Job Title:
Lead – Red Team
Job Details:
Business Unit: Information Security Group
Team: ISG
Reports to: Head – Red Team & Bug Bounty
Location: Kanjurmarg
Role Type: Supervisory Role
Direct Reportees: 4-5
Travel: Moderate
Job Band: D1
JD Created: 14 Feb 2025
Version: 1.0
Job Purpose:
Orchestrates offensive security operations
Simulates real-world attacks
Identifies vulnerabilities
Enhances security posture
Mentors team members
Contributes to security strategy
Job Responsibilities:
Plans, coordinates red team engagements
Executes penetration tests, social engineering, physical security
Evaluates security controls, provides improvement insights
Collaborates with blue teams, incident response
Mentors junior red team members, provides guidance
Stays updated on threats, develops tools
Incorporates threat intelligence into operations
Reviews, refines red team processes
Engages stakeholders, communicates findings
Ensures compliance with standards
Educational Qualifications:
Graduate/Bachelors/Masters in Engineering/IT/Cybersecurity
Key Skills:
Expertise in web, network, mobile penetration tests
Identifies, assesses vulnerabilities
Familiarity with OWASP, NIST, MITRE ATT&CK
Analyzes threat intelligence
Leads, mentors security professionals
Analytical, critical thinking skills
Manages multiple red team engagements
Stays updated on security trends
Experience Required:
15-18 years proven Red Team experience
Relevant experience leading Red Team practice
Major Stakeholders:
Internal audit, BTG, IT teams, business teams
This is a strategic yet deeply hands-on leadership role, responsible for designing and executing adversarial attack simulations on both traditional systems and cutting-edge Al systems.
The ideal candidate will have a strong background in Offensive Security Testing, Al Security, Agentic Al systems, and Red Team operations, with the ability to establish enterprise-grade offensive Al frameworks.
Key Responsibilities:
Build and lead the Bank's Al Red Team from the ground up.
Establish AI security testing practice aligned with established industry frameworks such as MITRE ATT&CK, MITRE ATLAS, OWASP, OSSTMM etc.
Develop and operationalize autonomous Agentic systems capable of executing adversarial attacks on the Bank's Al and traditional technology systems.
Plan attack campaigns chains and provide active guidance to team members on their activities and overall program governance.
Keep abreast with latest attacks and mentor junior team members and use insights to conduct Adversarial campaigns against the bank’s traditional and Al systems.
Prepare deep-dive and executive reports for various stakeholders including senior leadership.
Required Experience:
18+ years of demonstrated hands on experience covering Development, Offensive Security, Red Teaming, Penetration Testing, AppSec, Al/ML Security.
Proven expertise in designing and running adversarial attack simulations.
Hands-on experience with Al Security, adversarial ML techniques, LLM vulnerabilities, and Agentic Al architectures.