Назад
Company hidden
2 мСсяца Π½Π°Π·Π°Π΄

Principal Security Operation Engineer (Red Team)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
Malaysia/China
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Principal Security Operation Engineer (Red Team) (Cybersecurity/AI Security): Conducting enterprise penetration testing, red-blue confrontation exercises, attack surface analysis, and security evaluations across networks, cloud environments, APIs, business systems, and AI applications with an accent on adversarial testing, threat research, and large language model security. Focus on designing attack chains, validating prompt injection and agent risks, developing automated red team tools, and converting findings into detection rules and security governance improvements.

Location: Hong Kong SAR or Kuala Lumpur, Malaysia

Company

hirify.global is a cryptocurrency exchange and digital financial platform providing trading, payments, wealth management, custody, institutional services, and Web3 products.

What you will do

  • Plan and execute penetration tests, red-blue confrontation exercises, and attack-and-defense drills across enterprise networks, applications, cloud environments, APIs, and core business systems.
  • Analyze attack surfaces, threat intelligence, vulnerabilities, APT methods, cloud assets, supply chains, and third-party access risks.
  • Evaluate AI applications, RAG systems, agents, model services, MCP services, plugins, and tool-calling workflows for prompt injection, data leakage, privilege, and isolation risks.
  • Develop red team tools, scripts, automated security evaluation platforms, vulnerability verification workflows, and AI-assisted penetration testing capabilities.
  • Produce technical security reports covering attack paths, impact analysis, AI risks, remediation recommendations, and governance requirements.
  • Collaborate with blue team, security operations, infrastructure, R&D, data, algorithm, and business teams on remediation, detection rules, emergency exercises, and secure design reviews.

Requirements

  • More than 5 years of experience in red teaming, penetration testing, security research, or offensive and defensive exercises.
  • Strong knowledge of TCP/IP, network architecture, authentication, access control, operating systems, web frameworks, APIs, microservices, containers, and Kubernetes security.
  • Proficiency with red team processes and tools including Sliver, Cobalt Strike, Burp Suite, Metasploit, Nmap, Masscan, Frida, and Impacket.
  • Experience with vulnerability analysis, PoC development, exploit verification, impact assessment, and security tool or automation platform development.
  • Knowledge of AI application architectures and security testing methods covering Prompt, RAG, embeddings, vector databases, agents, function calling, MCP, jailbreaks, poisoning, data leakage, and unauthorized tool invocation.
  • Ability to write high-quality technical reports, analyze attack chains, collaborate across teams, and research emerging attack surfaces and tools.

Nice to have

  • Experience with cloud attack and defense, AWS, Azure, GCP, Tencent Cloud, or Alibaba Cloud.
  • Knowledge of Kubernetes, containers, service mesh, CI/CD, DevSecOps, supply chain security, zero trust, threat hunting, and vulnerability management.
  • Experience with automated red teaming, AI penetration testing, agent orchestration, security knowledge bases, or security RAG systems.
  • Security certifications such as OSCP, OSCE, CISSP, CISP, CEH, or CCSP.
  • Experience with CVEs, vulnerability submissions, open-source security projects, technical publications, or frameworks such as MITRE ATT&CK, OWASP Top 10, OWASP LLM Top 10, or NIST AI RMF.

Culture & Benefits

  • Professional development support through a Study Growth Fund.
  • Internal team-building activities, workshops, and innovation events.
  • Collaboration with an international team across global operations.
  • Career advancement and internal mobility opportunities.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’