Назад
Company hidden
18 часов назад

Principal Security Operation Engineer (AI Security)

Формат работы
remote (только APAC)
Тип работы
fulltime
Грейд
senior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Operation Engineer (AI Security): Building and executing enterprise red-team exercises, attack-surface assessments, and AI application security evaluations with an accent on penetration testing, threat research, and large-language-model attack and defense. Focus on designing attack chains, validating prompt-injection and agent risks, developing security automation, and converting findings into detection and governance improvements.

Location: Remote in APAC; Kuala Lumpur, Malaysia

Company

hirify.global is a cryptocurrency exchange and digital financial platform serving users across more than 200 countries and regions, with products spanning trading, payments, wealth management, custody, institutional services, and Web3.

What you will do

  • Develop and execute penetration tests, red-blue confrontation exercises, and practical attack-and-defense drills across enterprise networks, applications, cloud environments, and core business systems.
  • Design realistic attack chains covering external exploitation, phishing, privilege escalation, lateral movement, data discovery, persistence, and defense bypass.
  • Analyze attack surfaces, internet and cloud assets, APIs, supply-chain components, third-party access, vulnerabilities, and threat intelligence.
  • Evaluate AI applications, RAG systems, agents, model services, tool calls, MCP services, and related data and permission boundaries.
  • Build red-team tools, scripts, automated security evaluation platforms, vulnerability verification workflows, and AI-assisted penetration-testing capabilities.
  • Produce technical security reports and collaborate with blue teams, infrastructure, R&D, algorithm, data, and business teams to improve detection, response, WAF, EDR, SIEM, NDR, HIDS, zero-trust, identity, and logging capabilities.

Requirements

  • More than 5 years of experience in red teaming, penetration testing, security research, or offensive and defensive exercises.
  • Strong knowledge of TCP/IP, network architecture, identity and access control, operating-system security, web and API architectures, microservices, containers, and Kubernetes security.
  • Experience with penetration-testing processes, vulnerability exploitation, intranet penetration, privilege escalation, lateral movement, persistence, trace cleaning, vulnerability analysis, and PoC development.
  • Proficiency with red-team tools such as Sliver, Cobalt Strike, Burp Suite, Metasploit, Nmap, Masscan, Frida, and Impacket.
  • Proficiency in at least one programming or scripting language, including Python, Go, Bash, PowerShell, or JavaScript, with experience developing security tools and automation platforms.
  • Knowledge of LLM, Prompt, RAG, Embedding, vector database, Agent, Function Calling, MCP, prompt-injection, jailbreak, data-poisoning, unauthorized-tool-invocation, and AI security governance concepts.

Nice to have

  • Experience with enterprise attack-and-defense drills, cloud attack and defense, intranet penetration, AI security, automated red-team platforms, or security-tool platform construction.
  • Knowledge of AWS, Azure, GCP, Tencent Cloud, Alibaba Cloud, Kubernetes, Service Mesh, CI/CD, DevSecOps, and supply-chain security.
  • Experience with zero trust, threat hunting, attack-surface management, vulnerability management, CVEs, security research, or open-source security projects.
  • Familiarity with MITRE ATT&CK, OWASP Top 10, OWASP LLM Top 10, and NIST AI RMF.
  • Security certifications such as OSCP, OSCE, CISSP, CISP, CEH, or CCSP.

Culture & Benefits

  • Professional development support through a Study Growth Fund.
  • Regular team-building activities, workshops, and internal events.
  • Collaboration with an international team across multiple regions.
  • Career advancement opportunities and internal mobility.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →