锦鲤求职

中电控股

Red Team Manager

锦鲤会替你打开官网网申、按简历自动填表提交,你只需要在关键步骤确认。

岗位描述

Working Location: Kai Tak, Kowloon, Hong Kong

Employment Duration: Permanent

The Red Team Manager is responsible for identifying and exploiting vulnerabilities in computer systems, applications, and networks. This role will work closely with various internal teams and security personnel to ensure that proper security measures are implemented throughout the organisation.

The primary focus of this role will be to help scope and perform Red Team exercises.

As such, it is expected that the successful candidate will possess Red Team skills and relevant experience.

Key Responsibilities

Assist to develop and execute a program of offensive campaigns (Red Team exercises) to test CLP’s cyber detective and protective controls.

Drive innovative thinking by researching, creating and testing new tools and techniques to identify vulnerabilities in the people, processes and technologies that CLP use.

Provide CLP with detailed reports that contain the necessary insight to support security fixes, patches, remediation, and training to ensure the same opportunities for exploitation do not exist in the future.

Perform quality assurance of technical reports (both Red Team and penetration testing reports).

Develop and execute custom scripts to automate and streamline testing procedures.

Work with development teams and security personnel to help prioritize and remediate identified vulnerabilities.

Stay current with emerging security threats, vulnerabilities, and share knowledge with other security team members.

Provide regular reports and assist with creating technical presentations for senior leadership.

Qualifications & Experience

Bachelor's degree in Computer Science, Information Technology, or a related field.

6-7 years of experience in scoping and executing Red Team exercises, penetration tests, and security tests.

Independent management experience covering penetration testing projects, including project planning, scoping, and quality assurance.

In-depth understanding of attacker TTPs (tactics, techniques, and procedures) and how these apply to Red Team exercises.

Strong understanding of network security, web application security, API security, cloud security, and mobile application security.

Experience performing EDR evasion, bespoke tool development, and associated research.

Experience reviewing Windows Active Directory security and cloud environments.

Knowledge of scripting languages such as Python, C/C++, .NET, or PowerShell.

Good command of spoken and written English.

Ability to explain technical issues to non-technical stakeholders.

Ability to work collaboratively with cross-functional teams.

Exhibit a high level of self-motivation and drive to achieve personal and team goals.

Actively shares technical knowledge and insights with team members to foster a collaborative environment.

Independent research experience performing vulnerability research and exploitation is a plus.

Embrace new ideas, approaches, and be willing to learn and adapt to evolving technologies.

Holding a relevant penetration testing certification such as OSCP, OSCE, OSEP, or OSCE3 is required.

Holding a Red Team certification (such as CRTO/CRTE/PACES) is required.

运维/技术支持方向的申请准备

先核对岗位要求与自己的经历,再准备档案、投递和面试。

阅读求职步骤与示例 →