Senior Manager, Penetration Testing
SophosJob Description
About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies â including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at .
Role Summary
ãœãã©ã¹ã¯ãæ¥æ¬ãæ ç¹ãšãããSophos Red Teamãã®ãªãŒããŒãåéããŠããŸãããã®ããžã·ã§ã³ã§ã¯ã確ç«ãããå®çžŸãæã€ãé«ãããã©ãŒãã³ã¹ãçºæ®ããæ»æçã»ãã¥ãªãã£ã®å°éå®¶ããŒã ãçããŠããã ãããšã«ãªããŸããåœç€Ÿã®æåã¯ãè¬èã§ãããªããæ ç±ã«æºã¡ãé«åºŠãªæè¡åãæã¡ããµã€ããŒã»ãã¥ãªãã£ãžã®æ ç±ãå ±æãããããã§ãã·ã§ãã«ãã¡ãèåããããŠããŒã¯ãªãã®ã§ãããã®ãªãŒããŒã·ããããžã·ã§ã³ã§ã¯ãAPJå/æ¥æ¬æ åœãã£ã¬ã¯ã¿ãŒãšç·å¯ã«é£æºããã°ããŒãã«ãªãã©ã¯ãã£ã¹ãªãŒããŒãä»ã®éšé暪æçãªããŒãããŒãšååããŠãåè¶ãããµãŒãã¹æäŸãå®çŸããŠããã ããŸããçæ³çãªåè£è ã¯ãæ»æçã»ãã¥ãªãã£ããŒã ãçããçµéšãæããŠããããšãæ±ããããŸããããžãã¹ãªãŒããŒãšããŠããã®åœ¹è·ã¯ç¹å®ã®ãã©ã¯ãã£ã¹ææšïŒåçãå©ççãNPSïŒé¡§å®¢æºè¶³åºŠãªã©ïŒã®éæã«è²¬ä»»ãè² ããå¶æ¥ãããŒã±ãã£ã³ã°ããã®ä»ã®çµç¹ãšç·å¯ã«é£æºããŠãã©ã¯ãã£ã¹ã®æé·ãæ¯æŽããŸããããã¯æŠç¥çãªãªãŒããŒã·ããããžã·ã§ã³ã§ãããããŒã ããŒãã£ã³ã°ãå šç€ŸããŒãã£ã³ã°ãæŠç¥äŒè°ããã®ä»ã®ã¯ãŒã¯ã·ã§ãããéããŠãçŸå°ã§ã®åŒ·åãªãªãŒããŒã·ãããçºæ®ããããŒã ã®ææãé¡§å®¢ãæºè¶³ãããæå 端ã§ããããšãä¿èšŒããå¿ èŠããããŸãã
Sophos is looking for a Japan based leader on the Sophos Red Team in Japan to lead a well-established, high performing team of offensive security professionals. Our culture is a unique mix of low ego â high energy, highly technical, and motivated professionals with a passion for cybersecurity. This leadership position will partner closely with the Director of APJ North/Japan and will work collaboratively with global practice leadership and other cross-functional partners to achieve service delivery excellence. The ideal candidate will have experience leading offensive security teams. As a business leader this role will be responsible for achieving select practice metrics (Revenue, Margin, NPS/customer satisfaction, etc.) and partner closely with sales, marketing and other organizations to help grow the practice. This is a strategic leadership position which requires strong local leadership presence through team meetings, all hands, strategy sessions, and other workshops to ensure the teamâs delivery is customer delighting and at the bleeding edge.
