Principal Penetration Tester/ Offensive Security Team Lead
BreachLock is seeking a Principal Penetration Tester to lead their offensive security practice in a player-coach capacity. The role involves hands-on execution of complex penetration tests alongside team leadership, methodology development, and client advisory duties. Candidates require 10+ years of deep technical experience in offensive security and proficiency with standard industry tooling. This position offers the opportunity to drive service innovation and mentor a team in a fast-growing environment.
50k new jobs listed every day. Install TAL to find more jobs like this.

Experience
10+ years
Function
Engineering
Work mode
Onsite, India
Company
Tier 2
What you will work on
BreachLock is seeking a Principal Penetration Tester to lead their offensive security practice in a player-coach capacity. The role involves hands-on execution of complex penetration tests alongside team leadership, methodology development, and client advisory duties. Candidates require 10+ years of deep technical experience in offensive security and proficiency with standard industry tooling. This position offers the opportunity to drive service innovation and mentor a team in a fast-growing environment.
TAL's take
Strong role for a specialized cybersecurity company with clear expectations for a player-coach technical lead in offensive security.
Very well-defined responsibilities, clear technical requirements, and explicit expectations for the player-coach model.
Must haves
- 10+ years in cybersecurity with focus on hands-on penetration testing
- Proven track record of personally executing penetration tests
- Experience leading or building penetration testing teams
- Deep expertise in web application, network, and cloud security testing
- Proficiency with offensive security tools like Burp Suite and Cobalt Strike
- Experience engaging directly with enterprise clients and executive stakeholders
Tools and skills
Nice to have: oscp, oswe, osep, osed, crto, crte, lpt master, cissp.
About the company
Established cybersecurity company, recognized player in the market but not a top-tier global or India-native flagship brand.