Talent.com
Unilever
Offensive Security Senior ManagerUnilever • Kingston upon Thames, England, GB
Offensive Security Senior Manager

Offensive Security Senior Manager

Unilever • Kingston upon Thames, England, GB
30+ days ago
Job type
  • Full-time
Job description

Overview

Job Title: Offensive Security Senior Manager

Business Function: Cyber Security

Location: Kingston Head Office / Bangalore

Unilever is a global leader in Food, Home and Personal Care products with sales in over 190 countries and 3.4 billion consumers daily. Unilever’s purpose is to make sustainable living commonplace. The Cyber Security team is a global, product-led function aligned to the NIST Cyber Security Framework, delivering capabilities across governance, protection, detection, response, and recovery.

Job Purpose

We are looking for a technically exceptional and visionary Senior Manager to lead our Offensive Security function. This role is strategic and hands-on, responsible for delivering high-impact penetration testing, attack surface management, and a mature bug bounty program. The ideal candidate will be a transformation leader with deep technical expertise in offensive security and a passion for building purple team capabilities that proactively identify and close control gaps across the enterprise.

The Senior Manager – Offensive Security will lead the evolution of our offensive security capabilities, delivering penetration testing, managing attack surface, and overseeing a global bug bounty program. The role requires identifying control gaps, advancing purple team maturity, and leading high-performing teams in a threat-informed environment.

Responsibilities

  • Technical Leadership & Execution
    • Personally lead and execute advanced penetration tests, red/purple team exercises, and adversary emulation campaigns across cloud, application, and infrastructure layers.
    • Identify and exploit vulnerabilities to simulate real-world attack scenarios, validate detection and response capabilities, and uncover control gaps.
    • Develop and maintain a Purple Team playbook tailored to business-specific technologies and threat models.
    • Integrate offensive findings into SOC tuning, detection engineering, and control validation workflows.
  • Program Ownership
    • Own and evolve the offensive security roadmap, including internal testing services, external bug bounty operations, and attack surface management.
    • Establish and lead a Purple Team Steering Committee with cross-functional stakeholders from Cyber, OT, R&D, and Business Units.
    • Drive quarterly purple team exercises and ensure findings are embedded into the broader Cyber Transformation roadmap.
  • Team Building & Transformation
    • Build and mentor a global team of offensive security engineers and red teamers.
    • Lead the transformation from traditional pentesting to intelligence-driven, continuous offensive security.
    • Foster a culture of innovation, experimentation, and continuous learning.
  • Collaboration & Influence
    • Partner with Threat Intelligence, SOC, and Engineering teams to contextualize findings and drive remediation.
    • Communicate technical findings clearly to both technical and executive audiences.
    • Influence security architecture and product design through early engagement and threat modeling.

Requirements

  • Advanced Penetration Testing: Deep experience conducting and leading penetration tests across web applications, APIs, cloud environments (Azure, AWS, GCP), and enterprise infrastructure.
  • Red and Purple Teaming: Expertise in adversary emulation, threat-informed defense, and purple team exercises that validate detection and response capabilities.
  • Attack Surface Management: Familiarity with ASM platforms and methodologies to continuously identify, assess, and reduce external exposure.
  • Bug Bounty Program Management: Experience managing or collaborating with external bug bounty platforms (e.g., HackerOne, Bugcrowd), including triage and remediation workflows.
  • Exploit Development & Vulnerability Research: Ability to identify and exploit zero-day and known vulnerabilities, and develop custom proof-of-concept exploits.
  • Tool Proficiency
    • Offensive tools: Cobalt Strike, Metasploit, Burp Suite, Nmap, BloodHound, Covenant, Sliver
    • Scripting: Python, PowerShell, Bash
    • Automation: CI/CD integration for security testing, custom tooling for red team automation
  • Detection Engineering Collaboration: Translate offensive findings into detection logic and partner with SOC teams to improve alerting and response.
  • Threat Modelling & MITRE ATT&CK: Strong understanding of attacker TTPs and ability to map findings to frameworks like MITRE ATT&CK and the Cyber Kill Chain.
  • Cloud Security Testing: Hands-on experience with offensive techniques in cloud-native environments, including IAM misconfigurations, container escape, and serverless exploitation.
  • Security Control Validation: Experience assessing the effectiveness of EDR, WAF, IAM, and other security controls through offensive testing.

Experience

  • 15+ years in cybersecurity, with 5+ years in offensive security and team leadership.
  • Hands-on experience with red/purple teaming, adversary emulation, and vulnerability exploitation.
  • Proficiency with tools such as Cobalt Strike, Metasploit, Burp Suite, BloodHound, and custom scripting.
  • Strong understanding of MITRE ATT&CK, cyber kill chain, and threat-informed defense.
  • Experience integrating offensive security into CI/CD pipelines and cloud-native environments.
  • Relevant certifications (e.g., OSCP, OSCE, CRTO, GXPN) strongly preferred.

Behaviours

Candidates would be required to demonstrate the Unilever Standards of Leadership & Values through the following behaviours:

  • Agility – Flexes leadership style and plans to meet changing situations with urgency. Learns from the past, envisions the future, and challenges the status quo.
  • Personal Mastery – Builds wellbeing and resilience; demonstrates emotional intelligence and openness to feedback.
  • Passion for High Performance – Inspires energy and focus to deliver results at speed.

Notes

About Unilever: Unilever is a leading global supplier with brands including Dove, Persil, Ben & Jerry’s, Marmite, and more. We are committed to equity, diversity, and inclusion and strive for a welcoming, inclusive workplace. We offer flexible working options where possible and provide wellbeing support.

