Full-Time

Offensive Security Practice Manager

Application Security

Posted on 6/18/2024

Praetorian

Praetorian

51-200 employees

Provides continuous cybersecurity testing services

Compensation Overview

$140k - $230k/yr

Senior

Remote in USA

Candidates must be based in California, Colorado, Washington, and New York for salary estimation.

Category
Cybersecurity
IT & Security
Requirements
  • 3+ years of experience in the cybersecurity field with exposure to application security, offensive security, or penetration testing (or 2+ years in any combination of these areas with additional experience in a related technical field)
  • 1+ years of experience in a leadership role (formal or informal), demonstrating the ability to coach, mentor, and lead technical teams
  • Familiarity with client-facing roles, including communicating technical findings and recommendations to non-technical stakeholders
  • Experience managing or contributing to the success of technical projects or initiatives
  • Basic understanding of web application testing, network penetration testing, or cloud security best practices
  • Eagerness to learn and grow into a full Practice Manager role, taking ownership of technical teams and projects
Responsibilities
  • Lead one of Praetorian’s security engineering practices as a front line manager
  • Primary focus on offensive application security service lines
  • Manage, develop, and retain a team of approximately 10 technically diverse and developing security engineers
  • Drive performance management by objectives and key results
  • Provide technical guidance, quality assurance, and oversight on client-facing engagements, such as foundational web application assessments or network penetration tests
  • Provide project management support on client-facing engagements from the initial preparation through engagement closeout
  • Guide, assist, and contribute to internal initiatives and development opportunities
  • Maintain a strong focus on both employee satisfaction and client satisfaction during service delivery
  • Assist with customer-facing interactions related to project scoping and qualification.
Desired Qualifications
  • Familiarity with offensive security methodologies, frameworks (e.g., OWASP ASVS, OWASP MASVS, OWASP WSTG, MITRE ATT&CK), or offensive security tools
  • Familiarity with threat modeling or security architecture
  • Basic project management experience or certifications (e.g., PMP, Agile certifications)
  • Bachelor’s degree in business, computer science, engineering, or a related field
  • Security certifications such as OSCP, OSWE, or equivalent

Praetorian provides ongoing cybersecurity testing services to protect various infrastructures, including IoT devices, SaaS applications, mobile apps, cloud systems, and corporate networks. Their approach involves continuous security analysis rather than one-time evaluations, allowing clients to identify and fix vulnerabilities as they emerge. This subscription-based model enables clients to enhance their security without needing extensive in-house resources. Praetorian's services include defensive enablement, red team operations, incident response, and automated security analysis, making them a reliable partner for organizations looking to maintain high security standards over time.

Company Size

51-200

Company Stage

Series A

Total Funding

$10M

Headquarters

Austin, Texas

Founded

2010

Simplify Jobs

Simplify's Take

What believers are saying

  • Increased demand for AI-driven cybersecurity aligns with Praetorian's innovation focus.
  • Growing interest in Kubernetes security tools boosts Praetorian's Konstellation tool adoption.
  • Zero-trust architecture adoption presents opportunities for specialized security assessments.

What critics are saying

  • AI-driven threats could outpace Praetorian's current capabilities.
  • Quantum computing may challenge Praetorian's encryption-based security solutions.
  • IoT ecosystem complexity may introduce hard-to-detect vulnerabilities.

What makes Praetorian unique

  • Praetorian offers continuous security testing, unlike traditional one-time evaluations.
  • Their subscription model ensures ongoing security analysis and vulnerability management.
  • Praetorian's expertise extends across IoT, SaaS, cloud, and critical infrastructure security.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Company Match

Employee Stock Purchase Plan

Paid Maternity Leave

Paid Paternity Leave

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

↑ 4%

1 year growth

↑ 4%

2 year growth

↑ 1%
PR Newswire
May 6th, 2025
Ur® Codes Pass Rigorous Independent Security Testing

Praetorian Security attests to the protocol's secure-by-design architectureSUMMERLIN, Nev., May 6, 2025 /PRNewswire/ -- FaceTec announced that its digitally-signed biometric barcode UR® Code protocol successfully passed Praetorian Security Inc's rigorous reverse engineering testing process and its risk-informed security assessment as the company continues to expand its industry-leading position in global 3D Face Verification and digital identity software.Praetorian completed reverse engineering analysis of the UR Code's SDK focused on identifying internal hashing mechanisms, encryption keys, and customer PII. During the analysis, Praetorian identified the following:0 Critical Risk Issues0 High Risk Issues0 Medium Risk Issues0 Low Risk Issues0 Informational Risk IssuesComplete attestation letters can be found here:www.urcodes.com/Praetorian_FaceTec_UR_Code_Security_Letter.pdfwww.urcodes.com/Praetorian_FaceTec_UR_Codes_Reverse_Engineering_Analysis_Letter.pdfPraetorian also tested security controls related to robust code obfuscation, like dead code insertion, control flow flattening, and variable, class, and function renaming.UR Codes enable legal identity-issuing authorities to provide machine-readable codes that bind together the legal identity data and biometric face data of a code holder. UR Codes provide similar privacy-protecting biometric security to e-passports, but without the usability and durability problems, or the exorbitant costs of scannable NFC chips.UR Codes are generated by issuing authorities using secure UR Encoder software that runs behind their own firewall. The issuing authority encodes the identity information and feature vector data from the face photo of the person who is being issued the UR Code. A digital signature is then derived and also encoded, verifying that the identity data was truly issued - as encoded - by the listed issuing authority. Using each issuer's unique public/private encryption key pair, the software cryptographically signs each UR Code, making them provably immutable

PRWeb
Jan 11th, 2024
Praetorian Appoints David Hunt As Vice President Of Applied Research

"David's exceptional track record in cybersecurity and his experience developing tools at the intersection of security and artificial intelligence makes him an invaluable addition to our company. David's leadership will be instrumental in driving our mission to innovate on behalf of our customers.". .

Praetorian
Oct 26th, 2023
Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747

Praetorian Group targeted the F5 BIG-IP Virtual Edition with the goal of finding an unauthenticated vulnerability that would result in complete compromise of the target server.

Security Boulevard
Aug 1st, 2023
Introducing konstellation, for Kubernetes RBAC analysis

Praetorian is excited to announce the upcoming release of Konstellation, a new open-source tool that simplifies Kubernetes role-based access control (RBAC) data collection and security analysis.

Praetorian
May 16th, 2023
Praetorian Named 2023 Cloud Security Awards Finalist

Praetorian Security, Inc. announced today it has been named a finalist in The Cloud Security Awards 2023 in the Best Security Solution in Risk Identification category for its Chariot Managed Service Solution.

INACTIVE