Manager, Cyber Assessment (Penetration Testing)
EX SquaredAt EX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.
Our client is a leading global organization in the professional services and consulting industry, supporting businesses with complex technology, cybersecurity, risk, compliance, and transformation initiatives.
For this position, EX Squared LATAM is supporting our client with the recruitment and selection process. The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.
Role Overview
We’re currently looking for a Manager, Cyber Assessment (Penetration Testing) to perform advanced, hands-on penetration testing and security assessment engagements across complex application, network, infrastructure, and cloud environments.
Despite the Manager title, this position is an Individual Contributor role with no direct reports or people-management responsibilities. The focus is on deep technical expertise, independent execution, stakeholder communication, and the ability to identify, validate, exploit, and clearly communicate security vulnerabilities.
Candidates must bring at least 5 years of hands-on Penetration Testing experience, with Pentesting as a primary/core responsibility. A broader Cybersecurity background where Penetration Testing has only been an occasional or secondary responsibility will not meet the requirements for this role.
Location
Mexico. Candidates located in Mexico City or Guadalajara are highly preferred.
- For professionals based in Mexico City or Guadalajara, the position follows a hybrid model with onsite attendance approximately 2–3 days per week.
- Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.
Contract Duration
Permanent, direct employment with the client.
This is a 100% payroll position in Mexico.
Working Hours
This position operates under 10-hour shifts, with one of the following schedules:
- Sunday through Wednesday, or
- Wednesday through Saturday.
Available shifts are:
- 7:00 a.m. – 5:00 p.m., or
- 1:00 p.m. – 11:00 p.m.
Candidates must be comfortable working within one of these schedules.
Language Requirement
Advanced English – C1 level.
The role requires candidates to conduct technical discussions, explain security findings, and collaborate directly with U.S.-based teams and stakeholders in English.
What you'll do
- Conduct detailed application, API, network, infrastructure, and cloud penetration testing engagements to identify exploitable vulnerabilities, security control gaps, and remediation opportunities.
- Plan and execute penetration testing across web applications, APIs, internal and external networks, cloud-hosted environments, and supporting infrastructure.
- Perform hands-on vulnerability validation and exploitation beyond automated vulnerability scanning.
- Identify and assess vulnerabilities such as authentication and authorization weaknesses, injection vulnerabilities, business logic flaws, insecure configurations, and sensitive data exposure.
- Document findings with clear technical evidence, business impact, risk context, reproducible steps, and practical remediation recommendations.
- Support remediation efforts through technical discussions, retesting, and collaboration with application, infrastructure, and security teams.
- Communicate assessment results to both technical and non-technical stakeholders through reports, walkthroughs, and remediation discussions.
- Apply established security assessment methodologies and frameworks such as MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, and PTES.
- Use scripting and automation to improve security assessment and penetration testing activities.
- Stay current with emerging vulnerabilities, exploitation techniques, security tools, and penetration testing methodologies.
- Work independently on technically complex assessments while exercising strong analytical judgment.
What you'll bring
- 5+ years of hands-on Penetration Testing experience as a primary/core professional responsibility.
- Strong practical experience performing manual web application penetration testing.
- Strong hands-on experience with API penetration testing.
- Experience conducting network and infrastructure penetration testing, including internal and external environments.
- Experience assessing cloud-hosted environments and a solid understanding of cloud security concepts.
- Proven ability to identify, validate, and exploit vulnerabilities rather than relying exclusively on automated scanning tools.
- Strong familiarity with MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, PTES, or similar methodologies.
- Experience with penetration testing, vulnerability scanning, exploitation, and security assessment tools.
- Proficiency in scripting and automation, using technologies such as Python, Bash, or PowerShell.
- Strong understanding of security principles, IT security controls, remediation practices, and common and emerging security threats.
- Ability to clearly document and explain technical vulnerabilities, their practical impact, and recommended remediation.
- Experience working directly with clients, project stakeholders, application teams, or business units.
- Strong verbal and written communication, analytical thinking, problem-solving, and independent judgment skills.
- Bachelor’s degree or equivalent relevant professional background.
What will make you stand out
- Certifications such as OSCP, GPEN, GWAPT, OSCE, GXPN, or similar.
- CISSP or cloud security/platform certifications.
- Particularly strong experience performing penetration testing across several domains, including applications, APIs, networks, infrastructure, and cloud.
- Strong scripting or automation capabilities that improve the efficiency or repeatability of penetration testing activities.
- Experience working directly with U.S.-based or multicultural teams.
- Ability to translate highly technical vulnerabilities into clear business risk and actionable remediation recommendations.
- A strong commitment to continuously learning new offensive security techniques, technologies, and assessment methodologies.
Why this opportunity?
This is an opportunity to join a large, globally recognized organization in the professional services and consulting industry and work on technically challenging security assessments within an international environment.
The position is particularly suited for an experienced penetration tester who wants to remain deeply hands-on technically while operating at a senior Manager level, without moving into a traditional people-management role.
You’ll have exposure to complex enterprise environments, U.S.-based stakeholders, modern application and cloud technologies, and a wide variety of penetration testing scenarios.
What the Client Offers
- Career growth opportunities.
- Meal/grocery vouchers.
- Savings fund.
- Remote-work allowance, when applicable.
Selection Process
The selection process is highly technical and focused on validating practical Penetration Testing expertise.
- Initial approximately 30-minute technical interview with the local leader, focused specifically on hands-on Penetration Testing depth and proficiency.
- Technical panel interviews with the U.S.-based team.
- The process may include a final interview with the U.S.-based Area Director.
- Background check.
Eligibility Note
This opportunity is available to candidates currently residing in Mexico.
Candidates located in Mexico City and Guadalajara are strongly preferred due to the hybrid working model. Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.
Candidates must also be comfortable working one of the established 10-hour Sunday–Wednesday or Wednesday–Saturday shifts.
Ready for your next career opportunity?
Apply through EX Squared LATAM and take the next step toward joining a global organization where advanced cybersecurity expertise, hands-on Penetration Testing, and real-world risk reduction come together.