Security Engineer (Penetration Testing-Red Team)
Some ghost-posting signals
- open for 308 days (90+ without a fill is a strong ghost signal)
- 167 open roles at this company in 30 days (mass-hiring blitz)
- no salary disclosed (correlates with ghost postings)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
Job Responsibilities:
Conduct comprehensive penetration testing on company applications and systems, and organize regular attack-defense drills.
Test and bypass the defense technologies of the company's blue team to enhance the security protection level.
Research offensive and defensive technologies, track and analyze cutting-edge industry technologies, and introduce excellent security technologies and tools.
Participate in the construction of security capabilities, including detection rules, monitoring strategies, and intrusion traceability.
Build and drill countermeasures and TTPs (Tactics, Techniques, and Procedures) based on real threat intelligence and industry APT behavior models.
Requirements
Possess more than 5 years of practical experience in attack and defense, and be able to independently complete penetration testing work.
Familiar with common internal network attack ideas and methods, have internal network penetration and domain penetration capabilities with successful cases.
Have practical experience in AWS cloud environment penetration, container and Kubernetes security attack and defense.
Familiar with Linux/Windows system principles, databases and related technologies, and proficient in command execution and privilege escalation techniques.
Familiar with mainstream Web frameworks and capable of code auditing and vulnerability mining (java/go/python).
Have practical experience in red and blue team exercises.
Be able to write scripts or tools for automated exploitation and basic tool development.
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot