Senior Red Team Operator (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Red Team Operator (Cybersecurity): Planning and executing red team assessments, attack simulations, and adversary emulation exercises to identify exposures in critical information systems with an accent on penetration testing, exploit development, social engineering, and cloud command-and-control environments. Focus on developing custom offensive tooling, evading security controls, mentoring operators, and testing detection capabilities through Red and Purple Team exercises.
Location: Taguig City, National Capital Region (Manila), Philippines
Company
provides financial security and health-related services to clients, families, and communities worldwide.
What you will do
- Plan, execute, and report on red team assessments, attack simulations, and adversary emulation exercises.
- Conduct network, web, and mobile application penetration testing, source code reviews, threat analysis, and social engineering assessments.
- Develop scripts, tools, programs, and operational pipelines for offensive security activities.
- Manage and improve an OPSEC-focused cloud command-and-control environment across AWS, Azure, GCP, and DigitalOcean.
- Develop security-control evasion and bypass capabilities while researching emerging threats and red team frameworks.
- Collaborate on Red and Purple Team exercises and contribute to recurring security vulnerability reports.
Requirements
- 5–7 years of experience in offensive security or penetration testing.
- University degree in computer science, computer engineering, or computer security.
- Strong programming and automation experience with languages such as C, C++, Assembly, C#, JavaScript, PowerShell, Rust, or Nim.
- At least 2 years of mentoring junior and mid-level red team operators.
- At least 4 years of delivering technical red team reports and briefings.
- Strong knowledge of operating systems, network protocols, application configuration, information security concepts, and technical communication.
Nice to have
- Experience leading grey- or black-hat engagements from start to finish.
- Reverse engineering, x86 internals, Active Directory exploitation, OSINT, and social engineering expertise.
- Experience with Cobalt Strike, EDR evasion, malware techniques, custom tooling, and pipeline development.
- Knowledge of AWS, Azure, DigitalOcean, IaaS, SDN, Windows, Linux, UNIX, and macOS internals.
- Industry certifications such as OSCP, SANS, CEH, CISSP, or CPTS.
Culture & Benefits
- Work with cybersecurity professionals and cross-functional business stakeholders.
- Access to an environment focused on professional growth, knowledge sharing, and meaningful client impact.
- Contribute to information security initiatives supporting confidential data protection and operational stability.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →