Full-Time

Penetration Testing Manager

Updated on 9/3/2026

Laika

Laika

201-500 employees

End-to-end security compliance audit platform

No salary listed

North America

Remote

Remote within Latin America.

Category
Cybersecurity (1)
Required Skills
Bash
Python
Vulnerability Analysis
SOC 2
AWS
Penetration Testing
HIPAA

Get referred to Laika

See people who can refer or advise you

Requirements
  • At least 5–8 years of experience in penetration testing or red teaming, including at least 1 year of people management experience.
  • Prior experience mentoring or managing security professionals.
  • Strong technical expertise in web application, application programming interface, mobile, and network penetration testing, plus a working understanding of testing artificial intelligence-powered systems such as large language model applications, agents, and Model Context Protocol integrations.
  • At least one of the following certifications: Offensive Security Certified Professional, Offensive Security Certified Expert, Offensive Security Web Expert, Practical Web Pentest, or Burp Suite Certified Practitioner.
  • Knowledge of current attack methods, manual penetration testing techniques, and popular hacking tools, including Claude Code, Codex, Burp Suite Professional, and sqlmap, as well as using artificial intelligence tools to accelerate testing while maintaining control over results.
  • Proficient scripting skills in Bash, Python, or similar languages, including the ability to use artificial intelligence coding assistants to build and adapt tooling quickly.
  • Fluency in English with strong verbal and written communication skills for explaining complex technical topics to varied stakeholders.
  • Strong operational ownership and the ability to balance delivery speed, quality, customer satisfaction, and appropriate use of artificial intelligence versus human expertise.
Responsibilities
  • Lead and manage a penetration testing team of 4–5 pentesters, providing technical guidance, feedback, and professional development support.
  • Ensure assigned engagements are delivered on time, within scope, and according to Thoropass standards.
  • Conduct one-on-one meetings, coaching sessions, and technical reviews to maintain motivation, quality, and team engagement.
  • Collaborate with other Penetration Testing Managers to balance workloads, share best practices, and standardize delivery processes.
  • Partner with leadership to improve internal operations, delivery frameworks, and team morale.
  • Conduct web, network, application programming interface, large language model, and Model Context Protocol penetration tests using black-box, gray-box, and white-box methods, combining manual testing with traditional automation and artificial intelligence-assisted tooling.
  • Identify and exploit vulnerabilities to build realistic attack paths and demonstrate business impact, including prompt injection, insecure model outputs, data leakage, unsafe tool and function calling, and abuse of agentic or Model Context Protocol workflows.
  • Produce detailed customer-facing reports with practical remediation guidance in clear professional English, using artificial intelligence to draft and refine content while manually verifying every finding, rating, and recommendation.
  • Stay current with modern attack techniques and tools, including offensive and defensive uses of artificial intelligence.
  • Scale the penetration testing program through improved workflows, templates, and automation.
  • Lead internal knowledge-sharing sessions and encourage continuous learning.
  • Collaborate with Customer Success, Sales, and Operations to support seamless customer delivery.
  • Support hiring, onboarding, and training as the penetration testing function expands.
Desired Qualifications
  • Contributions to the security community through conference talks, blog posts, open-source projects, or CVE discoveries.
  • Knowledge of compliance frameworks such as SOC 2, ISO 27001, PCI DSS, and HIPAA.
  • Experience working with Sales, Customer Success, and Engineering teams to scope, plan, or deliver penetration tests.
  • Participation in bug bounty programs or vulnerability research initiatives.
  • Experience with artificial intelligence or large language model security testing and cloud environments such as Amazon Web Services.
  • Experience with Hack the Box, PortSwigger Academy, or similar learning platforms.

Laika provides a platform called Thororpass that helps businesses manage audits and achieve compliance across SOC 2, ISO 27001, HITRUST, and PCI DSS. Thororpass combines technology with expert auditors to support end-to-end audits, adapts to a company’s current compliance stage, and scales workflows as a business grows. It differentiates itself by offering an all-in-one solution for multiple frameworks with human oversight, reducing gaps and surprises compared to using separate tools or fragmented services. The goal is to make compliance worry-free, help organizations get compliant on the first attempt, and let teams focus on strategy and growth while security scales with the business.

Company Size

201-500

Company Stage

Series C

Total Funding

$98M

Headquarters

New York City, New York

Founded

2019

Get referred to Laika

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Thoropass launched Smart Sort AI on January 29, 2026, expanding evidence automation.
  • August 12, 2026 Inc. 5000 recognition signals continued revenue growth and market traction.
  • March 2026 AI-risk report positions Thoropass as a trusted voice on governance gaps.

What critics are saying

  • Vanta, Drata, and Secureframe pressure Thoropass with software-first models and broader ecosystems.
  • AI compliance tooling is commoditizing fast; January 2026 Smart Sort reduces switching friction.
  • If enterprises unbundle audits from software, Thoropass loses its core all-in-one wedge by 2027.

What makes Laika unique

  • Thoropass bundles audit software and in-house auditors, unlike Vanta or Drata.
  • Its July 2026 MCP Server targets AI-native audit workflows across customer agents.
  • Rebrand from Laika to Thoropass unified software, services, and assurance under one identity.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Early equity in a fast-growing company

Unlimited PTO

Remote work from home model

Stipend for home office equipment

Quarterly wellness and home wifi stipend

Paid courses and certifications

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

3%
Laika
Mar 2nd, 2023
Laika Welcomes Dicken Chaplin as First CFO

After an exhaustive search, Laika is excited to welcome Dicken Chaplin as its first-ever CFO!

TechCrunch
Nov 8th, 2022
Laika laps up $50M for its automated security compliance platform

GDPR, HIPAA, SOC 2... compliance is the order of the day for organizations wanting to work together and to keep customers' trust.

PR Newswire
Aug 30th, 2022
Glean Ai Completes Soc 2® Type 1 Attestation With Laika

Glean AI is committed to the industry's highest standards for managing customer data and has partnered with Laika to build credibility with customers. NEW YORK, Aug. 30, 2022 /PRNewswire/ -- Glean AI , a SaaS company that helps businesses save money through deep insights and automation, announced today they have completed the SOC 2® Type 1 attestation

PR Newswire
Jul 27th, 2022
Hubsync Completes Soc 2® Type 1 Certification With Laika

Achieving SOC 2 compliance highlights HubSync's commitment to the top CPA firms and tax professionals' highest standards for managing customer data. BOSTON, July 27, 2022 /PRNewswire/ -- HubSync , the industry's first fully digital, end-to-end productivity platform for top CPA firms and tax professionals, announced today they have completed the SOC 2® Type 1 examination and are officially SOC 2 compliant

PR Newswire
Jun 28th, 2022
Reprise Completes Soc 2® Type 2 Audit, Enhancing Commitment To Security, Privacy, And Confidentiality

BOSTON, June 28, 2022 /PRNewswire/ -- Reprise , the only demo creation platform go-to-market teams use to create both live and guided demos, announced the successful completion of its System Organization Control (SOC) 2 Type 2 audit. The American Institute of Certified Public Accounts (AICPA) developed the SOC 2® Type 2 auditing standards, requiring all security practices and processes meet or exceed AICPA Trust Service Criteria. Reprise