Red team security engineer at Axiata's Security Operations team who plans and executes adversary simulations, develops offensive TTPs and custom exploits, performs full exploitation across Active Directory and mixed Windows/*nix/macOS environments, builds tooling, and writes technical and executive reports. Core tech: penetration testing, C2 frameworks, Kali Linux.
We are looking for smart, talented, and self-motivated cyber security professionals to join our fast-growing Security Operations team at Axiata. As a security engineer, you will be working with companies across Southeast Asia to solve security challenges at scale and speed. If you are passionate about all things cyber security and looking for an exciting every day, then this role is for you!
Key Responsibilities
Plan, spearhead and execute sophisticated adversary simulation activities to enable the identification and mitigation of identified vulnerabilities
Research, develop, and apply offensive tactics, techniques, and procedures (TTP´s) to effectively mimic the capabilities of relevant threat actors
Provide subject matter expertise in offensive security for cyber defenders, remediation teams and enterprise technology teams
Develop tooling to support reconnaissance, automation, and metrics collection
Conduct full exploitation within multiple environments, including complex Active Directory and mixed Windows, *nix and MacOS environments
Develop comprehensive, accurate reports targeting both technical and executive audiences
Define and maintain a set of Standard Operating Procedures (SOP), Rules of Engagement (ROE), Methodologies and checklist for Red and Purple Team operations
Excellent communication and presentation skills to communicate levels of risk as well as solutions to reduce risk most accurately and effectively in a prioritized manner
Person Specifications
3+ years of experience performing vulnerability assessments
Excellent understanding of OWASP Top 10 vulnerabilities and it's mitigations
Clear understanding of networking fundamentals: OSI layers, TCP/IP, protocols, etc
Experience working on a GNU/Linux based penetration testing operating system and the command line (such as Kali Linux, Parrot, BlackArch, etc.)
Experience with security testing tools and tradecraft. Must have an in depth understanding of common concepts relating to Command and Control (C2) frameworks and their development/customization/use
Ability to modify known and/or craft custom exploits manually without dependence on consumer tools such as Metasploit
Ability to modify known and/or craft custom exploits manually without dependence on consumer tools such as Metasploit
Good spoken and written English skills
Nice To Have
Security certifications: OSCP, OSCE, CRTP, GIAC certs or equivalent
Working knowledge of Tenable security solutions
Knowledge of Windows penetration testing: Active Directory, Azure AD
CVE publications, knowledge of exploit development
Talks/workshops organized at security conferences
Excellent bug bounty track record
Open-source contributions made to security tools, scripts & solutions
Development background and code review capabilities