ISG-Lead-Red Team
- Bug Bounty
- AI
- OWASP
- Penetration Testing
- AppSec
- AI/ML
- NIST
- Threat Intelligence
Lead – Red Team (ISG)
Business Unit (PA): Information Security Group
Team: ISG
Reports to: Head – Red Team & Bug Bounty
Location: Airoli
Job Function: Red Team & Bug Bounty
Role Type: Supervisory
Direct Reports: 4–5
Travel: Moderate
Band: D2–D3
Version: 1.0
Â
Job Purpose
Build and lead the Bank’s AI Red Team and develop an agentic offensive‑security platform capable of simulating real attack scenarios on AI and traditional systems. Conduct adversarial campaigns, identify security vulnerabilities using latest TTPs, strengthen detection/defense posture, mentor team members, and collaborate closely with wider security units to uplift enterprise cyber resilience.
Â
Key Responsibilities
Red Team Operations & Governance
Build and lead the AI Red Team from scratch.
Establish AI security testing practice aligned to MITRE ATT&CK, MITRE ATLAS, OWASP, OSSTMM frameworks.
Develop autonomous agentic systems to execute adversarial attacks on AI and traditional tech ecosystems.
Plan attack campaign chains; guide team members through operations and program governance.
Track latest attacks; mentor juniors; conduct adversarial campaign simulations across AI + traditional systems.
Prepare deep‑dive technical reports and executive‑level presentations for senior stakeholders.
Qualifications & Experience
Graduate/Post‑Graduate in Engineering / IT / Cybersecurity or related fields.
18+ years hands‑on experience in Development, Offensive Security, Red Teaming, Pen‑Testing, AppSec, AI/ML Security.
Proven expertise designing/running adversarial attack simulations.
Experience with AI security, adversarial ML, LLM vulnerabilities, agentic AI architectures.
Should have led Red Team practice in mid‑to‑large organizations.
Key Skills
Penetration testing (web, network, mobile); strong manual + tool‑based exploitation capability.
Vulnerability assessment expertise; ability to identify latent weaknesses.
Knowledge of OWASP, NIST, MITRE ATT&CK best practices.
Threat‑intelligence analysis & tracking emerging TTPs.
Leadership & mentoring skills; team collaboration.
Strong analytical & problem‑solving mindset; creative adversarial thinking.
Ability to manage multiple Red Team engagements and stakeholder expectations.
Major Stakeholders
Internal Audit
BTG
IT Teams (IT TS & SD, BSG, IT Governance, etc.)
Relevant business units
ISG-Lead-Red Team · HDFC Bank