Назад
Company hidden
14 часов назад

Principal Security Operation Engineer (Red Team)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Malaysia/China
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Operation Engineer (Red Team) (Cybersecurity/AI Security): Conducting enterprise penetration testing, red-blue confrontation exercises, attack surface analysis, and security evaluations across networks, cloud environments, APIs, business systems, and AI applications with an accent on adversarial testing, threat research, and large language model security. Focus on designing attack chains, validating prompt injection and agent risks, developing automated red team tools, and converting findings into detection rules and security governance improvements.

Location: Hong Kong SAR or Kuala Lumpur, Malaysia

Company

hirify.global is a cryptocurrency exchange and digital financial platform providing trading, payments, wealth management, custody, institutional services, and Web3 products.

What you will do

  • Plan and execute penetration tests, red-blue confrontation exercises, and attack-and-defense drills across enterprise networks, applications, cloud environments, APIs, and core business systems.
  • Analyze attack surfaces, threat intelligence, vulnerabilities, APT methods, cloud assets, supply chains, and third-party access risks.
  • Evaluate AI applications, RAG systems, agents, model services, MCP services, plugins, and tool-calling workflows for prompt injection, data leakage, privilege, and isolation risks.
  • Develop red team tools, scripts, automated security evaluation platforms, vulnerability verification workflows, and AI-assisted penetration testing capabilities.
  • Produce technical security reports covering attack paths, impact analysis, AI risks, remediation recommendations, and governance requirements.
  • Collaborate with blue team, security operations, infrastructure, R&D, data, algorithm, and business teams on remediation, detection rules, emergency exercises, and secure design reviews.

Requirements

  • More than 5 years of experience in red teaming, penetration testing, security research, or offensive and defensive exercises.
  • Strong knowledge of TCP/IP, network architecture, authentication, access control, operating systems, web frameworks, APIs, microservices, containers, and Kubernetes security.
  • Proficiency with red team processes and tools including Sliver, Cobalt Strike, Burp Suite, Metasploit, Nmap, Masscan, Frida, and Impacket.
  • Experience with vulnerability analysis, PoC development, exploit verification, impact assessment, and security tool or automation platform development.
  • Knowledge of AI application architectures and security testing methods covering Prompt, RAG, embeddings, vector databases, agents, function calling, MCP, jailbreaks, poisoning, data leakage, and unauthorized tool invocation.
  • Ability to write high-quality technical reports, analyze attack chains, collaborate across teams, and research emerging attack surfaces and tools.

Nice to have

  • Experience with cloud attack and defense, AWS, Azure, GCP, Tencent Cloud, or Alibaba Cloud.
  • Knowledge of Kubernetes, containers, service mesh, CI/CD, DevSecOps, supply chain security, zero trust, threat hunting, and vulnerability management.
  • Experience with automated red teaming, AI penetration testing, agent orchestration, security knowledge bases, or security RAG systems.
  • Security certifications such as OSCP, OSCE, CISSP, CISP, CEH, or CCSP.
  • Experience with CVEs, vulnerability submissions, open-source security projects, technical publications, or frameworks such as MITRE ATT&CK, OWASP Top 10, OWASP LLM Top 10, or NIST AI RMF.

Culture & Benefits

  • Professional development support through a Study Growth Fund.
  • Internal team-building activities, workshops, and innovation events.
  • Collaboration with an international team across global operations.
  • Career advancement and internal mobility opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →