Jobiglo

No results.

Principal Security Operation Engineer (Red Team)

Bybit · Île de Hong Kong

New
🇬🇧 English
TCP/IP network architecture identity authentication access control Sliver Cobalt Strike NPS Burp Suite Metasploit Nmap Masscan Frida Impacket Windows Linux macOS web frameworks API architectures containers Kubernetes WAF EDR SIEM NDR HIDS Python Go Bash PowerShell JavaScript

Job description

About the role

Bybit is seeking a Principal Security Operation Engineer to lead its Red Team activities. The role focuses on designing and executing realistic attack simulations, researching AI‑related threats, and enhancing the company’s detection and response capabilities across its global digital‑finance platform.

Key responsibilities

  • Design and run red‑blue confrontation drills covering the full attack chain—from external network breach to privilege escalation and data exfiltration.
  • Analyze enterprise attack surface, identify exposed assets (network, cloud, APIs, supply‑chain) and provide mitigation recommendations.
  • Research and evaluate AI model security risks, develop red‑team test cases for large‑model attacks such as prompt injection and RAG poisoning.
  • Develop and maintain custom Red Team tools, scripts, and automated evaluation platforms using languages like Python or Go.
  • Conduct security assessments of critical systems, cloud environments, endpoints, APIs and AI applications, delivering detailed technical reports and remediation guidance.
  • Collaborate with Blue Team, security operations, engineering, and product groups to improve detection rules, baseline configurations and incident response processes.

Required profile

  • Strong foundation in networking, operating‑system security, and common security devices.
  • Hands‑on experience with penetration testing, vulnerability exploitation, privilege escalation, lateral movement and evidence cleanup.
  • Deep knowledge of enterprise security products such as WAF, EDR, SIEM, NDR, HIDS and zero‑trust architectures.
  • Ability to analyse public vulnerabilities, write PoCs and assess 0‑day/1‑day risks.
  • Proficiency in at least one scripting or programming language (Python, Go, Bash, PowerShell, JavaScript).
  • Familiarity with AI model architectures and emerging threats to large‑scale AI services.

Required skills

  • TCP/IP, network architecture, identity authentication, access control.
  • Red‑team toolchains: Sliver, Cobalt Strike, NPS, Burp Suite, Metasploit, Nmap, Masscan, Frida, Impacket.
  • Operating systems: Windows, Linux, macOS security mechanisms.
  • Web technologies: common frameworks, API architectures, micro‑services, containers, Kubernetes security.
  • Security platforms: WAF, EDR, SIEM, NDR, HIDS, zero‑trust gateways, bastion hosts.
  • Programming/scripting: Python, Go, Bash, PowerShell, JavaScript.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Bybit.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Hong Kong.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 23 hours ago

Expires 1 month from now

6 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Bybit

Île de Hong Kong