обновлено 20 дней назад
Senior Red Team Operator (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Red Team Operator (Cybersecurity): Planning and executing red team assessments, attack simulations, adversary emulation, and penetration testing across critical information systems with an accent on offensive security, cloud-based command-and-control environments, and security control evasion. Focus on developing custom tools, testing detection capabilities through Purple Team exercises, mentoring operators, and producing technical security reports.
Location: Taguig City, National Capital Region (Manila), Philippines
Company
provides financial security and health-related services to clients, families, and communities worldwide.
What you will do
- Plan, execute, and report on Red Team assessments, attack simulations, and adversary emulation exercises.
- Conduct network, web, and mobile application penetration testing, source code reviews, threat analysis, and social engineering assessments.
- Develop scripts, tools, programs, and security control evasion capabilities for Red Team operations.
- Manage and improve an OPSEC-focused cloud command-and-control environment across AWS, Azure, GCP, and DigitalOcean.
- Develop detection-testing methods through Purple Team and Red Team exercises in collaboration with other business functions.
- Research emerging threats and contribute to recurring security vulnerability reports.
Requirements
- 5–7 years of experience in offensive security or penetration testing.
- University degree in computer science, computer engineering, or computer security.
- Strong programming and automation experience with languages such as C, C++, Assembly, C#, JavaScript, PowerShell, Rust, or Nim.
- At least 2 years of mentoring junior and mid-level Red Team operators.
- At least 4 years of producing technical Red Team reports and briefings.
- Strong knowledge of operating systems, network protocols, application configuration, problem-solving, communication, and presentation.
Nice to have
- OSCP, SANS, CEH, CISSP, or CPTS certification.
- Experience leading grey-hat or black-hat engagements from start to finish.
- Reverse engineering, including x86, Active Directory exploitation, OSINT, social engineering, and MITRE framework experience.
- Experience with Cobalt Strike, EDR evasion, malware techniques, custom tooling, pipeline development, and cloud environments.
- Knowledge of Ruby, Python, PHP, Java, C, C++, Assembly, and Windows, Linux, UNIX, or OSX internals.
Culture & Benefits
- Work with experienced colleagues and leaders who support professional growth.
- Contribute to protecting confidential information and maintaining operational stability against cyberattacks.
- Work in an environment focused on meaningful impact for clients, families, and communities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →