DIRECTOR - Application Security
Practice Head - Application Security, Red Teaming, & Threat/Vulnerability Management (TVM)
Experience Required: 15+ Years
Position Overview
We are seeking a visionary, highly technical, and strategically minded Practice Head to lead, scale, and mature our Application Security (AppSec), Red Teaming, and Threat & Vulnerability Management (TVM) cybersecurity division.
In this senior leadership role, you will take full ownership of the practice, driving technology roadmaps, managing P&L, nurturing top-tier offensive security talent, and acting as a trusted advisor to executive stakeholders. You will balance a deep technical background in adversary simulation and secure software development with strong business acumen to protect our enterprise ecosystem and clients.
Key Responsibilities
1. Practice Leadership & Strategy
- Define the vision and strategy for the AppSec, Red Teaming, and TVM service offerings, aligning them with overall enterprise risk management goals.
- Oversee practice growth, resource allocation, budgeting, tool evaluation, and vendor partnerships.
- Establish modern delivery methodologies, frameworks, playbooks, and standardized reporting structures for offensive operations.
- Serve as a thought leader, representing the firm at cybersecurity conferences and driving internal security advocacy.
2. Technical Governance & Execution
- Application Security (AppSec): Drive Secure SDLC practices by embedding threat modeling, secure code reviews (SAST), dynamic testing (DAST), and Software Composition Analysis (SCA) into advanced CI/CD DevSecOps pipelines.
- Red Teaming & Adversary Simulation: Oversee sophisticated cyber-attack simulations across cloud environments (AWS/Azure/GCP), complex Active Directory setups, and network architectures using frameworks like MITRE ATT&CK.
- Threat & Vulnerability Management (TVM): Architect enterprise-wide vulnerability discovery, prioritization, validation, and remediation programs. Ensure seamless transition of threat intelligence into proactive testing parameters.
3. Team Management & Mentorship
- Lead, mentor, and upscale a high-performing team of ethical hackers, AppSec engineers, and security analysts.
- Build a continuous-learning culture focused on reverse engineering, exploit development, and emerging threat research.
4. Stakeholder & Cross-Functional Alignment
- Translate highly technical vulnerability and attack path findings into clear, business-relevant risk profiles for engineering leads and C-suite executives.
- Coordinate with DFIR, SOC, and Threat Intelligence teams during active incident response or post-assessment reviews.
Required Skills and Qualifications
Education & Experience
- Bachelor?s or Master?s degree in Computer Science, Cyber Security, Information Technology, or a related field.
- 15+ years of deep hands-on experience across offensive security, application testing, and enterprise vulnerability management.
- Minimum 5+ years of experience leading and scaling cybersecurity teams or practices in India.
Technical Proficiencies
- Core Methodologies: Expert knowledge of OWASP (Web/API/Mobile Top 10), SANS Top 25, MITRE ATT&CK framework, and NIST standards.
- Offensive Security Tooling: In-depth knowledge of platforms like Burp Suite, Metasploit, Cobalt Strike, Qualys, Nessus, and Checkmarx.
- Cloud & Infrastructure: Proven architecture security knowledge of AWS, Azure, or GCP alongside containerized security (Kubernetes/Docker).
- Automation: Scripting fluency in Python, PowerShell, Bash, or Go to customize attack payloads and automate security tests.
Preferred Professional Certifications
Candidate must possess one or more recognized advanced credentials:
- Offensive: OSCP (Mandatory/Highly Preferred), OSCE, OSWE, GXPN, CRTO.
- Management/Governance: CISSP, CISM, or equivalent.
Recommended Jobs
Posted just now
Posted just now
Posted just now
Posted just now
Posted just now

