14 часов назад
Principal Security Operation Engineer (Red Team)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Operation Engineer (Red Team) (Cybersecurity/AI Security): Conducting enterprise penetration testing, red-blue confrontation exercises, attack surface analysis, and security evaluations across networks, cloud environments, APIs, business systems, and AI applications with an accent on adversarial testing, threat research, and large language model security. Focus on designing attack chains, validating prompt injection and agent risks, developing automated red team tools, and converting findings into detection rules and security governance improvements.
Location: Hong Kong SAR or Kuala Lumpur, Malaysia
Company
is a cryptocurrency exchange and digital financial platform providing trading, payments, wealth management, custody, institutional services, and Web3 products.
What you will do
- Plan and execute penetration tests, red-blue confrontation exercises, and attack-and-defense drills across enterprise networks, applications, cloud environments, APIs, and core business systems.
- Analyze attack surfaces, threat intelligence, vulnerabilities, APT methods, cloud assets, supply chains, and third-party access risks.
- Evaluate AI applications, RAG systems, agents, model services, MCP services, plugins, and tool-calling workflows for prompt injection, data leakage, privilege, and isolation risks.
- Develop red team tools, scripts, automated security evaluation platforms, vulnerability verification workflows, and AI-assisted penetration testing capabilities.
- Produce technical security reports covering attack paths, impact analysis, AI risks, remediation recommendations, and governance requirements.
- Collaborate with blue team, security operations, infrastructure, R&D, data, algorithm, and business teams on remediation, detection rules, emergency exercises, and secure design reviews.
Requirements
- More than 5 years of experience in red teaming, penetration testing, security research, or offensive and defensive exercises.
- Strong knowledge of TCP/IP, network architecture, authentication, access control, operating systems, web frameworks, APIs, microservices, containers, and Kubernetes security.
- Proficiency with red team processes and tools including Sliver, Cobalt Strike, Burp Suite, Metasploit, Nmap, Masscan, Frida, and Impacket.
- Experience with vulnerability analysis, PoC development, exploit verification, impact assessment, and security tool or automation platform development.
- Knowledge of AI application architectures and security testing methods covering Prompt, RAG, embeddings, vector databases, agents, function calling, MCP, jailbreaks, poisoning, data leakage, and unauthorized tool invocation.
- Ability to write high-quality technical reports, analyze attack chains, collaborate across teams, and research emerging attack surfaces and tools.
Nice to have
- Experience with cloud attack and defense, AWS, Azure, GCP, Tencent Cloud, or Alibaba Cloud.
- Knowledge of Kubernetes, containers, service mesh, CI/CD, DevSecOps, supply chain security, zero trust, threat hunting, and vulnerability management.
- Experience with automated red teaming, AI penetration testing, agent orchestration, security knowledge bases, or security RAG systems.
- Security certifications such as OSCP, OSCE, CISSP, CISP, CEH, or CCSP.
- Experience with CVEs, vulnerability submissions, open-source security projects, technical publications, or frameworks such as MITRE ATT&CK, OWASP Top 10, OWASP LLM Top 10, or NIST AI RMF.
Culture & Benefits
- Professional development support through a Study Growth Fund.
- Internal team-building activities, workshops, and innovation events.
- Collaboration with an international team across global operations.
- Career advancement and internal mobility opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
8 часов назад
Red Team - Sr Security Engineer (Cybersecurity)
21 час назад
Offensive Security Engineer/Lead (Cybersecurity)
7 часов назад
Cyber Red Team Operator (Cybersecurity)
110 000 - 160 000$
1 день назад
Offensive Security Engineer (Fintech)
1 день назад
Senior Information Security Engineer
1 день назад