- Company Name
- EMW
- Job Title
- C004570 Dep. Service Delivery Manager - Pen Testing Services (NS) - THU 15 Jan
- Job Description
-
Job title: Deputy Service Delivery Manager – Penetration Testing Services
Role Summary: Act as the technical and managerial lead for penetration testing engagements across NATO and NCIA environments, ensuring accurate scoping, high‑quality delivery, and continuous improvement while serving as the primary liaison between testers, service management, and stakeholders.
Expectations:
- Deliver penetration testing services on schedule, within budget, and in alignment with NCSC PTAE and other relevant standards.
- Maintain service quality, consistency, and adherence to agreed KPIs and reporting metrics.
- Manage risks, dependencies, and resource allocation effectively.
- Translate complex technical findings into clear, risk‑focused narratives for decision‑makers.
- Contribute to methodology refinement and lessons‑learned documentation.
Key Responsibilities:
- Support the Service Delivery Manager in overall service delivery.
- Assess scope, attack surface, constraints, and complexity of target systems; produce LoE estimates aligned with NCSC PTAE methodology.
- Conduct technical scoping discussions with stakeholders; define objectives, in/out of scope, assumptions, constraints, Rules of Engagement, and deliverables.
- Plan, schedule, and coordinate resources for penetration testing engagements; ensure adherence to timelines and quality standards.
- Monitor engagement progress, manage risks and dependencies, and provide regular status updates.
- Translate technical findings into risk‑focused language during kick‑offs, debriefings, and technical discussions.
- Support service reporting, KPI dashboards, and stakeholder briefings.
- Contribute to updates of testing methodologies, tools, and lessons‑learned documents.
Required Skills:
- Minimum 3 years of project or service delivery management experience in cybersecurity.
- Deep technical expertise in penetration testing and offensive security across network, application, and cloud environments.
- Proven ability to estimate effort and scope for complex technical assessments and to apply NCSC PTAE standards.
- Strong understanding of the penetration testing service lifecycle, scoping, and deliverable definition.
- Knowledge of OWASP, PTES, NIST/ISO‑aligned practices, and other penetration testing standards.
- ITIL experience with a focus on Change Management.
- Excellent stakeholder management, requirements gathering, and expectation‑setting skills.
- Ability to communicate complex technical concepts as actionable risk insights to non‑technical audiences.
Required Education & Certifications:
- NATO Secret security clearance (mandatory).
- Bachelor’s degree in Computer Science, Cybersecurity, Information Assurance, or a related field (or equivalent professional experience).
- Professional certifications preferred: PTES, OSCP, CEH, CISSP, ITIL Foundation.