Skip to content

Security Consulting Manager – Infrastructure & Application Security

Talakunchi NetworksMumbai, MH, IndiaOctober 8, 2026
On-site
Full-time
Security Engineering
Management

Experience: 8+ Years

Employment Type: Full-Time

Location: Mumbai

Employment Type: Full-Time

Role Overview

We are seeking an experienced and results-driven Security Consulting Manager to lead and manage cybersecurity consulting engagements across Infrastructure Security and Application Security.

The role will be responsible for managing a team of security consultants, overseeing end-to-end security assessment projects, managing client relationships, and ensuring the successful delivery of security engagements within defined scope, timelines, SLAs, and quality standards.

The ideal candidate should have strong experience in Infrastructure VA/PT, Web Application Penetration Testing, API Security, Mobile Application Security, vulnerability management, client governance, and security project delivery. The candidate should also be capable of translating complex technical security findings into business risks and actionable recommendations for senior management and CISO-level stakeholders.

Key Responsibilities

1. Team Leadership & Management

  • Lead and manage a team of 15+ security consultants across Infrastructure Security and Application Security engagements.
  • Plan and allocate resources based on project requirements, skill sets, workload, and delivery timelines.
  • Provide technical and professional guidance to security consultants.
  • Mentor team members and ensure adherence to defined security methodologies, quality standards, and industry best practices.
  • Monitor team performance, utilization, productivity, and delivery commitments.

2. Security Project Management

  • Manage end-to-end security projects, including planning, resource allocation, scheduling, execution, reporting, remediation tracking, retesting, and closure.
  • Coordinate Infrastructure VA/PT, Web Application Penetration Testing, API Security Assessments, Mobile Application Penetration Testing, and other security assessment engagements.
  • Ensure projects are delivered within defined scope, timelines, SLAs, assessment calendars, and quality standards.
  • Monitor project deliverables, dependencies, risks, issues, resource utilization, and escalations.
  • Manage project-level change requests and ensure appropriate stakeholder communication.

3. Client & Stakeholder Management

  • Act as the primary point of contact for clients, application owners, infrastructure teams, project stakeholders, senior management, and CISOs.
  • Conduct regular governance and review meetings with clients and internal stakeholders.
  • Provide updates on project progress, security posture, critical vulnerabilities, remediation status, risks, and upcoming activities.
  • Build and maintain strong relationships with key client stakeholders.
  • Translate technical security findings into business-level risks and actionable recommendations for management.

4. Vulnerability Management

  • Manage the complete vulnerability lifecycle from identification and risk prioritization through remediation, validation, retesting, and closure.
  • Track critical and high-risk vulnerabilities and drive timely remediation with relevant technical and business teams.
  • Review and validate risk acceptance or deviation requests where vulnerabilities cannot be remediated due to technical, business, or operational constraints.
  • Monitor vulnerability ageing, remediation trends, closure rates, and overall security posture.

5. Quality & Security Assessment Review

  • Review security assessment reports for technical accuracy, risk classification, completeness, and quality.
  • Ensure findings are supported with appropriate evidence and actionable remediation recommendations.
  • Ensure security assessments follow defined methodologies, standards, and internal quality guidelines.
  • Support continuous improvement of assessment methodologies, reporting standards, and delivery processes.

6. Security Governance & Reporting

  • Maintain vulnerability dashboards and management MIS covering:
    • Open vulnerabilities
    • Critical and high-risk findings
    • Vulnerability ageing
    • Remediation status
    • Closure trends
    • Project performance
  • Prepare and present monthly and quarterly security reports, management dashboards, KRIs, project status reports, and executive presentations.
  • Conduct periodic governance reviews with stakeholders to assess security posture, project progress, risks, and remediation performance.

7. Risk, Issue & Escalation Management

  • Identify, assess, and manage project risks, issues, dependencies, and escalations.
  • Coordinate with technical and business teams to ensure timely resolution of critical security issues.
  • Escalate significant security risks and delivery concerns to senior management where required.
  • Ensure appropriate communication and visibility of project risks throughout the engagement lifecycle.

8. Continuous Improvement

  • Identify opportunities to improve security assessment processes, delivery methodologies, reporting, and client engagement.
  • Drive initiatives to improve operational efficiency, assessment quality, and resource utilization.
  • Encourage automation and standardization across security consulting activities.
  • Participate in post-engagement reviews and implement lessons learned across future projects.

Required Qualifications & Skills

  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 8+ years of experience in Cybersecurity, Security Consulting, VAPT, Application Security, Infrastructure Security, or a related domain.
  • Proven experience managing and leading cybersecurity teams.
  • Experience managing teams of 15+ security consultants is preferred.
  • Strong hands-on understanding of:
    • Infrastructure VA/PT
    • Web Application Penetration Testing
    • API Security Assessment
    • Mobile Application Security Testing
    • Vulnerability Management
    • Security Risk Management
  • Strong project management and stakeholder management skills.
  • Experience working directly with enterprise clients and senior stakeholders/CISOs.
  • Strong understanding of vulnerability risk ratings, remediation processes, retesting, and risk acceptance.
  • Excellent report review and presentation skills.
  • Strong analytical, communication, negotiation, and problem-solving abilities.

Preferred Certifications

One or more of the following certifications will be an advantage:

  • CISSP
  • CISM
  • OSCP
  • OSWE
  • CEH
  • CREST certifications
  • PMP / PRINCE2
  • Other relevant cybersecurity or project management certifications

Key Competencies

  • Strategic leadership
  • Team management and mentoring
  • Client relationship management
  • Security project management
  • Risk and vulnerability management
  • Stakeholder communication
  • Governance and reporting
  • Problem-solving and decision-making
  • Strong business and security acumen
  • Ability to manage multiple projects and priorities simultaneously

What We Offer

  • Opportunity to lead large-scale cybersecurity consulting engagements.
  • Exposure to enterprise clients and CISO-level stakeholders.
  • Leadership responsibility across Infrastructure and Application Security teams.
  • Opportunity to work across diverse security assessment programs and technologies.
  • Professional growth and leadership development opportunities.
  • Collaborative and security-focused work environment

Job Details

Experience

Management

Preferred Certs

CEH
CISM
CISSP
OSCP
OSWE