Offensive Security Expert Engineer (Red Team)

Shopee

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Shopee’s Red Team within Information Security simulates real-world adversaries, proactively uncovering vulnerabilities across Sea Group’s infrastructure, apps, and people, including Shopee. The team drives security maturity through research, tooling, and methodology refinement.

Requirements include a CS degree and 5+ years of security engineering, with end-to-end pentesting, multi-platform research, social engineering, and AD/ Kerberos expertise.

Qualifications

  • Bachelor's degree in Computer Science or related field.
  • 5+ years of security engineering experience with red/blue team exposure.
  • End-to-end penetration testing: external compromise, lateral movement, privilege escalation.
  • Vulnerability research across OS, cloud native, IoT, or mobile platforms.
  • Design and execution of social engineering campaigns and phishing.
  • Familiarity with LLM security risks and tool integrations is a plus.
  • Active Directory attack know-how including Kerberos and domain lateral movement.
  • Ability to build or adapt exploitation tools and automation in Python/Go/C.

Responsibilities

  • Conduct offensive security research: vulnerability discovery, exploit development, tooling.
  • Drive purple team collaboration: map attack paths to MITRE ATT&CK and produce reports.
  • Codify attack workflows and build a scalable red team program.

Skills

Penetration testing
Red team tooling
ATT&CK mapping
Phishing campaigns
Exploitation development
Python/Go/C
EDR evasion
SOC collaboration

Education

Bachelor's Degree in Computer Science

Job description

About The Team

The Red Team within Information Security simulates real-world adversaries to proactively uncover vulnerabilities across Sea Group's infrastructure, applications, and people, including Shopee, SeaMoney (Monee), and Digibank. We conduct end-to-end offensive operations from external compromise and social engineering through to internal lateral movement. We collaborate closely with defensive teams to translate findings into stronger detections and hardening measures. Through continuous research, custom tooling development, and methodology refinement, we drive the maturity of Sea Group's overall security posture.

Job Description
  • Conduct offensive security research: independently perform vulnerability discovery and exploit development, build and adapt post-exploitation tooling and red team infrastructure, and continuously grow a reusable capability and tooling arsenal.
  • Drive purple team collaboration: map attack paths and findings to MITRE ATT&CK, produce high-quality technical reports, work with the defensive team to translate TTPs into detection rules and hardening measures, and validate improvements through retesting.
  • Contribute to red team methodology and program maturity: codify standardized attack workflows, automation, and a TTP library to improve the team's overall operational efficiency and repeatability.
Requirements
  • Bachelor's Degree in Computer Science or related field.
  • At least 5 years of security engineering experience
  • End-to-end penetration testing. Able to independently handle external compromise (perimeter asset discovery, web/service exploitation, initial access) and perform lateral movement and privilege escalation across internal networks, reliably reaching target assets in live engagements.
  • Multi-platform vulnerability research. Deep expertise in at least 2 of the following: operating systems, cloud native (containers / Kubernetes), IoT, and mobile (Android / iOS). Able to independently drive vulnerability discovery, root-cause analysis, and reliable exploit development — not merely run existing tools.
  • Hands-on social engineering & phishing. Able to independently design and execute social engineering campaigns, including phishing infrastructure setup and maintenance (domain reputation, mail-gateway evasion, SPF/DKIM/DMARC alignment), payload delivery and identity theft (AiTM session hijacking, OAuth consent abuse), and multi-channel pretext design across email, IM, and voice.
  • AI attack surface awareness and practice. Familiarity with the security weaknesses of LLM-based applications (prompt injection, broken authorization, data leakage) and the attack surface introduced by emerging integrations such as MCP, agents, and tool calling; prior research or hands-on experience is a plus.
  • Active Directory attack expertise. Deep understanding of AD authentication and trust models, with hands-on command of Kerberos attacks (Kerberoasting, delegation abuse, ticket forgery), ACL/ADCS abuse, domain privilege escalation, and cross-domain / cross-forest lateral movement.
  • Offensive tooling development. Able to build or adapt exploitation tools, post-exploitation modules, and automation using Python / Go / C, without relying on any single off-the-shelf framework.
  • Operational OPSEC discipline. Able to evade mainstream EDR and detection during engagements, understand how offensive activity surfaces in logs and detection rules, and adjust tradecraft accordingly.
Preferred Experience
  • Tracking records of bug bounty awards, CVEs, public security articles, security conference speakers, Github star authors, etc.
  • Experience in pentesting and red teaming, familiarity with kill chains in ATT&CK Framework (for example: initial access, Windows AD testing, lateral movement).
  • Experience in spear phishing and social engineering tactics.
  • Experience in performing APT offensive and defensive
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Red Team Expert
Senior Red Team Expert

Planet Nine • Singapore

On-site
SGD 100,000 - 150,000
Cyber Defense Analyst, Cyber Security
Cyber Defense Analyst, Cyber Security

605 Marina Bay Sands Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Senior Red Team Engineer
Senior Red Team Engineer

Shopee • Singapore

On-site
SGD 120,000 - 180,000
Consultant, Security Testing and Red Teaming
Consultant, Security Testing and Red Teaming

Ensign InfoSecurity • Singapore

On-site
SGD 90,000 - 150,000
Red Team Specialist, Financial Services
Red Team Specialist, Financial Services

Kerry Consulting • Singapore

On-site
SGD 120,000 - 190,000
Penetration Testers/ Red Teamers
Penetration Testers/ Red Teamers

KERRY CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior Red Team Specialist — Offensive Security
Senior Red Team Specialist — Offensive Security

Kerry Consulting • Singapore

On-site
SGD 120,000 - 190,000
Cybersecurity Engineer (Web Security) - Information Security (2027 Graduate)
Cybersecurity Engineer (Web Security) - Information Security (2027 Graduate)

Shopee • Singapore

On-site
SGD 120,000 - 180,000
Associate Consultant, Security Testing and Red Teaming
Associate Consultant, Security Testing and Red Teaming

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

On-site
SGD 52,000 - 82,000
Security Engineer (Security Operation Center), Information Security (2027 Graduate)
Security Engineer (Security Operation Center), Information Security (2027 Graduate)

Shopee • Singapore

On-site
SGD 90,000 - 130,000