The posting
The Info Security Ops Group Manager is a senior management level position responsible for providing strategic leadership, operational oversight, and people management for application security testing services. This role ensures the delivery of high-quality Application Vulnerability Assessment and Management (AVA/AVM) services while maintaining operational excellence, service continuity, and adherence to cybersecurity standards.
The position plays a critical role in defining and executing the organization's perimeter testing strategy, helping protect critical business applications from emerging cyber threats. As a people leader, the Manager develops and leads a team of cybersecurity professionals, drives continuous service improvement, and partners with senior stakeholders to enhance the firm's overall security posture.
Key Responsibilities
Strategic Leadership
- Define and execute the long-term strategy and roadmap for Application Vulnerability Management services.
- Lead the evolution of perimeter testing capabilities to address emerging threats and business requirements.
- Partner with senior cybersecurity leaders, technology organizations, and business stakeholders to align security testing initiatives with enterprise risk management objectives.
- Drive innovation, automation, and process improvements to enhance service effectiveness and efficiency.
Service Delivery & Operations
- Oversee day-to-day AVA/AVM pentest operations, ensuring consistent delivery of high-quality vulnerability assessment services.
- Maintain service continuity, operational resilience, and compliance with established service level expectations.
- Establish and monitor key performance indicators, quality metrics, and reporting to measure program effectiveness.
- Ensure timely identification, assessment, prioritization, and remediation tracking of application vulnerabilities.
Team Leadership & Development
- Lead, mentor, and develop a team of cybersecurity specialists responsible for application security testing and vulnerability management activities.
- Foster a culture of accountability, collaboration, innovation, and continuous learning.
- Support workforce planning, talent development, succession planning, and employee engagement initiatives.
- Provide technical guidance and strategic direction to ensure consistent execution across the team.
Risk Management & Governance
- Ensure AVA/AVM services operate in alignment with organizational cybersecurity policies, standards, and regulatory requirements.
- Identify and manage security, operational, and compliance risks associated with application security testing activities.
- Communicate risk insights and remediation priorities to senior management and key stakeholders.
- Support internal and external audit activities and demonstrate effective security governance practices.
Stakeholder Engagement
- Build strong relationships with technology, engineering, application development, and cybersecurity teams.
- Act as the primary management representative for AVA/AVM services.
- Present program performance, risk trends, and strategic initiatives to senior leadership.
Qualifications
- 10+ years of extensive experience in application security, vulnerability assessment, vulnerability management, penetration testing, or related cybersecurity domains.
- Demonstrated experience leading cybersecurity teams and managing large-scale security operations.
- Strong understanding of application security testing methodologies, vulnerability management practices, and secure software development principles.
- Experience managing stakeholder relationships across technology and business organizations.
- Excellent leadership, communication, and organizational skills.
- Experience building and executing enterprise-scale application security programs.
- Knowledge of cloud security, DevSecOps practices, and modern application architectures.
- Experience driving cybersecurity transformation and service modernization initiatives.
Education:
- Bachelor’s degree/University degree or equivalent experience
- Holding relevant professional cybersecurity certifications such as CISSP, CISM, GWAPT, GPEN, OSCP, or equivalent.



