.
Documentation & Methodologies: Keep methodologies, templates, playbooks, evidence, and knowledge base up to date.
Security Culture: Promote security culture through technical and executive training.
🧠 Skills & Competencies
Leadership of cybersecurity teams.
Analytical thinking and attention to detail.
Effective communication with technical and executive stakeholders.
Risk management and decision-making under pressure.
Proactivity and sense of urgency.
Ability to mediate disagreements and manage expectations.
Results-oriented and continuous improvement mindset.
Knowledge of international standards and regulations.
🏢 About the Opportunity
You will be part of Periferia IT Group, an organization focused on digital transformation and cybersecurity, where you will have the opportunity to lead high-impact initiatives, interact with clients in regulated sectors, and strengthen the security posture of the organization and its clients.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.