Cybersecurity & Pentesting Lead
Posted 2 days ago

We are looking for a Cybersecurity & Pentesting Lead to lead the continuous strengthening of the cybersecurity posture of Periferia IT Group and its clients, through risk management, implementation of controls, technical analysis, authorized pentesting, and adoption of frameworks such as NIST, CIS, ISO 27001/27002, MITRE ATT&CK, and MITRE ATLAS.
This role involves designing and executing the corporate and client cybersecurity strategy, coordinating purple team exercises, managing vulnerabilities, and supporting audits and certifications.
✅ Requirements & Experience
Academic Background
Professional degree in Systems Engineering, Telecommunications, Cybersecurity, or related fields.
Required Experience
5+ years of experience in offensive security, risk management, or security architecture.
Experience leading assessments for clients and presenting results to senior management.
Desirable: Experience in regulated sectors and hybrid or multi-cloud environments.
Specific Knowledge
Practical knowledge of networks, operating systems, cloud, APIs, DevSecOps, IAM, cryptography, and application security.
Experience with PTES, OWASP Testing Guide, OWASP ASVS, and CVSS methodologies.
Proficiency in frameworks: NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001/27002, MITRE ATT&CK, MITRE ATLAS.
Technologies
Main: Offensive Security / Pentesting.
Associated: NIST / ISO 27001 / MITRE ATT&CK / MITRE ATLAS / OWASP.
🔧 Main Responsibilities
Cybersecurity Strategy: Design and execute the corporate and client cybersecurity strategy. Assess risks, control gaps, technology exposure, and security maturity.
Pentesting & Technical Assessments: Plan and perform pentesting for web, API, mobile, infrastructure, cloud, wireless networks, and internal environments. Define rules of engagement, scope, authorizations, risk criteria, and evidence handling.
Reporting & Communication: Prepare executive and technical reports with reproducible findings, impact, evidence, and prioritized recommendations. Present results to senior management and clients.
Purple Team & Threat Hunting: Coordinate purple team, threat hunting, and control validation exercises using MITRE ATT&CK. Assess artificial intelligence and machine learning risks using MITRE ATLAS.
Vulnerability & Control Management: Implement and measure controls based on CIS Controls, NIST CSF, NIST SP 800-53, ISO 27001/27002, and OWASP practices. Manage vulnerabilities, treatment plans, exceptions, and remediation tracking.
Monitoring & Response: Define monitoring, incident response, continuity, and recovery capabilities.
Audits & Certifications: Support audits, certifications, commercial processes, and client meetings.
Documentation & Methodologies: Keep methodologies, templates, playbooks, evidence, and knowledge base up to date.
Security Culture: Promote security culture through technical and executive training.
🧠 Skills & Competencies
Leadership of cybersecurity teams.
Analytical thinking and attention to detail.
Effective communication with technical and executive stakeholders.
Risk management and decision-making under pressure.
Proactivity and sense of urgency.
Ability to mediate disagreements and manage expectations.
Results-oriented and continuous improvement mindset.
Knowledge of international standards and regulations.
🏢 About the Opportunity
You will be part of Periferia IT Group, an organization focused on digital transformation and cybersecurity, where you will have the opportunity to lead high-impact initiatives, interact with clients in regulated sectors, and strengthen the security posture of the organization and its clients.
Somos una empresa de tecnología que ofrece soluciones para impulsar negocios y generar ventajas competitivas que añaden valor a empresas y proyectos. Trabajamos de manera coordinada en los proyectos para lograr resultados mediante la innovación y la mejora continua. Contamos con presencia y trayectoria en Colombia, Perú, Ecuador, Panamá, Honduras, México y Estados Unidos. Gracias a más de 19 años de trabajo constante, aplicando metodologías Ágiles y formando equipos emergentes, ofrecemos experiencia, respaldo y solidez. Nos centramos en cumplir y superar las expectativas de nuestros clientes. Nos distinguimos por nuestros resultados y nuestra capacidad para marcar la diferencia. Somos Periferia IT Group.
Key team members
Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.
