Skip to main content
Thoropass

Pentest Manager

RemoteLATAM
Published
Role
Security
Experience
Senior
Company size
Startup
Salary not disclosed
Check eligibility

Open to Anywhere in LATAM. Set where you work from to check your eligibility.

No BS summary

Penetration Testing Manager for LATAM with 5–8+ years in pentesting or red teaming and 1+ year managing people. Must be hands-on across web, API, mobile, network and AI/LLM/MCP testing, hold at least one listed security certification, script in Bash/Python or similar, and be fluent in English.

Core skills

Burp Suite ProPenetration TestingLLM Security Testing

Required skills

LLMMCPOSCP/OSCE/OSWE/PWPT/Burp Suite Certified PractitionerClaude CodeCodexsqlmapBash/Python

Optional skills

AWSHack the BoxPortswigger Academy

Required languages

English Fluent; exceptional verbal & written communication

What you'll do

  • Lead and manage a Pentest team of 4–5 pentesters, providing technical guidance, feedback, and professional development support.
  • Ensure all assigned engagements are delivered on time, within scope, and aligned with Thoropass standards.
  • Conduct 1:1s, coaching sessions, and technical reviews to maintain motivation, quality, and team engagement.
  • Collaborate with other Pentest Managers to balance workloads, share best practices, and standardize delivery processes.
  • Partner with leadership to continuously improve internal operations, delivery frameworks, and team morale.
  • Conduct web, network, API, LLM and MCP penetration tests using black box, gray box or white box methods, combining manual testing with both traditional automation and AI assisted tooling to increase coverage and speed without losing depth.
  • Identify and exploit vulnerabilities to build realistic attack paths and show clear business impact, including AI specific risks such as prompt injection, insecure model outputs, data leakage, unsafe tool and function calling, and abuse of agentic or MCP based workflows.
  • Produce detailed, customer facing reports with practical remediation guidance written in clear and professional English, and use AI to draft and refine content faster while keeping a human in the loop to verify every finding, rating and recommendation.
  • Stay current with modern attack techniques and tools, including offensive and defensive uses of AI, so your work and your team's work remain technically strong as both the threat landscape and the technology keep changing.
  • Help scale the pentest program through improved workflows, templates, and automation.
  • Lead internal knowledge-sharing sessions and encourage a culture of continuous learning.
  • Collaborate cross-functionally with Customer Success, Sales, and Operations to ensure seamless customer delivery.
  • Support hiring, onboarding, and training as the pentest function expands.

What they require

  • You have experience leading technical teams and understand how to motivate, mentor, and empower others.
  • You are hands-on and comfortable switching between performing pentests and managing people.
  • You thrive in fast-paced environments where structure and processes are actively evolving.
  • You set high standards for quality, lead by example, and bring a collaborative mindset to team leadership.
  • 5–8+ years in pentesting or red teaming, including 1+ year of people management experience.
  • Prior experience mentoring or managing security professionals.
  • Strong technical expertise in web application, API, mobile and network penetration testing, plus a working understanding of how to test AI powered systems such as LLM applications, agents and MCP based integrations.
  • At least 1 of the following certifications: OSCP, OSCE, OSWE, PWPT, Burp Suite Certified Practitioner.
  • Knowledge of current attack methods, manual penetration testing techniques and popular hacking tools (for example Claude Code, Codex, Burp Suite Pro, sqlmap), including how to use AI tools to speed up testing while keeping full control over the results.
  • Proficient scripting skills in bash, Python or similar languages, with the ability to use AI coding assistants to build and adapt tooling quickly.
  • Fluency in English, with exceptional verbal & written communication.
  • You’re able to convey complex, technical topics to an array of stakeholders in a digestible and compelling manner.
  • Strong sense of operational ownership, able to balance delivery speed, quality and customer satisfaction, and to judge when AI can help and when human expertise has to lead.
  • Preferred: Contributions to the security community, such as conference talks, blog posts, open-source projects, or CVE discoveries.
  • Preferred: Knowledge of compliance frameworks that often require pentesting (e.g., SOC 2, ISO 27001, PCI DSS, HIPAA).
  • Preferred: Experience working with cross-functional teams (Sales, Customer Success, Engineering) to scope, plan, or deliver pentests.
  • Preferred: Participation in bug bounty programs or vulnerability research initiatives.
  • Preferred: Experience with AI/LLM security testing and cloud environments such as AWS is a plus.
  • Preferred: Experience with Hack the Box, Portswigger Academy, or similar learning platforms.

Benefits

  • Competitive base salary
  • Exceptional private healthcare
  • Early equity in a fast-growing company
  • Work-from-home model
  • Flexible PTO
  • Home office equipment
  • Monthly wellness and home Wi-Fi stipend

Thoropass pairs compliance automation software with expert guidance and continuous monitoring to help companies prepare for and stay compliant with audits.

🇺🇸 United StatesComplianceStartup
Salary not disclosed