Lead Manager - Information Security
CHENNAI, Infosys Limited · Chennai, Tamil Nadu
Not Disclosed
Job Description
## Educational Qualification
* Bachelor of Engineering (B.E.)
## Service Line
**Information Security Group**
## Key Responsibilities
* Plan and execute authorized **Red Team** assessments to simulate real-world cyber threats across enterprise environments.
* Perform security testing covering cloud infrastructure, applications, endpoints, networks, Active Directory, and identity platforms.
* Execute controlled attack simulations to evaluate the effectiveness of security controls and incident response capabilities.
* Identify vulnerabilities, misconfigurations, and security weaknesses that could be exploited by attackers.
* Conduct penetration testing and exploitation activities within approved project scope while ensuring compliance with organizational policies.
* Analyze attack paths and demonstrate how critical assets could be compromised based on business risk.
* Collaborate with Security Operations Center (SOC), Incident Response, Detection Engineering, and Infrastructure teams to strengthen defensive measures.
* Participate in Purple Team exercises to validate security detections, improve monitoring rules, and enhance response procedures.
* Develop and maintain red team methodologies, playbooks, automation scripts, and security testing frameworks.
* Prepare detailed technical reports with risk assessments, remediation recommendations, and executive-level summaries.
* Coordinate with team members to ensure effective communication, task management, and successful project execution.
* Define responsibilities, monitor progress, and support knowledge sharing within the security team.
## Technical & Professional Requirements
* Hands-on experience with Red Team tools such as **Kali Linux**, **Cobalt Strike**, **Metasploit**, **Empire**, **Sliver**, and **BloodHound**.
* Strong understanding of **Windows** and **Linux** operating systems, Active Directory, authentication mechanisms, and identity-based attacks.
* Experience performing network, web application, and infrastructure security assessments.
* Proficiency in scripting using **Python**, **PowerShell**, and **Bash** for automation and offensive security tasks.
* Knowledge of MITRE ATT&CK framework, attack simulation techniques, and adversary emulation.
* Excellent analytical, troubleshooting, documentation, and risk communication skills.
* Ability to collaborate with cross-functional security and engineering teams.
## Preferred Skills
* Security Operations Center (SOC) Operations
* Red Team Operations
* Penetration Testing
* Ethical Hacking
* Active Directory Security
* Windows & Linux Security
* Kali Linux
* Cobalt Strike
* Metasploit
* BloodHound
* Python
* PowerShell
* Bash Scripting
* MITRE ATT&CK Framework
### Preferred Certifications
* OSCP (Offensive Security Certified Professional)
* CRTO (Certified Red Team Operator)
* CEH (Certified Ethical Hacker)
* GWAPT (GIAC Web Application Penetration Tester)
* Bachelor of Engineering (B.E.)
## Service Line
**Information Security Group**
## Key Responsibilities
* Plan and execute authorized **Red Team** assessments to simulate real-world cyber threats across enterprise environments.
* Perform security testing covering cloud infrastructure, applications, endpoints, networks, Active Directory, and identity platforms.
* Execute controlled attack simulations to evaluate the effectiveness of security controls and incident response capabilities.
* Identify vulnerabilities, misconfigurations, and security weaknesses that could be exploited by attackers.
* Conduct penetration testing and exploitation activities within approved project scope while ensuring compliance with organizational policies.
* Analyze attack paths and demonstrate how critical assets could be compromised based on business risk.
* Collaborate with Security Operations Center (SOC), Incident Response, Detection Engineering, and Infrastructure teams to strengthen defensive measures.
* Participate in Purple Team exercises to validate security detections, improve monitoring rules, and enhance response procedures.
* Develop and maintain red team methodologies, playbooks, automation scripts, and security testing frameworks.
* Prepare detailed technical reports with risk assessments, remediation recommendations, and executive-level summaries.
* Coordinate with team members to ensure effective communication, task management, and successful project execution.
* Define responsibilities, monitor progress, and support knowledge sharing within the security team.
## Technical & Professional Requirements
* Hands-on experience with Red Team tools such as **Kali Linux**, **Cobalt Strike**, **Metasploit**, **Empire**, **Sliver**, and **BloodHound**.
* Strong understanding of **Windows** and **Linux** operating systems, Active Directory, authentication mechanisms, and identity-based attacks.
* Experience performing network, web application, and infrastructure security assessments.
* Proficiency in scripting using **Python**, **PowerShell**, and **Bash** for automation and offensive security tasks.
* Knowledge of MITRE ATT&CK framework, attack simulation techniques, and adversary emulation.
* Excellent analytical, troubleshooting, documentation, and risk communication skills.
* Ability to collaborate with cross-functional security and engineering teams.
## Preferred Skills
* Security Operations Center (SOC) Operations
* Red Team Operations
* Penetration Testing
* Ethical Hacking
* Active Directory Security
* Windows & Linux Security
* Kali Linux
* Cobalt Strike
* Metasploit
* BloodHound
* Python
* PowerShell
* Bash Scripting
* MITRE ATT&CK Framework
### Preferred Certifications
* OSCP (Offensive Security Certified Professional)
* CRTO (Certified Red Team Operator)
* CEH (Certified Ethical Hacker)
* GWAPT (GIAC Web Application Penetration Tester)