jobs in Shopee

Shopee Hiring! Full Time Offensive Security Expert Engineer (Red Team) in - Ricebowl

Offensive Security Expert Engineer (Red Team)

Shopee

Undisclosed

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

Department Engineering and Technology
LevelExperienced (Individual Contributor)
LocationSingapore

The Engineering and Technology team is at the core of the Shopee platform development. The team is made up of a group of passionate engineers from all over the world, striving to build the best systems with the most suitable technologies. Our engineers do not merely solve problems at hand; We build foundations for a long-lasting future. We don't limit ourselves on what we can or can't do; we take matters into our own hands even if it means drilling down to the bottom layer of the computing platform. Shopee's hyper-growing business scale has transformed most "innocent" problems into huge technical challenges, and there is no better place to experience it first-hand if you love technologies as much as we do.

About the Team:
The Red Team within Information Security simulates real-world adversaries to proactively uncover vulnerabilities across Sea Group's infrastructure, applications, and people, including Shopee, SeaMoney (Monee), and Digibank. We conduct end-to-end offensive operations from external compromise and social engineering through to internal lateral movement. We collaborate closely with defensive teams to translate findings into stronger detections and hardening measures. Through continuous research, custom tooling development, and methodology refinement, we drive the maturity of Sea Group's overall security posture.
Job Description:
  • Conduct offensive security research: independently perform vulnerability discovery and exploit development, build and adapt post-exploitation tooling and red team infrastructure, and continuously grow a reusable capability and tooling arsenal.
  • Drive purple team collaboration: map attack paths and findings to MITRE ATT&CK, produce high-quality technical reports, work with the defensive team to translate TTPs into detection rules and hardening measures, and validate improvements through retesting.
  • Contribute to red team methodology and program maturity: codify standardized attack workflows, automation, and a TTP library to improve the team's overall operational efficiency and repeatability.
Requirements:
  • Bachelor's Degree in Computer Science or related field.
  • At least 5 years of security engineering experience
  • End-to-end penetration testing. Able to independently handle external compromise (perimeter asset discovery, web/service exploitation, initial access) and perform lateral movement and privilege escalation across internal networks, reliably reaching target assets in live engagements.
  • Multi-platform vulnerability research. Deep expertise in at least 2 of the following: operating systems, cloud native (containers / Kubernetes), IoT, and mobile (Android / iOS). Able to independently drive vulnerability discovery, root-cause analysis, and reliable exploit development — not merely run existing tools.
  • Hands-on social engineering & phishing. Able to independently design and execute social engineering campaigns, including phishing infrastructure setup and maintenance (domain reputation, mail-gateway evasion, SPF/DKIM/DMARC alignment), payload delivery and identity theft (AiTM session hijacking, OAuth consent abuse), and multi-channel pretext design across email, IM, and voice.
  • AI attack surface awareness and practice. Familiarity with the security weaknesses of LLM-based applications (prompt injection, broken authorization, data leakage) and the attack surface introduced by emerging integrations such as MCP, agents, and tool calling; prior research or hands-on experience is a plus.
  • Active Directory attack expertise. Deep understanding of AD authentication and trust models, with hands-on command of Kerberos attacks (Kerberoasting, delegation abuse, ticket forgery), ACL/ADCS abuse, domain privilege escalation, and cross-domain / cross-forest lateral movement.
  • Offensive tooling development. Able to build or adapt exploitation tools, post-exploitation modules, and automation using Python / Go / C, without relying on any single off-the-shelf framework.
  • Operational OPSEC discipline. Able to evade mainstream EDR and detection during engagements, understand how offensive activity surfaces in logs and detection rules, and adjust tradecraft accordingly.

Preferred Experience
  • Tracking records of bug bounty awards, CVEs, public security articles, security conference speakers, Github star authors, etc.
  • Experience in pentesting and red teaming, familiarity with kill chains in ATT&CK Framework (for example: initial access, Windows AD testing, lateral movement).
  • Experience in spear phishing and social engineering tactics.
  • Experience in performing APT offensive and defensive

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More