Senior VAPT Practice Head
Job Description
Job ID: R - 8100\nJob Title: Senior VAPT Practice Head\nLocation: Candidate should be willing to relocate to Kuala lumpur\n \nEC-Council...
Job Description
Job ID: R - 8100
\nJob Title: Senior VAPT Practice Head
\nLocation: Candidate should be willing to relocate to Kuala lumpur
\nEC-Council is the world's largest cyber security technical certification body. We operate in 145 countries globally and we are the owner and developer of various world-famous cyber security programs. We are proud to have trained and certified over 400,000 information security professionals globally that have influenced the cyber security mindset of countless organizations worldwide.
\nVisit us on www.eccouncil.org
\nJob Summary
\nThe Senior VAPT Practice Head is a strategic leadership role responsible for the end-to-end lifecycle of the Vulnerability Assessment and Penetration Testing (VAPT) business unit. This individual will act as the architect of our testing methodologies, the driver of operational delivery excellence, and the primary technical ambassador for our clients.
\nThe ideal candidate is a subject matter expert in offensive security who can transition seamlessly from deep-dive technical reviews to high-level strategic discussions with C-suite stakeholders. You will be responsible for scaling the practice, ensuring the highest quality of deliverables, and driving revenue through technical pre-sales and relationship management.
\nKey Responsibilities
\n1. Practice Management & Strategy (Growth & Innovation)
\n- \n
- Service Roadmap: Define and execute the long-term vision for the VAPT practice, including expanding service lines (e.g., Red Teaming, Cloud Security, DevSecOps, API Security). \n
- Methodology Development: Establish and continuously evolve standardized testing frameworks based on industry standards (OWASP, NIST, OSSTMM, PTES) to ensure consistent, high-quality results. \n
- Resource & Talent Management: Lead recruitment, mentoring, and technical training for a team of penetration testers. Build a culture of continuous learning and research. \n
- Tooling & Automation: Evaluate, implement, and manage the security testing stack (automated scanners, manual exploitation tools, and custom-built scripts) to increase efficiency and coverage. \n
- P&L Responsibility: Manage the practice budget, optimize resource utilization, and drive profitability through efficient delivery models. \n
2. Delivery Management (Excellence & Quality Assurance)
\n- \n
- Operational Oversight: Oversee the end-to-end execution of all VAPT engagements, ensuring projects are delivered on time, within scope, and according to agreed-upon SLAs. \n
- Quality Control: Act as the final technical authority for all deliverables. Perform rigorous reviews of technical reports to ensure findings are accurate, risks are clearly articulated, and remediation advice is actionable. \n
- Risk Management: Ensure all testing activities are conducted within the bounds of legal and ethical frameworks, managing the risks associated with high-impact testing environments. \n
- Continuous Improvement: Implement feedback loops from clients and post-engagement reviews to drive iterative improvements in delivery processes. \n
3. Customer Engagement & Pre-Sales (Consulting & Revenue)
\n- \n
- Technical Pre-Sales: Partner with the sales team to lead technical discovery sessions, define project scopes, provide complex estimations, and draft technical proposals/RFPs. \n
- Client Advisory: Act as a trusted advisor to clients, translating complex technical vulnerabilities into business-level risk intelligence for CISOs and Board members. \n
- Relationship Management: Maintain strong, long-term relationships with key accounts, identifying opportunities for upselling, cross-selling, and service expansion. \n
- Incident Response/Crisis Consulting: Serve as the lead technical consultant during critical security incidents or high-stakes compliance audits involving client infrastructure. \n
Required Qualifications & Skills
\nTechnical Expertise
\n- \n
- Advanced Penetration Testing: Deep expertise in Web Application, Mobile (iOS/Android), Network, Cloud (AWS/Azure/GCP), API, and Wireless security testing. \n
- Offensive Security Mastery: Proficiency with industry-standard tools (Burp Suite Professional, Metasploit, Nessus, Nmap, Cobalt Strike, etc.) and the ability to develop custom automation scripts (Python, Bash, or Go). \n
- Security Frameworks: Expert knowledge of OWASP Top 10, NIST SP 800-115, and regulatory requirements (PCI-DSS, HIPAA, GDPR). \n
Certifications
\n- \n
- Mandatory: Advanced VAPT-specific certifications (e.g., OSCP, OSWE, or OSCE). \n
- Preferred: CREST Certified (e.g., CREST Registered Penetration Tester or higher) is highly desirable. \n
- Bonus: CISSP, CISM, or cloud-specific security certifications (AWS Certified Security – Specialty). \n
Leadership & Soft Skills
\n- \n
- Communication: Exceptional ability to write technical reports and present complex security findings to non-technical stakeholders. \n
- Strategic Thinking: Ability to balance technical excellence with business objectives and profitability. \n
- Project Management: Proven experience managing multiple concurrent high-stakes projects in a fast-paced environment. \n
Education
\n- \n
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or a related field. \n
About Our Culture:
\nEC-Council is driven by a mission to strengthen global cybersecurity capability and advance the profession of ethical hacking and information security. Our teams operate across regions and cultures, united by integrity, professionalism, and a commitment to meaningful impact. Continuous learning and accountability are encouraged, empowering individuals to take ownership of their contributions. Respect, trust, and ethical conduct guide how we work with colleagues, partners, and the global cybersecurity community.
\nAdditional Information:
\nEC-Council is an equal opportunity workplace and an affirmative action employer. We are committed to providing equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status. We do not discriminate based on these or any other characteristics protected by applicable laws or regulations in the locations where we operate.
