jobs in Shopee

全职 Offensive Security Expert Engineer (Red Team) 工作, 薪水, Shopee 公司招聘中 - Ricebowl

Offensive Security Expert Engineer (Red Team)

Undisclosed

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

About The Team

The Red Team within Information Security simulates real-world adversaries to proactively uncover vulnerabilities across Sea Group's infrastructure, applications, and people, including Shopee, SeaMoney (Monee), and Digibank. We conduct end-to-end offensive operations from external compromise and social engineering through to internal lateral movement. We collaborate closely with defensive teams to translate findings into stronger detections and hardening measures. Through continuous research, custom tooling development, and methodology refinement, we drive the maturity of Sea Group's overall security posture.

Job Description

  • Conduct offensive security research: independently perform vulnerability discovery and exploit development, build and adapt post-exploitation tooling and red team infrastructure, and continuously grow a reusable capability and tooling arsenal.
  • Drive purple team collaboration: map attack paths and findings to MITRE ATT&CK, produce high-quality technical reports, work with the defensive team to translate TTPs into detection rules and hardening measures, and validate improvements through retesting.
  • Contribute to red team methodology and program maturity: codify standardized attack workflows, automation, and a TTP library to improve the team's overall operational efficiency and repeatability.

Requirements

  • Bachelor's Degree in Computer Science or related field.
  • At least 5 years of security engineering experience
  • End-to-end penetration testing. Able to independently handle external compromise (perimeter asset discovery, web/service exploitation, initial access) and perform lateral movement and privilege escalation across internal networks, reliably reaching target assets in live engagements.
  • Multi-platform vulnerability research. Deep expertise in at least 2 of the following: operating systems, cloud native (containers / Kubernetes), IoT, and mobile (Android / iOS). Able to independently drive vulnerability discovery, root-cause analysis, and reliable exploit development — not merely run existing tools.
  • Hands-on social engineering & phishing. Able to independently design and execute social engineering campaigns, including phishing infrastructure setup and maintenance (domain reputation, mail-gateway evasion, SPF/DKIM/DMARC alignment), payload delivery and identity theft (AiTM session hijacking, OAuth consent abuse), and multi-channel pretext design across email, IM, and voice.
  • AI attack surface awareness and practice. Familiarity with the security weaknesses of LLM-based applications (prompt injection, broken authorization, data leakage) and the attack surface introduced by emerging integrations such as MCP, agents, and tool calling; prior research or hands-on experience is a plus.
  • Active Directory attack expertise. Deep understanding of AD authentication and trust models, with hands-on command of Kerberos attacks (Kerberoasting, delegation abuse, ticket forgery), ACL/ADCS abuse, domain privilege escalation, and cross-domain / cross-forest lateral movement.
  • Offensive tooling development. Able to build or adapt exploitation tools, post-exploitation modules, and automation using Python / Go / C, without relying on any single off-the-shelf framework.
  • Operational OPSEC discipline. Able to evade mainstream EDR and detection during engagements, understand how offensive activity surfaces in logs and detection rules, and adjust tradecraft accordingly.

Preferred Experience

  • Tracking records of bug bounty awards, CVEs, public security articles, security conference speakers, Github star authors, etc.
  • Experience in pentesting and red teaming, familiarity with kill chains in ATT&CK Framework (for example: initial access, Windows AD testing, lateral movement).
  • Experience in spear phishing and social engineering tactics.
  • Experience in performing APT offensive and defensive

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多