

Alois Solutions
https://aloissoutions.comAbout
Company social profiles
Jobs at Alois Solutions
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
Key Responsibilities
- Establish, lead, and develop a penetration testing team, including recruitment, onboarding, mentoring, performance management, and career development.
- Define the team structure, capability model, skills matrix, training plan, and operating procedures.
- Develop and mature penetration testing services across areas such as web applications, APIs, infrastructure, cloud, Active Directory, wireless, mobile, social engineering, red teaming, and attack simulation.
- Define, own, and maintain methodologies, standards, scopes of work, report templates, and QA processes.
- Own engagement models and commercial assets including pricing models and delivery processes..
- Own the end-to-end delivery of penetration testing engagements, ensuring work is delivered safely, legally, on time, and to a high technical standard.
- Act as the technical authority for penetration testing, providing escalation support and quality review for complex findings and reports.
- Build trusted relationships with clients, internal stakeholders, technology teams, risk teams, and senior leadership.
- Identify market demand, emerging threats, and customer needs to shape the future service roadmap.
- Support pre-sales, bid responses, proposals, scoping calls, statements of work, and commercial discussions.
- Ensure all testing activity is conducted within agreed rules of engagement, legal boundaries, regulatory requirements, and internal governance.
- Implement quality control processes, peer review, report assurance, technical standards, and continuous improvement mechanisms.
- Track team performance, utilisation, revenue, margin, delivery quality, customer satisfaction, and remediation outcomes where relevant.
- Maintain awareness of emerging vulnerabilities, exploit techniques, threat actor tactics, industry trends, and regulatory changes.
- Represent the penetration testing function in senior management forums, client meetings, audits, and risk committees.
- Develop strategic partnerships, tooling strategies, lab environments, knowledge bases, and reusable assets to improve delivery efficiency and quality.
Required Skills and Experience
- Significant industry experience in penetration testing, offensive security, red teaming, vulnerability assessment, or security consultancy.
- Proven experience in leading, managing, and mentoring penetration testers and offensive security professionals.
- Demonstrable ability to create, grow, or mature a security testing function, consultancy practice, or technical service line.
- Strong technical background across web application, API, infrastructure, cloud, Active Directory, and network penetration testing.
- Experience in developing service offerings, methodologies, testing standards, engagement models, and reporting frameworks.
- Strong understanding of common security frameworks, standards, and scoring methodologies, including OWASP, MITRE ATT&CK, NIST, ISO 27001, PCI DSS, Cyber Essentials, and CVSS.
- Experience in managing multiple concurrent engagements, priorities, stakeholders, and delivery risks.
- Ability to review and challenge technical findings, exploit evidence, risk ratings, and remediation recommendations.
- Strong commercial awareness, including experience with scoping, pricing, proposals, bids, utilisation, profitability, and customer relationship management.
- Excellent written and verbal communication skills, with the ability to engage technical teams, executives, clients, auditors, and regulators.
- Strong understanding of legal, ethical, and operational risk considerations associated with penetration testing.
- Experience building processes for quality assurance, peer review, safe testing, evidence handling, and reporting consistency.
Certifications
Candidates should hold relevant industry certifications such as:
- OSCP, OSEP, OSWE, OSED, or other Offensive Security certifications
- CREST Certified Tester, CREST Certified Infrastructure Tester, CREST Certified Web Application Tester, or equivalent
- GIAC certifications such as GPEN, GWAPT, GXPN, GMOB, GCPN, or GSE
- CISSP, CISM, CRISC, or similar senior security management certifications
- CompTIA PenTest+ or Security+
Holding multiple technical and leadership-focused certifications would be advantageous.
Desirable Skills
- Experience building a penetration testing team, consultancy practice, or managed security testing service from inception through to delivery and execution.
- Experience creating go-to-market propositions, service catalogues, sales collateral, and delivery playbooks.
- Previous responsibility for revenue, budget, headcount, utilisation, margin, or service profitability.
- Experience with red teaming, threat-led penetration testing, adversary simulation, purple teaming, or assumed-breach exercises.
- Experience delivering services aligned to CREST, PCI DSS, CBEST, TIBER, STAR-FS, or similar assurance schemes.
- Knowledge of cloud security testing across AWS, Azure, or Google Cloud Platform.
- Experience with DevSecOps, CI/CD security testing, container security, Kubernetes assessments, and secure software development practices.
- Experience selecting, implementing, and managing penetration testing tools, labs, reporting platforms, and collaboration systems.
- Experience managing external suppliers, contractors, or partner organisations.
- Ability to mentor senior consultants and develop future technical leaders.
Similar companies
About the company
Knacklabs.ai is Product Development Studio. WE BUILD TRUE PRODUCT TEAMS for our clients. Each team is a small, well-balanced group of geeks and a product manager that together produce relevant and high-quality products. We use data to make decisions, bringing big data and analysis to software development. We believe the product development process is broken as most studios operate as IT Services. We operate like a software factory that applies manufacturing principles of product development to the software.
Jobs
9
About the company
Deep Tech Startup Focusing on Autonomy and Intelligence for Unmanned Systems. Guidance and Navigation, AI-ML, Computer Vision, Information Fusion, LLMs, Generative AI, Remote Sensing
Jobs
5
About the company
Jobs
1
About the company
Jobs
22
About the company
We are hiring for multiple clients
Jobs
3
About the company
OIP Insurtech streamlines insurance operations and optimizes workflows by combining deep industry knowledge with advanced technology. Established in 2012, OIP InsurTech partners with carriers, MGAs, program managers, and TPAs in the US, Canada, and Europe, especially the UK.
With 1,200 professionals serving over 100 clients, we deliver insurance process automation, custom software development, high-quality underwriting services, and skilled tech staff to augment our clients.
While saving time and money is the immediate win, the real game-changer is giving our clients the freedom to grow their books, run their businesses, and focus on what they love. We’re proud to support them on this journey and make a positive impact on the industry!
Jobs
2
About the company
Jobs
1
About the company
At IndiDino, we are building Bharat-focused products for a billion people with the goal of creating a net positive impact. We are driven by a simple mission — to create meaningful products that solve real problems at scale and improve the lives of people across India. By combining innovation, technology, and a deep understanding of Bharat, we aim to build solutions that empower communities and create lasting value.
Jobs
1
About the company
finban gives small and mid-sized companies a clear view of their financial future. The platform connects bank accounts (PSD2), accounting systems such as DATEV, Lexware Office and sevdesk, payment providers like Stripe and PayPal, CRM systems and spreadsheets — and consolidates them into a single, always-current liquidity plan.
What sets finban apart is how it handles data. Instead of forcing one source of truth, actuals from the bank, open receivables and payables from accounting, and forward-looking budget assumptions coexist side by side. As real payments come in, they replace the plan automatically. The result is a forecast that stays accurate without manual maintenance.
Built in Germany, finban today serves primarily the DACH market — with an integration and banking layer designed to extend across Europe and beyond. It's made for companies of up to around 100 employees: teams that need serious financial visibility but don't have a dedicated treasury department to produce it.
Jobs
1
About the company
Jobs
1





