Get more replies from employers
Send a job-specific resume in minutes.
Deriv is seeking a senior Red Team Lead to proactively thwart threats before they become incidents. You will lead offensive security across infrastructure, applications, cloud, and people, turning engagements into detections, automation, and resilience.
We value deep adversary experience, real-world tooling, and the ability to produce actionable remediation reports. You will collaborate with SOC and Threat Hunting and mentor junior operators in a fast-moving fintech environment in Dubai and
We're not hiring a security engineer to keep up with threats. We're hiring someone to make threats irrelevant before they become incidents. We're looking for a Red Team Lead/Operator who thinks like an adversary, not an auditor. Someone who continuously emulates real-world attackers, challenges assumptions, and exposes the gaps that automated defenses miss. You'll lead offensive security operations across our infrastructure, applications, cloud, and people - turning every engagement into detections, automation, and resilience. The goal isn't to prove we can be breached. It's to make the platform smarter with every attack.
Deriv's mission is Trading for Anyone, Anywhere, Anytime. Millions of traders across the globe, around the clock, across regulatory environments. At this scale, a misconfigured WAF rule or undetected lateral movement isn't a technical inconvenience - it's a trader's funds at risk and a regulator on the phone.
Our Security Operations team isn't defending a perimeter. We're protecting a living, distributed system that processes transactions 24/7. When the threat surface never sleeps, your detection and response capabilities can't either - which is exactly why we're embedding AI and automation at every layer of the security stack.
$600B moves through this platform every month. That kind of scale attracts real adversaries: state-sponsored crews, financially motivated groups, insiders. Not hypothetical threat models, actual ones, actively working against us.
That's the environment. Not a lab. Not a CTF. A live financial platform under real pressure, defended by a security org that runs its own incident response instead of reading about breaches in the news.
We need someone who can operate like the people already trying to get in. Full kill chain, no shortcuts, no "we found SQLi and called it a day" energy.
If your idea of a challenging week is a scoped web app pentest with a checklist, this isn't for you. If you want to run against cloud, identity, source code, and now AI agents with tool access and memory, keep reading.
We already run our own incident response and purple-team our findings straight into detections, not a compliance exercise, an active discipline with real fallout when it's wrong. Our security org is starting to red-team AI agents with tool access and memory, work most companies haven't figured out how to even scope yet. You'll get hands‑on production experience that would take far longer to accumulate at a single-product company.
We share what we learn. Deriv is where we write about what we're building, what breaks, and what we figure out the hard way.
You'll sit inside a Security & AI Engineering org that treats offensive security as a real discipline, not a line item for the compliance audit.
You'll work across Dubai and Malaysia with a team that runs actual incident response, not tabletop exercises with fake scenarios.
You'll have a direct line from finding a hole to it getting closed, and room to build the tooling and run the engagements that shape how we red‑team the AI agents everyone else is still figuring out how to even think about.