Security Engineer - Offensive Security (Red Team)

XL Axiata

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

XL Axiata seeks a Security Engineer - Offensive Security (Red Team) to join the Security Operations team in Malaysia. You will plan and execute adversary simulations, develop offensive tactics, and provide SME guidance to defenders and remediation teams.

You will build tooling, perform exploitation across mixed environments, and produce reports for technical and executive audiences, while defining SOPs and ROE for Red/Purple Team operations.

Qualifications

  • 3+ years of experience performing vulnerability assessments.
  • Excellent understanding of OWASP Top 10 vulnerabilities and mitigations.
  • Clear understanding of networking fundamentals: OSI layers, TCP/IP, protocols.
  • Experience with a GNU/Linux based penetration testing OS (e.g., Kali, Parrot, BlackArch).
  • Experience with security testing tools and tradecraft; knowledge of C2 frameworks and customization.
  • Ability to craft/modify exploits without consumer tools like Metasploit.
  • Good spoken and written English skills.

Responsibilities

  • Plan, spearhead and execute adversary simulations to identify and mitigate vulnerabilities.
  • Research and apply offensive TTPs to mimic threat actors.
  • Provide SME offensive security guidance to cyber defenders and remediation teams.
  • Develop tooling to support recon, automation, and metrics collection.
  • Conduct full exploitation across AD, Windows, Linux, and MacOS environments.
  • Produce comprehensive reports for technical and executive audiences.
  • Define SOPs, ROE, methodologies and checklists for Red/Purple Team ops.
  • Communicate risk levels and solutions clearly to reduce risk effectively.

Skills

Vulnerability assessments
OWASP Top 10
Networking fundamentals
GNU/Linux pentesting
Security testing tools
C2 frameworks
Exploitation techniques
English communication

Education

OSCP/OSCE/CRTP/GIAC or equivalent

Tools

Kali Linux
Parrot
BlackArch
Tenable

Job description

Security Engineer - Offensive Security (Red Team)

We are looking for smart, talented, and self-motivated cyber security professionals to join our fast-growingSecurity Operations team at Axiata. As a security engineer, you will be working with companies acrossSoutheast Asia to solve security challenges at scale and speed. If you are passionate about all things cybersecurity and looking for an exciting every day, then this role is for you!

Key Responsibilities

  • Plan, spearhead and execute sophisticated adversary simulation activities to enable the identificationand mitigation of identified vulnerabilities
  • Research, develop, and apply offensive tactics, techniques, and procedures (TTP´s) to effectivelymimic the capabilities of relevant threat actors
  • Provide subject matter expertise in offensive security for cyber defenders, remediation teams andenterprise technology teams
  • Develop tooling to support reconnaissance, automation, and metrics collection
  • Conduct full exploitation within multiple environments, including complex Active Directory and mixedWindows, *nix and MacOS environments
  • Develop comprehensive, accurate reports targeting both technical and executive audiences
  • Define and maintain a set of Standard Operating Procedures (SOP), Rules of Engagement (ROE),Methodologies and checklist for Red and Purple Team operations
  • Excellent communication and presentation skills to communicate levels of risk as well as solutions toreduce risk most accurately and effectively in a prioritized manner

Person Specifications

  • 3+ years of experience performing vulnerability assessments
  • Excellent understanding of OWASP Top 10 vulnerabilities and it's mitigations
  • Clear understanding of networking fundamentals: OSI layers, TCP/IP, protocols, etc
  • Experience working on a GNU/Linux based penetration testing operating system and the command line(such as Kali Linux, Parrot, BlackArch, etc.)
  • Experience with security testing tools and tradecraft. Must have an in depth understanding of commonconcepts relating to Command and Control (C2) frameworks and their development/customization/use
  • Ability to modify known and/or craft custom exploits manually without dependence on consumer toolssuch as Metasploit
  • Ability to modify known and/or craft custom exploits manually without dependence on consumer toolssuch as Metasploit
  • Good spoken and written English skills

Nice To Have

  • Security certifications: OSCP, OSCE, CRTP, GIAC certs or equivalent
  • Working knowledge of Tenable security solutions
  • Knowledge of Windows penetration testing: Active Directory, Azure AD
  • CVE publications, knowledge of exploit development
  • Talks/workshops organized at security conferences
  • Excellent bug bounty track record
  • Open-source contributions made to security tools, scripts & solutions
  • Development background and code review capabilities
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Offensive Security (Red Team)
Security Engineer - Offensive Security (Red Team)

Axonect • Kuala Lumpur

On-site
MYR 100,000 - 180,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Axonect • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Engineer - Red Team
Security Engineer - Red Team

IBroad Solutions • Petaling Jaya

On-site
MYR 120,000 - 180,000
Red Team Security Engineer - Adversary Simulation
Red Team Security Engineer - Adversary Simulation

Axonect • Kuala Lumpur

On-site
MYR 100,000 - 180,000
Red Team Security Engineer - Offensive Pentesting & TTPs
Red Team Security Engineer - Offensive Pentesting & TTPs

XL Axiata • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 90,000 - 150,000
Senior Penetration Tester
Senior Penetration Tester

FIRMUS • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Incident Response Lead
Incident Response Lead

XL Axiata • Kuala Lumpur

On-site
MYR 240,000 - 300,000
Incident Response Lead
Incident Response Lead

Axonect • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Offensive Security Analyst (Penetration Testers)
Offensive Security Analyst (Penetration Testers)

Sekuro Asia - An Insight Company • Kuala Lumpur

On-site
MYR 60,000 - 90,000