Recruitment Fraud: Be vigilant for recruitment fraud. Unilever does not ask for payment or background checks up-front. If you encounter suspected fraud, report via Una Live Chat. We do not accept responsibility for candidates financially impacted by fraud.

#J-18808-Ljbffr
Create a job alert for this search

Offensive Security Senior Manager • Kingston upon Thames, England, GB

Similar jobs

Safeguarding Manager

Harrow SchoolHarrow on the Hill, England, GB
Full-time +1

CORPORATION SAFEGUARDING MANAGER Contract summary: Contract length: Permanent Working weeks: Full time, all year round Working hours: 40 hours per week, Monday to Friday all year round Salary: Plea... Show more

 • Promoted

Cyber Security Manager — Lead Strategy & Risk

TescoWelwyn Garden City, England, GB
Full-time

A leading mobile network provider in the UK is seeking a dedicated Cyber Security Manager to lead security initiatives and enhance security operations.The role involves maintaining stakeholder rela... Show more

 • Promoted

Security Operations Centre (SOC) Manager

PayPointWelwyn Garden City, England, GB
Full-time

Security Operations Centre (SOC) Manager.As our Security Operations Centre (SOC) Manager, you’ll play a pivotal role in protecting PayPoint’s enterprise, retail, digital and cloud platforms.This is... Show more

 • Promoted

Estimating Manager Passive Fire Protection

Mitchell Maguirecrawley, west sussex, WSX, United Kingdom
Full-time

Estimating Manager </b><b>Passive Fire Protection </b> </p><p >Job Title: Estimating Manager Passive Fire Protection </p><p >Job reference Number: ... Show more

 • Promoted

Tenancy Management Officer

The Hyde GroupCrawley, ENG, GB
Temporary

Chichester covering surrounding areas.Fixed Term Contract - 12 Month Maternity Cover ending 25/06/2027.Would you like to join Hyde as a Tenancy Management Officer?.At Hyde, we believe everyone dese... Show more

 • Promoted

VAT Senior Manager

BDOGatwick, GB
Full-time

An accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today's changing world.We work with the companies that are Britain's eco... Show more

 • Promoted

Site Security & Operations Leader

ICTSWest Drayton, England, GB
Full-time

A security management company is seeking a Site Manager in West Drayton to lead and manage a team of security supervisors and officers.The role involves maintaining key relationships, overseeing tr... Show more

 • Promoted

Training Manager (Interim)

Parkside RecruitmentHenfield, ENG, GB
Temporary

Our client is seeking an Interim Training Manager to join their team.This role is to lead the design, delivery and governance of operational training that builds capability supporting supervisors a... Show more

 • Promoted

Fire Security Engineer

Midasisleworth, United Kingdom
Full-time

PH1921 </b> Fire Service Engineer Fire and safety consultancy </p><p><b>REWARDS: £41k-£45k - </b>Basic Salary, 70K OTE, Car or car allowance allowance, Fuel Card &l... Show more

 • Promoted

Radiation Protection Adviser - Gosport

AWE Nuclear Security TechnologiesSouthwick, United Kingdom
Full-time

Radiation Protection Adviser - Gosport, Hampshire,PO12 2DL.Job Type:Full-TimeSalary: 47860 - 75640 per annum + Negotiable.Alverstoke (near Lee-On-Solent, Gosport) with.Just let us know your preferr... Show more

 • Promoted

Senior Security Research Engineer - Remote - up to £100k

Harvey NashHemel Hempstead, United Kingdom
Remote
Full-time

Senior Security Software Engineer | Vulnerability Research | up to £100K.We're partnered with a globally recognised technology organisation building advanced cyber capability across highly sensitiv... Show more

 • Promoted

Fire & Security Engineer

SER (Staffing) LtdRemote, HRT, United Kingdom
Remote
Full-time

Fire & Security Engineer<br>Service and Faults </strong><br><strong>Location: </strong> London<br><strong>Salary: </strong> £35,000 – £40,000 (DO... Show more

 • Promoted

Senior Cyber Security Project Manager

Pontoon SolutionsWelwyn Garden City, ENG, GB
Full-time

Senior Cyber Security Project Manager.Hybrid: 3 days per week in Welwyn Garden City, Hertfordshire.Strong, high-level Cyber PM required to join a complex cyber and infrastructure programme and deli... Show more

 • Promoted

Fire Security Engineer

HSB Technical LtdWest Sussex, ENG, GB
Full-time +1

Fire & Security Engineer (Installation, Service & Commissioning).Covering Sussex, Hampshire, Surrey & Dorset.Company van & fuel card, 4-day working week, paid holidays, on-call allo... Show more

 • Promoted

Fire & Smoke Technical Service Manager

CoSourcedCrawley, ENG, GB
Full-time

The Technical Service Manager AOV & Smoke Control is responsible for identifying, developing and converting technical opportunities within CoSourced Groups existing customer base and new accoun... Show more

 • Promoted

Assistant Manager

Heartwood InnsHorsham, England, GB
Full-time

On Target Earnings £40-42,000 (Including TRONC).At Heartwood Collection, we're on the lookout for passionate and vibrant individuals to join our team as an.We're an award-winning group of cosy pubs... Show more

 • Promoted

Site Security Manager

ICTSWest Drayton, England, GB
Full-time

To be part of a Security Management Team providing operational management to a team of security supervisors, controllers and security officers.Reporting to the Strategic Account Manager, and in con... Show more

 • Promoted

Senior Offensive Security Lead - Purple Team & Pentesting

UnileverKingston upon Thames, England, GB
Full-time

A global consumer goods company seeks a Senior Manager for Offensive Security to lead penetration testing and manage a global bug bounty program.The ideal candidate has 15+ years in cybersecurity, ... Show more