Lead Offensive Security & Red Team
IDEMIA Secure Transactions, a division of IDEMIA Group, is the leading technology provider making it safer and easier to pay and connect. With unmatched expertise in cryptography and credential issuance, IST is trusted by over 2,000 financial institutions, mobile operators, automotive manufacturers, and IoT providers worldwide. Every day, IST secures billions of essential transactions, ensuring the highest levels of data protection and convenience.
Purpose
The Head of Offensive Security & Red Team leads the Company’s offensive security capabilities, including red teaming, penetration testing, adversary simulation, attack-path analysis, and continuous security validation across cloud, identity, applications, networks, data centers, and critical production environments.
This is a hands-on player-coach role combining technical leadership, capability building, and provider management. The role drives a threat-informed and proactive testing approach, translates offensive findings into measurable defensive improvements, and develops AI-enabled and agentic offensive security capabilities to increase testing speed, coverage, and depth while maintaining strong human oversight, safety, and governance.
The role reports to the VP IT Cybersecurity / CISO.
Key Missions
- Define and execute the Company’s offensive security strategy, annual testing plan, operating model, and capability roadmap.
- Lead red-team campaigns, adversary emulation, penetration testing, attack-path analysis, and security-control validation across cloud, on-premises, identity, applications, networks, data centers, and production environments.
- Prioritize offensive security activities based on business criticality, exposure, threat intelligence, technology changes, incidents, regulatory requirements, and emerging AI-enabled threats.
- Develop a continuous and automated testing model to complement periodic assessments and enable faster validation of vulnerabilities, attack paths, and defensive controls.
- Build and operationalize AI-assisted and agentic Red Team capabilities for reconnaissance, attack-hypothesis generation, attack-path discovery, adversary simulation, testing automation, controlled exploit validation, campaign orchestration, analysis, and reporting.
- Evaluate emerging AI-enabled offensive security technologies and determine where they can safely improve testing coverage, efficiency, and quality.
- Lead Purple Team activities with the Cybersecurity Defense Center and ensure offensive findings translate into improved detections, investigation procedures, SOC playbooks, vulnerability prioritization, architecture improvements, and stronger defensive controls.
- Define and maintain rules of engagement, authorization, safety controls, confidentiality requirements, escalation paths, and production safeguards for offensive activities.
- Translate technical findings into clear business risks and drive material findings through remediation, retesting, risk treatment, or escalation.
- Manage and optimize the use of external penetration-testing and Red Team providers, progressively internalizing and automating repeatable activities to improve responsiveness, quality, and cost efficiency.
- Build and maintain the offensive security toolchain, laboratories, controlled testing environments, and automation capabilities.
- Support critical projects, cloud transformations, new production environments, and major technology changes through targeted offensive security validation.
- Support major cyber incidents when required through attack reconstruction, compromise-path analysis, exposure validation, and lessons learned.
- Develop the technical capability and autonomy of the Offensive Security team through coaching, knowledge sharing, and practical technical exercises.
- Produce meaningful KPIs/KRIs covering testing coverage, findings, remediation, Purple Team outcomes, provider performance, control improvements, and business value.
Profile & Other Information
Experience & technical skills
- 6–10 years of relevant cybersecurity experience, including substantial hands-on experience in offensive security, red teaming, penetration testing, adversary simulation, or security research.
- Ability to independently scope, design, and execute complex offensive-security engagements from attack hypothesis and rules of engagement through execution, reporting, remediation, and retesting.
- Strong technical depth in at least two areas such as Active Directory / Entra ID, cloud platforms, applications and APIs, endpoint and network infrastructure, containers, or Kubernetes.
- Practical knowledge of MITRE ATT&CK, attack-path analysis, privilege escalation, lateral movement, persistence, command-and-control concepts, operational security, and detection-aware testing.
- Ability to develop, adapt, and automate offensive-security capabilities using Python and at least one additional language or scripting environment such as PowerShell, Bash, Go, C#, Rust, or equivalent.
- Experience with adversary-emulation tooling, offensive-security infrastructure, controlled laboratories, and testing automation.
- Demonstrated interest or experience in AI-assisted security testing, LLMs, tool-using agents, agentic workflows, or automated security research.
- Ability to translate technical findings into business-relevant risk and communicate effectively with technical teams, operational stakeholders, and senior management.
- Strong understanding of safe-testing practices, rules of engagement, confidentiality, evidence handling, production safeguards, and escalation.
Leadership profile
- Strong player-coach mindset: able to lead complex technical engagements while remaining directly involved when needed.
- Autonomous, pragmatic, curious, and comfortable challenging traditional approaches.
- Able to mentor practitioners, coordinate specialist providers, and build new capabilities in a fast-evolving threat environment.
- Strong learning agility and interest in how AI and automation are reshaping offensive security.
Preferred
- Experience in cloud-native, identity-centric, payment, telecom, data-center, or other business-critical environments.
- Experience testing AI-enabled applications, RAG systems, LLMs, or autonomous agents.
- Evidence of continuous technical learning through research, open-source contributions, CTFs, bug bounty, CVEs, publications, or security-community involvement.Certifications such as OSCP, OSEP, OSCE3, CRTO, CRTE, GXPN, GPEN, or equivalent are valued but not mandatory.
Join Us!
Ready to make a move? Hit Apply and share your CV with us.
At IST, we believe in an inclusive environment where every talent can thrive. We welcome applicants from all backgrounds, identities, and abilities. If you require any accommodation during the process, let us know.
Join us to shape a career as unique as you are, where every day brings a new challenge and a new opportunity to learn.