Senior Manager – Secure Software Development Lifecycle (SSDLC)

Enphase Energy · Bengaluru

  • Experience10+ yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelmanager
  • Posted19 Sept 2026

About Enphase Energy

Enphase Energy is hiring in Bengaluru in energy utilities. This role looks for around 10+ years of experience.

The role

A manager-level Cloud Security Test Manager role at a solar, battery, and electric vehicle charging technology company. You lead offensive application and cloud security testing across Enphase’s cloud platform, including SAST, DAST, SCA, secrets scanning, penetration testing, threat modeling (STRIDE/PASTA), and red-team/purple-team exercises mapped to MITRE ATT&CK, while managing vulnerability lifecycle end to end. Skills include Jenkins, GitLab, GitHub Actions, OWASP Top 10, API Top 10, STRIDE, PASTA, MITRE ATT&CK, AWS, GCP, Azure, Kubernetes, RBAC, IAM, CVE disclosure, and scripting with Python and Bash. Location is Bengaluru, Karnataka, India with onsite work 3 days per week (transitioning toward full 5 days in office).

Full job description

Description

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries.

Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.

About the role:

As the Cloud Security Test Manager, you will lead the offensive security function protecting Enphase’s cloud platform, including Enlighten, Enphase App, and device APIs that connect over 4M homes globally.

In this role, you will build and lead the security testing program across SAST, DAST, penetration testing, threat modeling, and red-team operations. You will manage a team of testers while staying hands-on to guide exploitation strategies and validate findings, partnering closely with the CISO’s office to manage the vulnerability lifecycle end to end.

What you will be doing:

Build and lead the application and cloud security testing roadmap and teamIntegrate SAST, DAST, SCA, and secrets scanning into CI/CD pipelines (Jenkins, GitLab, GitHub Actions); tune rules, triage results, and manage false positives to drive shift-left adoptionConduct and oversee manual penetration testing of web apps, REST/GraphQL APIs, microservices, and cloud platforms against OWASP Top 10 and API Top 10Plan and run red-team and purple-team exercises mapped to MITRE ATT&CK — initial access, exploitation, post-exploitation, lateral movement, and detection validation with the SOCLead threat modeling (STRIDE/PASTA) for new services and architecture reviews, defining attack surfaces, trust boundaries, and security requirementsOwn end-to-end vulnerability lifecycle management — risk-based prioritization, remediation tracking, SLAs, and metrics — from identification through verified closureCollaborate closely with the CISO’s office to report risks, KPIs, and remediation SLAsDefine and enforce security standards and best practices across cloud environmentsPerform container, Kubernetes, and cloud-native security testing across multi-cloud (AWS/GCP/Azure) environmentsDevelop custom exploits, payloads, and automation to validate exploitability and reduce false positives

What you bring:

BE/BTech/MS/MTech in Computer Science, Electrical Engineering, or a related field.A minimum of 10+ years of experience in application/cloud security testing, with5+ years leading security or red-team functionsStrong experience with SAST, DAST, and SCA tooling, CI/CD integration, rule tuning, and triage at scaleHands-on manual penetration testing of web apps, APIs, microservices, and cloud environments, with exploit/PoC developmentExpertise in threat modeling frameworks (STRIDE, PASTA) and attack surface analysisStrong experience in red-team operations, adversary emulation (MITRE ATT&CK), C2 frameworks, and purple-team collaborationDeep understanding of cloud security across AWS/GCP/Azure — IAM and identity, network controls, container/Kubernetes (RBAC, escapes), serverless, and secrets managementKnowledge of OWASP Top 10 / API Top 10 and CVE disclosure processesFamiliarity with security standards such as IEC 62443, EU Cyber Resilience Act, SOC 2, ISO 27001Excellent leadership, communication, and stakeholder management skillsProficiency in scripting (Python, Bash) for security automation and custom tooling

Nice to have:

Experience in exploit development and custom security toolingUnderstanding of IoT to cloud security and trust boundariesExperience building DevSecOps culture and secure SDLC practicesRelevant certifications such as OSCP, OSCE, GWAPT, or CCSP

What we offer:

Competitive compensation and comprehensive employee benefitsOpportunity to lead security for large-scale global cloud platformsExposure to cutting-edge cybersecurity and cloud technologiesCollaborative and innovation-driven work environmentCareer growth and leadership opportunities

#ITSecurity