What You Will Do
- è€æ°å¹Žã«ããããµãŒãã¹æäŸèšç»ã®çå®ãšäž»å°ãããã³è²¡åæŠç¥ã®ãµããŒããéããŠãäŒç€Ÿã®ç®æšéæã𿻿åã»ãã¥ãªãã£åéã«ãããæ¥çãªãŒããŒãšããŠã®å°äœåŒ·åã«è²¢ç®ããã
- 倿§ãªæ»æåã»ãã¥ãªãã£æ¥åïŒäŸµå ¥ãã¹ããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ããæ¬æ Œçãªã¬ããããŒã 掻åãªã©ïŒãæäŸããããã€ããã©ãŒãã³ã¹ãªæè¡ã³ã³ãµã«ã¿ã³ãããŒã ãçããã
- äºæž¬ãããã¯ãã°ç®¡çã皌åçãã¹ã±ãžã¥ãŒç®¡çãå«ãæç管çãæ¯æŽããã
- å¶æ¥çµç¹ããã®ä»ã®äºæ¥éçºãªãŒããŒãšé£æºããè€éãªæ»æåãã¹ãã®ããŒãºã«ãããŠãé ŒããååšããšããŠèªèãããã
- ã€ã³ã·ãã³ã察å¿ããŒã ãè åšå¯ŸçãŠããããããŒã±ãã£ã³ã°ãå¶æ¥ãªã©ããœãã©ã¹ç€Ÿå ã®éšé暪æçãªé¢ä¿ãæ§ç¯ã»åŒ·åããã
- ããŒã ã®å¹çåãå³ãããã人æãããã»ã¹ããã¯ãããžãŒãšãã£ãæ©äŒãç¹å®ããã
- ãœãã©ã¹ã®ã¬ããããŒã ãµãŒãã¹ããŒããã©ãªãªã代衚ããæ°ãããµãŒãã¹ãæ©èœãææ¡ãç¹å®ã»æšé²ããããŸããææ³çãªãŒããŒã·ãããçºæ®ããããŒããã©ãªãªå ã®ãµãŒãã¹ã«é¢é£ããåžå Žæå ¥æŠç¥ãçå®ããã
- ããžãã¹äžã®åªå äºé ãæäŸã®ãã¹ããã©ã¯ãã£ã¹ãæ°ããã¢ã€ãã¢ã®å®è£ ã«ã€ããŠãããŒã å ã§åæåœ¢æãä¿é²ãããå€åãåãå ¥ããã¢ã€ãã¢ãç©æ¥µçã«ææ¡ããä»è ã®æèŠã«è³ãåŸããä»è ããåŠã¶ææ¬²ãæã€ãçŸç¶ã«çåãæããããå§¿å¢ã
- ããŒã ã¡ã³ããŒã®ãã£ãªã¢éçºãä¿é²ãããã£ãªã¢éçºæ©äŒïŒã«ã³ãã¡ã¬ã³ã¹ãç ä¿®ãè³æ ŒååŸãã¡ã³ã¿ãªã³ã°å¶åºŠãªã©ïŒãç©æ¥µçã«æ¯æŽããã
- NPS(ãããããã¢ãŒã¿ãŒã¹ã³ã¢)ãšé¡§å®¢æºè¶³åºŠã責任ããã£ãŠç®¡çããæåŸ ãããç®æšãéæããããã¯äžåãããã«åªããã質ã®é«ã顧客ãµãŒãã¹ãæäŸããæåãç¶æããã
- Help develop and lead a multi-year service, delivery, as well as supporting with financial strategy, to meet company objectives and reinforce our position as an industry leader in offensive security.
- Lead a high performing team of technical consultants delivering a variety of offensive security engagements (penetration testing, application security testing, full scale Red Team, etc.)
- Help manage a P&L including forecasting, backlog management, utilization, and scheduling
- Partner with the sales organization and other business development leaders and be seen as a âgo toâ for complex adversarial testing needs
- Build and advance cross-functional relationships within Sophos that include the Incident Response Team, Counter Threat Unit, Marketing, Sales.
- Identify opportunities â people, process, and technology -- to improve efficiencies within the team
- Represent the Sophos Red Team services portfolio; identify and champion new services, capabilities, and offers; provide thought leadership; and develop an associated go-to-market strategy for the services in the portfolio
- Drive teams to consensus on business priorities, delivery best practices, and implementation of new ideas. Willingness to changes, to contribute ideas, listen to others, and learn from others. Challenge the status quo.
- Foster career development and champion career development opportunities for the team (conferences, training, certifications, mentoring, etc.)
