Roles & Responsibilities :
- Develop and implement the penetration testing strategy in alignment with Amgen's security framework.
- champion a proactive security culture, integrating offensive security principles into Amgen's broader risk management program.
- Lead, mentor, and develop a team of penetration testers, fostering a culture of innovation and continuous learning.
- Provide coaching and training to enhance the team's technical and strategic capabilities.
- Build and maintain a high-performance security team, ensuring strong succession planning and career development opportunities.
- Oversee complex penetration testing engagements, ensuring high-quality execution and impactful reporting.
- Establish standard methodologies and frameworks for offensive security testing, risk assessment, and mitigation strategies.
- Ensure penetration testing methodologies align with industry standards (e.g., PTES, OWASP, MITRE ATT&CK).
- Serve as a trusted advisor to security, engineering, and executive leadership teams on cybersecurity risks and offensive security findings.
- Advocate for secure development practices and influence secure-by-design principles across engineering teams.
- Communicate technical security risks in business terms to executive collaborators and senior leadership.
- Define and enforce security testing policies, methodologies, and compliance requirements.
- Drive initiatives to enhance security automation and continuous testing frameworks.
- Ensure penetration testing efforts contribute to regulatory compliance (e.g., ISO 27001, NIST).
What we expect of you
We are all different, yet we all use our unique contributions to serve patients.
Basic Qualifications :
Master's degree and 8 to 10 years of experience in Computer Science, Cybersecurity or Information Systems related field OR
Bachelor's degree and 10 to 14 years of experience in Computer Science, Cybersecurity or Information Systems related field OR
Diploma and 14 to 18 years of experience in Computer Science, Cybersecurity or Information Systems related field
Must-Have
Skills :
Proven experience in leading and managing high-performing security teams.Strong ability to influence senior collaborators and drive security adoption across an organization.Ability to translate technical security risks into business-aligned security strategies.Experience building and managing enterprise-wide penetration testing programs.Demonstrated ability to foster a culture of innovation, learning, and collaboration within security teams.Technical & Security Skills
Deep knowledge of penetration testing frameworks and methodologies (e.g., OWASP, NIST, MITRE ATT&CK, PTES).Strong understanding of web application, cloud, and infrastructure security vulnerabilities.Experience with security tools such as Burp Suite, OWASP ZAP, Metasploit, Kali Linux.Familiarity with secure coding principles, threat modeling, and adversary simulation.Professional Certifications (please mention if the certification is preferred or mandatory for the role) :
PreferredOSCP, OSWE, OSWA, eWPTX, GWAPT, GXPN
PreferredCISSP
Preferred Qualifications :
Soft
Skills :
Excellent analytical and troubleshooting skillsStrong verbal and written communication skillsAbility to work effectively with global, virtual teamsHigh degree of initiative and self-motivationAbility to manage multiple priorities successfullyTeam oriented, with a focus on achieving team goalsStrong presentation and public speaking skillsSkills Required
Burp Suite, Penetration Testing, threat modeling , Owasp, Web Application