\nEC-Council is dedicated to working with and providing reasonable accommodations to individuals with d. isabilities. If you have a medical condition or disability that limits your ability to complete any part of the application process and require reasonable accommodation, please contact us at [email protected] and let us know how we can assist.
\nTo be eligible for this position, candidates must be able to provide proof that they are either a citizen of the country or have legal authorization to work in the country where the position is posted and are currently residing there. EC-Council does not offer employment to ineligible candidates and reserves the right to revoke employment in case the candidate loses the authorization to work.
\nIf, as part of the recruitment process, you are required to complete or submit any form of work, project, case study, or assignment, please note that such material will be considered the exclusive property of EC-Council. By submitting such work, you acknowledge that EC-Council retains all rights, title, and interest in the submitted content, including any intellectual property contained therein.
\nCandidates further waive any intellectual property or moral rights in such submissions, confirm that the work is original and free of third-party infringement, and acknowledge that it is provided solely for evaluation purposes, with no ownership or other rights retained.
\nOur Privacy Policy outlines how we collect, use, store, and protect your personal data during the recruitment process. This may include information such as your name, contact details, employment history, qualifications, and any other details you provide as part of your application. All data is handled in compliance with applicable data protection and privacy regulations.
\nPlease review our policy here: EC-Council Privacy Policy- User & company | Data ProtectionSubmission of your application will be considered as your acceptance of the terms stated above.
Below are some other jobs we think you might be interested in.
-
Practice Head
- UST
- Pattom, KL, IN
Job DescriptionWe are looking for a dynamic and visionary Practice Head to lead and grow our Microsoft Dynamics 365 Practice in India , encompassing...31 Aug -
VAPT Lead
- Adani Group
- Ahmedabad, Gujarat, India
About Business:Adani Group: In recent years, we have evolved from a new player in power generation to India's largest private thermal power producer,...13 Aug -
Architect VAPT
- Persistent Systems
- Pune, MH, IN
Job DescriptionAbout Position: We are seeking a senior Transition Transformation (TT) Architect / SME for the TT - Appsec, App PT, Threat Modeling, RBVM...31 Aug -
Practice Head
- Sutherland
- Hyderabad, TG, IN
Job DescriptionRole Overview We are seeking an experienced Infrastructure & Cloud Management Practice Head to lead market growth, strategic account...31 Aug -
VAPT Security Engineer
- IT Careers
- New Delhi
Experience: Minimum 4 years of experience in cybersecurity, VAPT, or information security roles. Technical Expertise: Vulnerability Management:...28 Aug -
VAPT / OSCP - Manager
- KPMG
- Hyderabad,Telangana,IN,500081
About KPMG in IndiaKPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited....12 Aug -
NopalCyber- AVP-VAPT
- Nexthire
- Hyderabad,IN
NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Managed extended...12 Aug -
Salesforce Practice Head
- Veracity
- Bengaluru,Karnataka,India
Leadership role in Salesforce Product Engineering Location: Bangalore Experience: 12-15 years in building commercial, enterprise SaaS Products...15 Aug -
VAPT - Appsec / Red Teaming
- KPMG
- Mumbai,Maharashtra,IN,400063
About KPMG in IndiaKPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited....26 Aug -
VAPT - Appsec / Red Teaming
- KPMG
- Gurugram,Haryana,IN,122002
About KPMG in IndiaKPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited....14 Aug -
Security Analyst - Application Security VAPT
- JUARA IT SOLUTIONS
- Chennai, Tamil Nadu, India
Job Title: Security Analyst - Application Security VAPT & CERTIn Empanelment/Experience (Mandatory) Experience: 5+ Years Location: Client Location...07 Aug -
Coralogix- Cloud Security Analyst-VAPT
- Nexthire
- Gurugram,IN
Title: Cloud Security Analyst (SOC/SIEM)Experience Level: 3- 6+ years Location: GurgaonWe work 5 days a week from the office. 24*7 rotational shift env....12 Aug -
Associate Consultant - VAPT / Red Teaming
- KPMG
- Mumbai,Maharashtra,IN,400063
About KPMG in IndiaKPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited....09 Aug -
Lead Information Security Analyst - VAPT Management
- iMerit Technology
- Hyderabad, TG, IN
Job DescriptionAt iMerit , we help some of the world's leading AI and technology companies build accurate, reliable, and scalable AI solutions. As our...31 Aug -
VAPT-DevSecops Experts(Individual contributor)
- Anaplan
- Gurugram
Senior Vulnerability Remediation EngineerP R O D U C T S E C U R I T Y A N A P L A NReports to: Senior Manager, Platform Security Working model:...14 Aug -
VAPT - AppSec / Red Teaming - Acon
- KPMG
- Bangalore,Karnataka,IN,560071
KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established...27 Aug -
VAPT - Appsec / Red Teaming - Consultant - Kochi
- KPMG
- Kochi,Kerala,IN,682019
About KPMG in IndiaKPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited....02 Aug -
Salesforce Technical Director / Salesforce Practice Head
- Veracity
- Bangalore,Karnataka,India
Leadership role in Salesforce Product Engineering Office location -Whitefield, Bangalore Hybrid work mode. Looking at 70% technical and 30% people...15 Aug -
Vulnerability Assessment and Penetration Testing (VAPT)
- ClifyX
- India
Request Information Request: Information Technology_IND - IND_Engineer Qty: 1 Candidate Submission Limit Per Supplier: 3 Candidate...31 Aug -
Practice Head -- Creatio Sales & No- Code
- VIRTUOS
- Gurugram, HR, IN
Job DescriptionROLE AT A GLANCE Category Category A — Sales & Pre-Sales Practice Creatio CRM / No-Code / AIVelocity | CX Practice Leadership Reports To...19 Aug