- Own NPS/customer satisfaction and ensure practice meets/exceeds expected targets. Maintain a culture of premium customer service
What You Will Bring
- ãµã€ããŒã»ãã¥ãªãã£æ¥çã«ãããŠãæ»æåã»ãã¥ãªãã£ïŒãªãã§ã³ã·ãã»ãã¥ãªãã£ïŒãäž»å°ãã5ïœ7幎ã®å®åçµéšïŒå€åã®æ¿ãããã€ãããã¯ãªç°å¢ã§ã®çµéšãããã°å°å¯ïŒã
- äžå°äŒæ¥ã¬ãã«ã§ã®ããªã»ãŒã«ã¹ããã³ãã¹ãã»ãŒã«ã¹ã®ãµãŒãã¹æäŸçµéšã
- ãã€ããã©ãŒãã³ã¹ãªããŒã ã管çãã匷åºãªããŒã æåãç¶æã»åŒ·åã§ããèœåã
- åªããå£é ããã³æžé¢ã«ããã³ãã¥ãã±ãŒã·ã§ã³çµéšãèœåãïŒçµå¶å¹¹éšå±€ãžã®å ±åçµéšãããã°å°å¯ïŒã
- ã°ããŒãã«ããªã¢ãŒãã倿åããŒã ã§ã®æ¥åçµéšã
- åªå é äœãä»ããæ¥åãå§ä»»ããå³ããçŽæã®äžã§ã¿ã¹ã¯ãå®äºãããããšãã§ããèœåã
- åªãã察人ã¹ãã«ãæã¡ãèªçºçãç©æ¥µçãææ¬²çãªããŒã ãã¬ãŒã€ãŒã§ããããšã
- çµæéèŠãã€é¡§å®¢å¿åã§ããããšã
- 課é¡è§£æ±ºã«ãããŠãäž»äœæ§ãšç確ãªå€æåãçºæ®ã§ããããšã
- çµå¶é£ã®æ¯æŽãåããªãããã¹ããŒã¯ãã«ããŒãšã®å¯Ÿç«ç®¡çã亀æžã广çã«è¡ããããšã
- ãããªãã¯ã¹åã®ã³ã³ãµã«ãã£ã³ã°ç°å¢ã«ãããŠãæè¡ããŒã ã®æå°ã»çµ±ççµéšãããããšã
- æ¥åéè¡ã«å¿ èŠãªæ¥æ¬èªèœåããã³ããžãã¹ã¬ãã«ã®è±èªåãå¿ é ã
ãå¿åèŠä»¶â¯ââ¯WANTã
- æ å ±ã»ãã¥ãªãã£åéã§ã®7幎以äžã®å®åçµéšã
- ãµã€ããŒã»ãã¥ãªãã£ã«é¢é£ããå°éåŠäœããŸãã¯åçã®å®åçµéšã
- OSCPãOSWPãOSEPãOSWAãOSWEãCEHãGPENãGCPNãGWAPTãCISSPãªã©ã®æè¡ç³»ãŸãã¯å°éè³æ Œãããã°å°å¯ã
- å¶æ¥éšéãšé£æºããæ¡ä»¶ã®ç¯å²èšå®ãææ¡æžã®äœæãªã©ãè¡ã£ãçµéšïŒå¥çŽç· çµã顧客察å¿ã¯éåžžãå¶æ¥ãæ åœããŸãïŒ
- ãµã€ããŒã»ãã¥ãªãã£æ¥çã®ãã©ãŒã©ã ãã€ãã³ããžã®åå çµéšãããã³è¬æŒãå·ç掻åïŒãã¯ã€ãããŒããŒãããã°ãªã©ïŒã®çµéšã
- Required:
- 7+ years in the cybersecurity industry leading offensive security, preferably in dynamic and fast changing environments.
- Presales and post sales delivery experience at the SME Level
- Demonstrated ability to manage high-performing teams as well as maintain and enhance a strong team culture.
- Excellent verbal and written communication skills with experience â ideally briefing executive management level also.
- Experience working with global, remote, multi-cultural teams.
- Ability to prioritize, delegate and complete tasks within tight timeframes to meets deadlines.
- Strong interpersonal skills, self-starting, proactive, motivated, team player.
- Results orientated and customer focused.
- Ability to demonstrate initiative and good judgment in resolving issues.
- Effective at managing conflict and negotiating with stakeholders, with support from senior leaderships.
- Experience mentoring and leading technical teams in a matrixed consulting environment. (align with sales, IR, threat intelligence and global teams)
- Fluent Japanese proficiency as well as business level English in running business required.
- Preferences:
- 7+ years of information security experience.
- Professional degree relevant to cybersecurity or equivalent work experience.
- Technical or professional certifications, such as OSCP, OSWP, OSEP, OSWA, OSWE, CEH, GPEN, GCPN, GWAPT, CISSP are a plus.
- Experience working with sales in scoping engagements, creating proposals, etc.
- Participation in cybersecurity industry forums and events, including speaking events and written publications (white papers, blogs, etc.).
#B2
Ready to Join Us?
At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back â we encourage you to apply.
What's Great About Sophos?
· Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship.
· Our people â we innovate and create, all of which are accompanied by a great sense of fun and team spirit
· Employee-led diversity and inclusion networks that build community and provide education and advocacy
· Annual charity and fundraising initiatives and volunteer days for employees to support local communities
· Global employee sustainability initiatives to reduce our environmental footprint
· Global fitness and trivia competitions to keep our bodies and minds sharp
· Global wellbeing days for employees to relax and recharge
· Monthly wellbeing webinars and training to support employee health and wellbeing
Our Commitment To You
Weâre proud of the diverse and inclusive environment we have at Sophos, and weâre committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know.
Data Protection
If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophosâ data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered | Sophos
Originally posted on Himalayas