- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Bachelor's Degree in Computer Science or related
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About The Team
The Red Team in Information Security simulates adversaries to proactively identify vulnerabilities across Sea Group's infrastructure, including Shopee, SeaMoney, and Digibank. This involves comprehensive offensive operations from external breaches and social engineering to lateral internal movements. Collaboration with defensive teams is essential to convert findings into improved detections and security enhancements. The team also focuses on continuous research, custom tool creation, and refining methodologies to enhance the group's security posture.
Job Responsibilities
- Carry out offensive security research by independently identifying vulnerabilities, developing exploits, creating and refining post-exploitation tools and red team infrastructure, and building a reusable toolkit.
- Facilitate purple team efforts by mapping attack chains to MITRE ATT&CK, producing detailed technical reports, working with defenders to translate tactics into detection and mitigation, and verifying improvements with retests.
- Enhance red team procedures by standardizing attack workflows, automating processes, and maintaining a tactics, techniques, and procedures (TTP) library to boost operational effectiveness and consistency.
Requirements
- Bachelor's Degree in Computer Science or related discipline.
- Minimum of five years in security engineering roles.
- Proficient in comprehensive penetration testing including external compromise and internal network lateral movement and privilege escalation in live environments.
- Specialized vulnerability research expertise in at least two areas among operating systems, cloud-native technologies (containers/Kubernetes), IoT, or mobile platforms (Android/iOS), including independent exploit development.
- Experience in social engineering and phishing, capable of independently designing and executing campaigns with infrastructure setup covering domain reputation, mail gateways, and identity theft techniques.
- Knowledge of AI security vulnerabilities such as prompt injection, authorization flaws, and data leakages related to LLM-based applications and integrations.
- Advanced skills in Active Directory attacks, including understanding authentication models, Kerberos-related exploits, ACL/ADCS abuse, domain privilege escalation, and cross-domain movement.
- Capability to develop or tailor offensive tools and automation using programming languages such as Python, Go, or C without dependence on established frameworks.
- Strong operational security discipline during engagements to bypass common detection systems and adapt tradecraft based on forensics and logs.
Preferred Experience
- Proven track record via bug bounty awards, CVEs, publications, conference presentations, or recognized open-source contributions.
- Experience with penetration testing, red teaming, and familiarity with ATT&CK framework kill chains.
- Background in spear phishing and social engineering strategies.
- Experience conducting advanced persistent threat (APT) offensive and defensive exercises.
Minimum education
Bachelor's Degree