18 часов назад
Principal Security Operation Engineer (AI Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Operation Engineer (AI Security): Building and executing enterprise red-team exercises, attack-surface assessments, and AI application security evaluations with an accent on penetration testing, threat research, and large-language-model attack and defense. Focus on designing attack chains, validating prompt-injection and agent risks, developing security automation, and converting findings into detection and governance improvements.
Location: Remote in APAC; Kuala Lumpur, Malaysia
Company
is a cryptocurrency exchange and digital financial platform serving users across more than 200 countries and regions, with products spanning trading, payments, wealth management, custody, institutional services, and Web3.
What you will do
- Develop and execute penetration tests, red-blue confrontation exercises, and practical attack-and-defense drills across enterprise networks, applications, cloud environments, and core business systems.
- Design realistic attack chains covering external exploitation, phishing, privilege escalation, lateral movement, data discovery, persistence, and defense bypass.
- Analyze attack surfaces, internet and cloud assets, APIs, supply-chain components, third-party access, vulnerabilities, and threat intelligence.
- Evaluate AI applications, RAG systems, agents, model services, tool calls, MCP services, and related data and permission boundaries.
- Build red-team tools, scripts, automated security evaluation platforms, vulnerability verification workflows, and AI-assisted penetration-testing capabilities.
- Produce technical security reports and collaborate with blue teams, infrastructure, R&D, algorithm, data, and business teams to improve detection, response, WAF, EDR, SIEM, NDR, HIDS, zero-trust, identity, and logging capabilities.
Requirements
- More than 5 years of experience in red teaming, penetration testing, security research, or offensive and defensive exercises.
- Strong knowledge of TCP/IP, network architecture, identity and access control, operating-system security, web and API architectures, microservices, containers, and Kubernetes security.
- Experience with penetration-testing processes, vulnerability exploitation, intranet penetration, privilege escalation, lateral movement, persistence, trace cleaning, vulnerability analysis, and PoC development.
- Proficiency with red-team tools such as Sliver, Cobalt Strike, Burp Suite, Metasploit, Nmap, Masscan, Frida, and Impacket.
- Proficiency in at least one programming or scripting language, including Python, Go, Bash, PowerShell, or JavaScript, with experience developing security tools and automation platforms.
- Knowledge of LLM, Prompt, RAG, Embedding, vector database, Agent, Function Calling, MCP, prompt-injection, jailbreak, data-poisoning, unauthorized-tool-invocation, and AI security governance concepts.
Nice to have
- Experience with enterprise attack-and-defense drills, cloud attack and defense, intranet penetration, AI security, automated red-team platforms, or security-tool platform construction.
- Knowledge of AWS, Azure, GCP, Tencent Cloud, Alibaba Cloud, Kubernetes, Service Mesh, CI/CD, DevSecOps, and supply-chain security.
- Experience with zero trust, threat hunting, attack-surface management, vulnerability management, CVEs, security research, or open-source security projects.
- Familiarity with MITRE ATT&CK, OWASP Top 10, OWASP LLM Top 10, and NIST AI RMF.
- Security certifications such as OSCP, OSCE, CISSP, CISP, CEH, or CCSP.
Culture & Benefits
- Professional development support through a Study Growth Fund.
- Regular team-building activities, workshops, and internal events.
- Collaboration with an international team across multiple regions.
- Career advancement opportunities and internal mobility.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Principal Security Engineer (AI Cybersecurity)
1 день назад
Principal Security Engineer (Blockchain, Cloud & AI)
110 000 - 170 000€
2 дня назад
Senior Security Engineer (AI)
7 дней назад
Senior Application Security Engineer, AI and Machine Learning
180 000 - 220 000$
2 дня назад
Application Security Engineer (AI)
1 день назад