Thoropass · 1 month ago
Penetration Testing Manager
Thoropass is a company revolutionizing the compliance and audit industry by integrating AI technology with expert human insight. They are seeking a Penetration Testing Manager to lead and mentor a team of pentesters while performing hands-on penetration tests and ensuring high-quality results are delivered on time and within scope.
ComplianceInformation TechnologySaaSSoftware
Responsibilities
Lead and manage a Pentest team of 4–5 pentesters, providing technical guidance, feedback, and professional development support
Ensure all assigned engagements are delivered on time, within scope, and aligned with Thoropass standards
Conduct 1:1s, coaching sessions, and technical reviews to maintain motivation, quality, and team engagement
Collaborate with other Pentest Managers to balance workloads, share best practices, and standardize delivery processes
Partner with leadership to continuously improve internal operations, delivery frameworks, and team morale
Conduct web, network, and API penetration tests with automated and manual testing, using black box, gray box or white box testing methods
Identify and exploit vulnerabilities to simulate realistic attack paths and demonstrate business impact
Produce detailed, customer-facing reports with actionable remediation guidance, written in clear and professional English
Stay current with modern attack techniques and tools, ensuring your work and your team’s work remain technically strong
Help scale the pentest program through improved workflows, templates, and automation
Lead internal knowledge-sharing sessions and encourage a culture of continuous learning
Collaborate cross-functionally with Customer Success, Sales, and Operations to ensure seamless customer delivery
Support hiring, onboarding, and training as the pentest function expands
Qualification
Required
5–8+ years in pentesting or red teaming, including 1+ year of people management experience
Prior experience mentoring or managing security professionals
Strong technical expertise in web application, API, mobile, and network penetration testing
At least 1 of the following certifications: OSCP, OSCE, OSWE, PWPT, Burp Suite Certified Practitioner
Knowledge of current attack methods, manual penetration testing techniques, and popular hacking tools (e.g., Nessus, Nmap, Metasploit, Kali Linux, IDA PRO, Burp Suite Pro, OWASP ZAP)
Proficient scripting skills in bash, Python, or similar languages
Fluency in English, with exceptional verbal & written communication. You're able to convey complex, technical topics to an array of stakeholders in a digestible and compelling manner
Strong sense of operational ownership: able to balance delivery speed, quality, and customer satisfaction
Preferred
Contributions to the security community, such as conference talks, blog posts, open-source projects, or CVE discoveries
Knowledge of compliance frameworks that often require pentesting (e.g., SOC 2, ISO 27001, PCI DSS, HIPAA)
Experience working with cross-functional teams (Sales, Customer Success, Engineering) to scope, plan, or deliver pentests
Participation in bug bounty programs or vulnerability research initiatives
Experience with AI/LLM security testing and cloud environments such as AWS is a plus
Experience with Hack the Box, Portswigger Academy, or similar learning platforms
Benefits
Exceptional private healthcare
Early equity in a fast-growing company
Work-from-home model
Flexible PTO
Home office equipment
Monthly wellness and home Wi-Fi stipend
Company
Thoropass
Thoropass offers services for a variety of frameworks, including SOC 2, PCI, ISO, HITRUST, and HIPAA.
H1B Sponsorship
Thoropass has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (1)
Funding
Current Stage
Growth StageTotal Funding
$97.95MKey Investors
Fin CapitalJ.P. Morgan Growth Equity PartnersCanapi Ventures
2022-11-08Series C· $50M
2021-11-02Series B· $35M
2020-09-23Series A· $10M
Recent News
Centana Growth Partners
2025-02-04
2024-12-04
Company data provided by crunchbase