Job SummaryThe Senior Consulting Director, Offensive Security will lead a team of technical security consultants focused on assessing and challenging the security posture of Unit 42's clients across a wide array of industries, geographies, and organizational structures. They will be the client's advocate for cybersecurity risk management and will provide strategic and technical leadership in this area.
Key Responsibilities- Drive business growth and profitability, maintaining direct oversight of practice P&L, margin targets, revenue forecasting, and resource utilization efficiency.
- Provide a direct positive influence on the security posture of the world's most prestigious organizations by leading Unit 42's elite group of cybersecurity professionals in a variety of assessments for our top-tier clientele.
- Orchestrate and manage a dynamic schedule for a large team of elite offensive security specialists, ensuring optimal alignment of skill sets to meet client needs and maximize usage of available billable hours.
- Serve as a mentor to a team of offensive security personnel, maximizing professional development by providing ad hoc technical guidance and aligning employees with appropriate industry-standard training courses.
- Craft policies governing offensive security practices which reflect cutting-edge capabilities of advanced persistent threat actors and enforce security best practices that ensure the safety of our client's environments.
- Fulfill a customer-facing case leadership role for multiple concurrent events, guiding a technically diverse team of personnel through the complex challenges posed by some of the world's largest networks.
- Ensure high quality engagement outcomes and deliverables by providing quality assurance and technical oversight during engagements.
- Provide hands-on support for highly complex offensive security operations, utilizing cutting-edge techniques in technically challenging environments.
- Provide front-line support to the sales team by meeting with clients to clearly articulate various penetration approaches and methodologies to both technical and executive audiences. Transform customer requirements into executable statements of work, including a work breakdown structure with accurate estimates of billable hours for each discrete phase of testing.
- Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements.
- Assist in the development of security standards and best practices for the organization and recommend security enhancements as needed.
- Assist with the development and maturity of both new and existing Unit 42 offensive security offerings.
Qualifications Required Qualifications- Bachelor's degree with 14+ years of progressive cybersecurity experience; OR Master's degree with 12+ years; OR PhD with 10+ years in Computer Science, Cyber Security, Digital Forensics, or a related field.
- Extensive experience managing a team of consultants in the execution of a variety of penetration testing requirements.
- Exceptional communication and interpersonal skills, with the ability to serve as a front-facing representative of Palo Alto Networks, building and maintaining strong relationships with clients and stakeholders.
- Proven ability to draft thorough, articulate reports that convey technically complex material to an executive-level audience, ensuring clear understanding and informed decision-making.
- Experience scoping new opportunities with prospective clients, including drafting statements of work and proposals.
- Hands-on experience and deep understanding of tools and techniques for conducting network, wireless, and web application penetration testing.
- Ability to perform travel requirements as needed to meet business demands (on average 30%).
Preferred Qualifications- Demonstrated subject matter expertise in multiple core offensive security service offerings, including a deep understanding of architecture requirements for Red Team exercises, Endpoint Detection and Response evasion methodologies, and Advanced Persistent Threat emulation techniques.
- Experience with penetration testing, administering, and troubleshooting major flavors of Linux, Windows, and major cloud IaaS, PaaS, and SaaS providers (i.e., AWS, GCP, and Azure).
- Knowledge of best practices for application, database, and web server design and implementation.
- Knowledge of open security testing standards and projects, including OWASP & MITRE ATT&CK.
- Experience with scripting and editing existing code and programming using one or more of the following: Perl, Python, Ruby, Bash, C/C++, C#, or Java.
Compensation DisclosureThe compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.
$236,000.00 - $275,000.00/yr