Principal Security Operation Engineer (Red Team)

Bybit
Kuala Lumpur
Workplace: OnsiteFull timeFunction: Administration & Executive AssistanceExperience: 5+ yearsSkills: ["Document writing","Problem analysis","Learning ability","Teamwork ability","Stress resistance"]

Develop and execute red-team penetration testing and red-blue confrontation drills that simulate real attack scenarios across enterprise networks, applications, cloud environments, work endpoints, and core business systems. Lead threat research and attack surface analysis, including monitoring threat intelligence and modeling attack paths. Evaluate and test AI applications and large-model/agent systems (e.g., Prompt Injection, RAG risks), build security automation tools and platforms, and produce technical security reports and improvement recommendations.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Bybit
Bybit
4 days ago

Principal Security Operation Engineer (Red Team)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 23 hours agoStatus: Live

Job Summary

Develop and execute red-team penetration testing and red-blue confrontation drills that simulate real attack scenarios across enterprise networks, applications, cloud environments, work endpoints, and core business systems. Lead threat research and attack surface analysis, including monitoring threat intelligence and modeling attack paths. Evaluate and test AI applications and large-model/agent systems (e.g., Prompt Injection, RAG risks), build security automation tools and platforms, and produce technical security reports and improvement recommendations.
Location: Kuala Lumpur
Workplace: Onsite
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Develop and execute penetration testing and red-blue confrontation drills to simulate real attack scenarios and identify security risks across networks, applications, cloud environments, work networks, and core business systems.
  • •Lead or participate in red-blue confrontation exercises to evaluate defense capabilities in attack detection, alarm analysis, traceability, emergency response, and recovery.
  • •Analyze attack surfaces and research threats by identifying enterprise exposure across internet assets, cloud assets, APIs, supply chain components, and third-party access risks; provide mitigation recommendations.
  • •Conduct security evaluation and reporting for critical systems and AI applications, producing technical reports with attack paths, impact analysis, risk levels, and repair recommendations.
  • •Develop and optimize red team tools/scripts and automated security evaluation platforms, including vulnerability scanning, asset mapping, PoC verification, attack path analysis, and AI-driven automation/report generation.

Pay and Benefits

Perks:Learning Budget

Key Requirements

  • •More than 5 years of experience in red team, penetration testing, security research, or offensive and defensive security exercises.
  • •Proficient in common attack techniques and red team toolchains, such as Sliver, Cobalt Strike, NPS, Burp Suite, Metasploit, Nmap, Masscan, Frida, and Impacket.
  • •Proficient in penetration testing and red team processes, including information collection, vulnerability scanning/exploitation, intranet penetration, privilege escalation, and lateral movement.
  • •Proficient in one or more programming/scripting languages (e.g., Python, Go, Bash, PowerShell, JavaScript) with experience in tool development and automation platform construction.
  • •Able to perform security testing for AI applications and large models (e.g., Prompt Injection, Jailbreak, RAG poisoning) including designing test cases and evaluating inputs/outputs and permission boundaries.
Experience:5+ yearsRed teamPenetration testingSecurity researchAI securityLarge language models
Skills:Document writingProblem analysisLearning abilityTeamwork abilityStress resistance
Certifications:OSCECISSPCISPCEHCCSPSecurity certifications
Tech Stack:TCP/IPNetwork architectureIdentity authenticationAccess controlWindowsLinuxMacOSSliverCobalt StrikeNPSBurp SuiteMetasploitNmapMasscanFridaImpacketWeb frameworksAPIMicroservicesContainers

Company Brief

Bybit
Operates a cryptocurrency exchange and trading platform offering spot, derivatives, copy trading, and related digital asset services for retail and institutional users. The platform focuses on high-liquidity crypto markets, trading tools, and Web3-related products.
Industry: Trading Platforms
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Founded: 2018
WebsiteLinkedIn