Security Engineer - Offensive Security (Red Team)
Axonect Kuala Lumpur, Kuala Lumpur, Malaysia
IT Services and IT Consulting · 1,001-5,000 employees
About the role
Plan and execute adversary simulation activities to identify and mitigate vulnerabilities while developing offensive tactics and procedures. Provide subject matter expertise to internal teams and develop tooling to support reconnaissance and automation.
What they look for
Requirements
Requires at least 3 years of experience in vulnerability assessments and a strong understanding of networking and OWASP vulnerabilities. Candidates must demonstrate proficiency in manual exploit development and possess excellent communication skills.
Full description
Overview
We are looking for smart, talented, and self-motivated cyber security professionals to join our fast-growing Security Operations team at Axiata. As a security engineer, you will be working with companies across Southeast Asia to solve security challenges at scale and speed. If you are passionate about all things cyber security and looking for an exciting every day, then this role is for you!
Key Responsibilities
- Plan, spearhead and execute sophisticated adversary simulation activities to enable the identification and mitigation of identified vulnerabilities
- Research, develop, and apply offensive tactics, techniques, and procedures (TTP´s) to effectively mimic the capabilities of relevant threat actors
- Provide subject matter expertise in offensive security for cyber defenders, remediation teams and enterprise technology teams
- Develop tooling to support reconnaissance, automation, and metrics collection
- Conduct full exploitation within multiple environments, including complex Active Directory and mixed Windows, *nix and MacOS environments
- Develop comprehensive, accurate reports targeting both technical and executive audiences
- Define and maintain a set of Standard Operating Procedures (SOP), Rules of Engagement (ROE), Methodologies and checklist for Red and Purple Team operations
- Excellent communication and presentation skills to communicate levels of risk as well as solutions to reduce risk most accurately and effectively in a prioritized manner
Person Specifications
- 3+ years of experience performing vulnerability assessments
- Excellent understanding of OWASP Top 10 vulnerabilities and it's mitigations
- Clear understanding of networking fundamentals: OSI layers, TCP/IP, protocols, etc
- Experience working on a GNU/Linux based penetration testing operating system and the command line (such as Kali Linux, Parrot, BlackArch, etc.)
- Experience with security testing tools and tradecraft. Must have an in depth understanding of common concepts relating to Command and Control (C2) frameworks and their development/customization/use
- Ability to modify known and/or craft custom exploits manually without dependence on consumer tools such as Metasploit
- Ability to modify known and/or craft custom exploits manually without dependence on consumer tools such as Metasploit
- Good spoken and written English skills
Nice To Have
- Security certifications: OSCP, OSCE, CRTP, GIAC certs or equivalent
- Working knowledge of Tenable security solutions
- Knowledge of Windows penetration testing: Active Directory, Azure AD
- CVE publications, knowledge of exploit development
- Talks/workshops organized at security conferences
- Excellent bug bounty track record
- Open-source contributions made to security tools, scripts & solutions
- Development background and code review capabilities
Similar roles
-
Cybersecurity Specialist
Berge Group Gothenburg, Nebraska, United States
-
Cloud Security Engineer F/H
Meilleurtaux Courbevoie, Ile-of-France, France
-
Consultant, Cybersecurity Consulting
Dell Technologies Taipei, Taiwan
-
Cybersecurity - Consultant.e junior
Wavestone Puteaux, Ile-of-France, France
-
Legal Manager – AI, Cybersecurity & Technology
Exein Rome, Lazio, Italy · €50K–€60K/yr
-
Cyber Security Engineer
NATO Mons, Wallonia, Belgium