1

Penetration Testing Manager Jobs in Connecticut (NOW HIRING)

... penetration testing support, and evaluate risks across IT infrastructure before systems go live ... Experience with risk management frameworks and compliance. * Bachelor's or Master's degree in ...

... network penetration testing activities. * Monitor systems and networks for potential security ... Vulnerability management platforms * Network monitoring and management platforms Knowledge and ...

... penetration testing support, and evaluate risks across IT infrastructure before systems go live ... Experience with risk management frameworks and compliance. * Bachelor's or Master's degree in ...

... penetration testing support, and evaluate risks across IT infrastructure before systems go live ... Experience with risk management frameworks and compliance. * Bachelor's or Master's degree in ...

Chief Information Security Officer

Westport, CT · On-site

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Oversee vulnerability management, penetration testing, and remediation programs aligned to business risk. * AI Governance, Risk & Security * Establish and lead AI governance frameworks covering ...

Senior Cybersecurity Engineer

Norwalk, CT · On-site

$125K - $167K/yr

Strong background in performing advanced risk assessments, vulnerability management, penetration testing, and forensic investigations. * In-depth knowledge of network infrastructure (routers ...

Senior Cybersecurity Engineer

Norwalk, CT · On-site

$125.93 - $167.91/hr

Strong background in performing advanced risk assessments, vulnerability management, penetration testing, and forensic investigations. * In-depth knowledge of network infrastructure (routers ...

Senior Cybersecurity Engineer

Norwalk, CT · On-site

$115K - $157K/yr

Strong background in performing advanced risk assessments, vulnerability management, penetration testing, and forensic investigations. * In-depth knowledge of network infrastructure (routers ...

Senior Cybersecurity Engineer

Norwalk, CT · On-site

$114K - $157K/yr

Strong background in performing advanced risk assessments, vulnerability management, penetration testing, and forensic investigations. * In-depth knowledge of network infrastructure (routers ...

Lead AppSec Engineer

Stamford, CT · On-site +1

$62.75 - $83.75/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Own day-to-day life cycle management, including identification, threat assessment ... Experience with penetration testing and web application assessment. Who you are: * Proven ...

Showing results 21-40

Penetration Testing Manager information

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Connecticut?

The most popular types of Penetration Testing jobs in Connecticut are:

What are popular job titles related to Penetration Testing Manager jobs in Connecticut?

For Penetration Testing Manager jobs in Connecticut, the most frequently searched job titles are:

What job categories do people searching Penetration Testing Manager jobs in Connecticut look for?

The top searched job categories for Penetration Testing Manager jobs in Connecticut are:

What cities in Connecticut are hiring for Penetration Testing Manager jobs?

Cities in Connecticut with the most Penetration Testing Manager job openings:

VP, Staff Cryptography Engineer

Synchrony Financial

Stamford, CT • On-site

Full-time

Re-posted 5 days ago


Synchrony Financial rating

9.0

Company rating: 9.0 out of 10

Based on 52 frontline employees who took The Breakroom Quiz

2nd of 150 rated financial services


Job description

Role Summary/Purpose:

TheVP,StaffCryptographyEngineerwillserveas akey role in safeguardingenterprisemulti-cloudsystems, networks, and data.The positionisresponsiblefordesigning,developing,driving,implementing,leadingand managingmulti-cloudInformation SecurityEngineering activities for the Cryptographyprogram,includingtheunderlyingcapabilities/technologies.In addition, this role willbe responsible foracting as atrustedpeer and stakeholderadvisor within the organization, working closely withInformation Security Engineeringleadership to ensure delivery of the overall program roadmapagainst the Cryptography strategy and vision.

TheVP,StaffCryptography Engineeris part of the Synchrony Information Security Cryptography Team, serving as aPublic Key Infrastructure (PKI) lead while supporting other efforts, such asCloud Security, Cryptography, Information Security, Key/Secrets Management, Privacy, and Tokenization.The candidate would have an engineering position focused on delivering critical/key enterprise data protection controls, efficient supporting processes, & comprehensive automation capabilities to protect & enable Synchrony's Information Security Engineering strategy at scale. The candidate is expected to have a strong understanding and technical work experience with Cloud Security, Cryptography,DevSecOps, Information Security, Key/Secrets Management, PKI (competency skills/work experience domains include automation, controls, governance, lifecycle management, operations, process engineering, and security standards development).

Essential Responsibilities:

  • Adopting and promoting engineering excellence byidentifyingefficiencies and synergies through means of automation, collaboration, and orchestration

  • Collaborates with architecture toidentifycapability gaps, develop requirements,identifysolutions to address,assistwith proof of concepts and testing of solutions

  • Implementation and technical lead responsibilities that include ongoingDevSecOps/Engineeringsupport for a global cryptography programthatleveragesa portfolio ofmulti-clouddata protection capabilities

  • Managing technology fromtheground up and understanding gaps within the tech stack, including overlap with other technology and/or coverage, capability gaps

  • Maintaining technology from a business as usual (BAU) aspect by ensuring the proper change management,disasterrecover,incident managementprocessesare occurring and current

  • Participate as one of several technical leads on team ofInformationSecurity engineers

  • Participate in authoring, editing, providing, or reviewing documentation (procedures, standards) to ensure a well-managed and mature security infrastructure

  • Partners with peerswithintheorganizationtoeffectively prioritize work by usingAgile processesand ensuring risks, impediments, and asks are brought to leadership ina timelyfashion

  • Plays a hands-on role in the engineering and implementation ofmulti-cloudsecurity measures that protectenterprise applications,computer systems,information, infrastructure, andnetworks

  • Plays a key role in designing and buildingmulti-cloudsolutionsthatsafeguard theorganizationsplatformsand systems

  • Proactivelyidentifiesproblems and clearlyarticulatessolutionsand recommendations

  • Provide day-to-day administration and support formulti-cloudinfrastructure related to API, application security, firewalls, encryption, intrusion detection systems, PKI, secrets management, vulnerability scanning, security monitoring tools, penetration testing, authentication, web filtering, identity management, or access control systems, and their associated logs and processes

  • Providingengineering/operationssupport formulti-cloudtechnology and processes, ensuring superior customer service is being met, andidentifyingprocess improvements

  • Serving as aleader,mentor, andsubject-matter expert (SME) to other InformationSecurityteam members and/or stakeholders throughout the organization

  • Serving as aSAFeProduct Owner for cryptographic technologies, accountable fordefining/leading/maintainingthe team backlog and product roadmap

  • Supporting a "you build it you own it" model- meaning the technology built byEngineering is also supported from a wing-to-wing operations aspect

  • Works closely with Information Security program manager, scrum master, and architects to convey technical impacts todevelopment/engineeringtimeline and risks

  • Work independently inidentifyingopportunities to improve engineering or other performance for Information Security/Technology & other functions across Synchrony

  • Work withEnterprise andInformation Security/Technologyapplication owners, architects, developers,engineers, and governance teamsto drive program delivery

  • Perform other duties and/or special projects as assigned

Qualifications/Requirements:

  • Bachelordegree with a minimum of 5years experiencein Application Development, Information Security, Systems Engineering or related field; in lieu of a degree, a High School Diploma/GEDand minimum 7 years equivalent work experience

  • Minimum3+ years of experience in Cloud

  • Minimum3+yearsof experience in Cryptography

  • Minimum3+yearsof experience inDevSecOps

  • Minimum3+ years of experience in leadership roles (as Cryptography Engineer is preferred)

  • Minimum4+ years of experience with regulatory compliance and information security management frameworks (e.g., COBIT, ISO27001, NIST, etc.)

  • Proficient hands-on technical/workingexpertise with APIdevelopment, API security, AWS(Certificate Manager, KMS, Private CA,Secrets Manager),Azure(Key Vault),big data,CI/CD pipelines,Cloudbees/Jenkins,Cloudera, containers,cryptography methodologies,data encryption,databases,GCP (Cloud KMS, Secret Manager)Git/Github, Go,HashiCorpVault,Java,key/secrets management,Linux, Perl, PKI, Python,storage security,Terraform,tokenization

  • Excellent oral communication and writing skills. Adept and presenting complex topics,influencingand executing withtimely/ actionable follow-through

Desired Characteristics:

  • Ability to work under pressure and sustain productivity with multiple simultaneous projectsacross cross-functional engineering and operational information security teams

