waypointjobs

Periferia IT

Cybersecurity & Pentesting Lead

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

We are looking for a Cybersecurity & Pentesting Lead to lead the continuous strengthening of the cybersecurity posture of Periferia IT Group and its clients, through risk management, implementation of controls, technical analysis, authorized pentesting, and adoption of frameworks such as NIST, CIS, ISO 27001/27002, MITRE ATT&CK, and MITRE ATLAS.

This role involves designing and executing the corporate and client cybersecurity strategy, coordinating purple team exercises, managing vulnerabilities, and supporting audits and certifications.

✅ Requirements & Experience

Academic Background

Professional degree in Systems Engineering, Telecommunications, Cybersecurity, or related fields.

Required Experience

5+ years of experience in offensive security, risk management, or security architecture.

Experience leading assessments for clients and presenting results to senior management.

Desirable: Experience in regulated sectors and hybrid or multi-cloud environments.

Specific Knowledge

Practical knowledge of networks, operating systems, cloud, APIs, DevSecOps, IAM, cryptography, and application security.

Experience with PTES, OWASP Testing Guide, OWASP ASVS, and CVSS methodologies.

Proficiency in frameworks: NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001/27002, MITRE ATT&CK, MITRE ATLAS.

Technologies

Main: Offensive Security / Pentesting.

Associated: NIST / ISO 27001 / MITRE ATT&CK / MITRE ATLAS / OWASP.

🔧 Main Responsibilities

Cybersecurity Strategy: Design and execute the corporate and client cybersecurity strategy. Assess risks, control gaps, technology exposure, and security maturity.

Pentesting & Technical Assessments: Plan and perform pentesting for web, API, mobile, infrastructure, cloud, wireless networks, and internal environments. Define rules of engagement, scope, authorizations, risk criteria, and evidence handling.

Reporting & Communication: Prepare executive and technical reports with reproducible findings, impact, evidence, and prioritized recommendations. Present results to senior management and clients.

Purple Team & Threat Hunting: Coordinate purple team, threat hunting, and control validation exercises using MITRE ATT&CK. Assess artificial intelligence and machine learning risks using MITRE ATLAS.

Vulnerability & Control Management: Implement and measure controls based on CIS Controls, NIST CSF, NIST SP 800-53, ISO 27001/27002, and OWASP practices. Manage vulnerabilities, treatment plans, exceptions, and remediation tracking.

Monitoring & Response: Define monitoring, incident response, continuity, and recovery capabilities.

Audits & Certifications: Support audits, certifications, commercial processes, and client meetings.

Documentation & Methodologies: Keep methodologies, templates, playbooks, evidence, and knowledge base up to date.

Security Culture: Promote security culture through technical and executive training.

🧠 Skills & Competencies

Leadership of cybersecurity teams.

Analytical thinking and attention to detail.

Effective communication with technical and executive stakeholders.

Risk management and decision-making under pressure.

Proactivity and sense of urgency.

Ability to mediate disagreements and manage expectations.

Results-oriented and continuous improvement mindset.

Knowledge of international standards and regulations.

🏢 About the Opportunity

You will be part of Periferia IT Group, an organization focused on digital transformation and cybersecurity, where you will have the opportunity to lead high-impact initiatives, interact with clients in regulated sectors, and strengthen the security posture of the organization and its clients.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job