Security Engineer (Penetration Testing - Red Team)
Conduct comprehensive penetration testing on company applications and systems, organize attack-defense drills, test blue-team defenses, research offensive and defensive technologies, introduce security tools, and build detection, monitoring, intrusion-traceability, and threat-informed countermeasure capabilities.
Responsibilities
- Conduct comprehensive penetration testing on company applications and systems
- Organize regular attack-defense drills
- Test and bypass the defense technologies of the company's blue team to enhance the security protection level
- Research offensive and defensive technologies and track and analyze cutting-edge industry technologies
- Introduce excellent security technologies and tools
- Participate in the construction of security capabilities, including detection rules, monitoring strategies, and intrusion traceability
- Build and drill countermeasures and TTPs based on real threat intelligence and industry APT behavior models
Requirements
- Possess more than 5 years of practical experience in attack and defense, and be able to independently complete penetration testing work
- Familiar with common internal network attack ideas and methods, with internal network penetration and domain penetration capabilities and successful cases
- Have practical experience in AWS cloud environment penetration, container and Kubernetes security attack and defense
- Familiar with Linux and Windows system principles, databases, command execution, and privilege escalation techniques
- Familiar with mainstream web frameworks and capable of code auditing and vulnerability mining in Java, Go, and Python
- Have practical experience in red and blue team exercises
- Be able to write scripts or tools for automated exploitation and basic tool development