  • Certifications in audit, big data, cloud, cybersecurity, governance, information security, PCI, privacy, risk; AWS, Azure, CSA, GCP, GIAC, IAPP, ISC2, ISACA, PCI

  • Cloud Security experience, especially around designing, building, managing solutionswith the following vendors:

  • AWS(Primary)

  • Azure

  • GCP

  • Creativity and individual thinking, the ability to work both independently & with teams

  • Cyber Security experience, especially around designing, building, managing solutions

  • Demonstrate technicalexpertisein existing Information Technology/Security systems with the ability to keep pace with evolving security and technologies

  • Demonstrate an understanding of business needs and commitment to deliveringconsistent,efficient, high quality, reliable and responsive service to the business

  • Demonstrate an understanding of the impact of emerging business and end-user technologies have on Information Security architecture/engineering requirements

  • Demonstrated experience communicating complex and technical issues to diverse audiences (verbally and in writing), in an actionable and easy to understand manner

  • Demonstrated team focused mentality with proven experience to work effectively with diverse stakeholders

  • Experience with Agile, Scaled Agile (SAFe), Scrum

  • Familiarity with problem and incident management, change management, notifications, and basic operational understanding of running andmaintaininginfrastructure

  • Proven strongdecision-makingcapabilities, with a proventrack recordof weighing relativebenefits/costs of potential actions andidentifyingthe mostappropriate one

  • Strong and efficient problem-solving and analytical skills, willingness to learn

  • Strong interpersonal skills with an emphasis ondemonstratingpreviousexperience at effectively influencing others, cross functionally at all levels within the organization

  • Understanding of information security practices and policies, including risks and threats

  • Understanding of various public clouddeployment/platform/servicemodels from a development,engineering,infrastructure, and information security aspect

Grade/Level: 12

The salary range for this position is 135,000.00 - 230,000.00 USD Annual and is eligible for an annual bonus based on individual and company performance.

Actual compensation offered within the posted salary range will be based upon work experience, skill level or knowledge.

Salaries are adjusted according to market in CA, NY Metro and Seattle.

Our Way of Working:

We're proud to offer you flexibility. At Synchrony, our way of working allows you to have the option to work from home near one of our Hubs or come into one of our offices.You will be required to commute to your nearestHub (either virtual or physical) for in-person engagement activities such as regularbusiness or team meetings, training and culture events.

*Field Sales and some Commercial team roles may have varied location requirements based upon partner obligations or preferences.

Eligibility Requirements:

  • You must be 18 years or older

  • You must have a high school diploma or equivalent

  • You must be willing to take a drug test, submit to a background investigation and submit fingerprints as part of the onboarding process

  • You must be able to satisfy the requirements of Section 19 of the Federal Deposit Insurance Act.

  • New hires (Level 4-7) must have 9 months of continuous service with the company before they are eligible to post on other roles. Once this new hire time in position requirement is met, the associate will have a minimum 6 months' time in position before they can post for future non-exempt roles. Employees, level 8 or greater, must have at least 18 months' time in position before they can post. All internal employees must consistently meet performance expectations and have approval from your manager to post (or the approval of your manager and HR if you don't meet the time in position or performance expectations).

Legal authorization to work in the U.S. is required. We will not sponsor individuals for employment visas, now or in the future, for this job opening.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Our Commitment:

When you join us, you'll be part of an inclusive culture where your individual skills, experience, and voice are not only heard - but valued. Together, we're building a future where we can all belong, connect, and turn ideals into action. More than 50% of our workforce is engaged in our Employee Resource Groups (ERGs), where community and passion intersect to offer a safe space to learn and grow.

This starts when you choose to apply for a role at Synchrony. We ensure all qualified applicants will receive consideration for employment without regard to age, race, color, religion, gender, sexual orientation, gender identity, national origin, disability, or veteran status. We're proud to have an award-winning culture for all.

Reasonable Accommodation Notice:

  • Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.

  • If you need special accommodations, please call our Career Support Line so that we can discuss your specific situation. We can be reached at 1-866-301-5627. Representatives are available from 8am - 5pm Monday to Friday, Central Standard Time

Job Family Group:

Information Technology

What Synchrony Financial employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom