Role Overview
We are a global technology enterprise building scalable digital platforms and operational systems for international enterprise clients. Our work is driven by a commitment to product excellence, engineering precision, speed of execution, and operational clarity.
As our platform scale expands, so does our exposure to system vulnerabilities, transaction abuse, data risks, and targeted attacks. We are establishing a dedicated Cybersecurity function to rigorously test our defenses, patch vulnerabilities, and protect our systems and users.
We are seeking a Cybersecurity Lead/Manager to own security testing end-to-end. In this role, you will be a hands-on technical authority—running security testing across web apps, APIs, cloud infrastructure, managing external pentest vendors, and reporting directly to executive management with full authority to set our security roadmap.
Key Responsibilities
-
Strategy & Roadmap: Define the overall security strategy—prioritizing high-risk areas, establishing risk benchmarks, and building out the cybersecurity function as the team expands.
-
Hands-On Testing: Plan and execute security testing across web applications, APIs, network infrastructure, and AWS cloud environments.
-
Logic & Integrity Testing: Test platforms for deep business-logic flaws, including account takeover (ATO), payment abuse, bonus manipulation, and platform integrity vulnerabilities.
-
Asset & Risk Governance: Build and maintain an accurate asset inventory and risk register to ensure total visibility over exposed attack surfaces.
-
Vendor & Pentest Management: Scope and manage third-party penetration testing and red-teaming vendors, ensuring findings are systematically remediated and tracked.
-
Vulnerability & Incident Response: Establish end-to-end vulnerability management workflows, continuous monitoring, and incident response procedures.
-
Culture & Awareness: Run simulated phishing campaigns, execute social engineering assessments, and drive company-wide security awareness.
-
Engineering Advisory: Partner with software engineering teams to conduct security reviews on new product features and embed secure coding practices.
-
Executive Visibility: Translate complex vulnerability data into clear, business-level risk summaries for leadership.
Requirements
-
5+ years in cybersecurity, with a strong background in hands-on penetration testing or security engineering.
-
Deep technical knowledge of web/API security (OWASP Top 10), infrastructure pentesting, and AWS cloud security.
-
Proven ability to uncover complex business-logic vulnerabilities, going beyond automated scanners.
-
Practical experience in incident response and handling active security events.
-
Demonstrated history of scoping, managing, and evaluating third-party security vendors.
-
Clear verbal and written English communication skills; able to translate technical vulnerabilities into executive risk metrics.
-
High ownership mindset with meticulous attention to detail.
Strong Pluses
-
Experience securing high-traffic consumer platforms featuring user authentication and online payment processing.
-
Security experience inside gaming, fintech, or real-money transactional platforms.
Note: Full-time, dedicated engagement. Secondary employment, advisory roles, or freelance consulting are strictly prohibited.