Offensive Security Engineer

4 weeks ago


Singapore PAYPAL PTE. LTD. Full time
Roles & Responsibilities

Job Description Summary:

This offensive security engineer will lead and execute security engagements that combine both red team and purple team methodologies. Your role will involve designing and executing sophisticated cyberattacks, simulating advanced persistent threats and collaborating closely with the defense (blue) teams to improve detection, response, and overall security posture. You will work to challenge, assess, and enhance the organization’s security operations, ensuring that defenses are robust and responsive to current and evolving threats.

Job Description:

Key Responsibilities:Red Team:
  • Execute adversarial simulations mimicking real-world threat actors (APTs, insider threats, etc.).
  • Research and simulate evolving cyber threats, vulnerabilities, and tactics, techniques, and procedures (TTPs) of adversaries.
  • Develop custom scripts, tools, and payloads to bypass security controls and detection.
  • Identify security weaknesses and vulnerabilities across systems, networks, and applications.
  • Evade detection while conducting stealthy operations to assess the maturity of monitoring capabilities.

Purple Team:
  • Collaborate with the blue team to optimize detection and response mechanisms.
  • Facilitate knowledge sharing and training during real-time testing engagements, emphasizing skill development across red, blue, and purple teams.
  • Test the effectiveness of existing security controls, offer insights for enhancement, and assist in adjusting strategies.
  • Provide real-time attack/defense simulations to measure the accuracy and effectiveness of the blue team’s response.

Reporting and Documentation:
  • Prepare detailed, actionable reports that communicate findings, risks, and remediation recommendations to both technical and non-technical stakeholders.
  • Work with leadership to develop strategic security roadmaps based on testing results.
Required Skills & Qualifications:
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience.
  • 5+ years of experience in offensive security (Red Teaming, Penetration Testing, or related fields).
  • Deep understanding of adversary tactics, techniques, and procedures (TTPs), such as those outlined by MITRE ATT&CK.
  • Strong proficiency with offensive security tools (e.g., Cobalt Strike, Metasploit, Burp Suite, BloodHound, Mimikatz).
  • Advanced experience in network and application penetration testing.
  • Knowledge of both Windows and Linux operating systems, scripting (e.g., Python, PowerShell, Bash), and familiarity with cloud environments (AWS, Azure, GCP).
  • Experience working collaboratively in a purple team environment with a focus on improving defensive capabilities.
  • Strong analytical and problem-solving skills, with a proactive and collaborative mindset.
  • Industry certifications such as OSCP, OSCE, CRTO, CRTP, CRTE, CEH, GPEN,GXPN or similar.

Preferred Qualifications:
  • Experience conducting stealth red team engagements, including lateral movement, persistence, and data exfiltration.
  • Proficiency in attack automation and tool development.
  • Familiarity with blue team operations and defensive security technologies (SIEMs, EDR, IDS/IPS).
  • Contributions to open-source security tools or published research on offensive security topics.

Tell employers what skills you have

CEH
Security Operations
Remediation
Azure
Defense
Powershell
Scripting
Information Technology
Penetration Testing
Python
Operating Systems
Windows
Simulations
Network Security
Burp Suite
Linux

  • Singapore TRAVELOKA TECHNOLOGY PTE. LTD. Full time

    Company Overview: Traveloka is a leading technology company that provides a one-stop travel and lifestyle platform for customers in Southeast Asia. Our platform offers a wide range of travel-related services, including flight and hotel bookings, activities, attractions, and more. With a mission to empower travelers with seamless experiences, we're...


  • Singapore TRAVELOKA TECHNOLOGY PTE. LTD. Full time

    Roles & ResponsibilitiesCompany Overview:Traveloka is a leading technology company that provides a one-stop travel and lifestyle platform for customers in Southeast Asia. Our platform offers a wide range of travel-related services, including flight and hotel bookings, activities, attractions, and more. With a mission to empower travelers with seamless...


  • Singapore PRIVASEC PTE. LTD. Full time

    Roles & Responsibilities*This role requires a security clearance. Eligible individuals will be prioritised.Our Red Team Offensive Security Consultants work with organisations and technical teams to perform a variety of assessments and provide practical advice to keep them secure. Red team members are generally familiar with and apply themselves to most...


  • Singapore PixiePoint Security Pte Ltd Full time

    We are seeking talented and passionate individuals to join our Offensive Security team! This position has a strong focus on developing exploits for known vulnerabilities in systems and devices. This position will be based in Singapore. Remote work arrangement is possible for the ideal candidate. We regret to inform that only shortlisted candidates will be...


  • Singapore PixiePoint Security Pte Ltd Full time

    We are seeking talented and passionate individuals to join our Offensive Security team! This position has a strong focus on discovering unknown vulnerabilities in systems and devices. This position will be based in Singapore. Remote work arrangement is possible for the ideal candidate. We regret to inform that only shortlisted candidates will be notified....


  • Singapore Wizlynx Group Full time

    About Wizlynx GroupWe're a cybersecurity firm dedicated to protecting our clients' digital assets. As a Red Team Specialist, you'll play a critical role in our team, focusing on emulating threat actors to assess and enhance the security of enterprise networks.Key ResponsibilitiesEmulate threat actor tactics, techniques, and procedures to assess the security...


  • Singapore Horangi Cyber Security Full time

    HORANGI CYBER SECURITYCybersecurity Consultant Job SummaryWe are seeking a highly skilled and experienced Cybersecurity Consultant to join our team. The successful candidate will work in our Cyber Operations (Offensive) team, performing offensive security assessments for our clients.Key Responsibilities:Conduct penetration testing of web and mobile...


  • Singapore Horangi Cyber Security Full time

    At Horangi Cyber Security, we are seeking a highly skilled Cybersecurity Specialist to join our team. The ideal candidate will possess at least two years of experience in offensive security and hold certifications such as OffSec Certified Professional (OSCP) and/or CREST Registered Penetration Tester.The successful candidate will work closely with our...


  • Singapore SINGAPORE MARITIME INSTITUTE Full time

    Roles & ResponsibilitiesYou will be a key member of the R&D Digital Translation team established under the Singapore Maritime Institute. The R&D Digital Translation team develops and operates digital and cyber products and translates R&D projects to real world implementations for the maritime industry. You will provide application security consultancy and...


  • Singapore Wizlynx PTE LTD Full time

    About usAt wizlynx group, we're on a mission to fortify the digital defense of our clients by staying one step ahead of cyber threats. As a Red Team Specialist, you'll play a pivotal role in our cybersecurity team, focusing on emulating threat actors to assess and enhance the security of enterprise networks. Your mission: to penetrate, identify...


  • Singapore WatchTowr Pte. Ltd. Full time

    We are watch Towr, a VC-backed cyber security startup helping organisations continuously discover vulnerabilities in their Internet-facing attack surface. Cyber security veterans and technical experts, we are obsessed with building cybersecurity technology to help prevent breaches. With experience informed by years of simulating sophisticated cyber attacks...


  • Singapore OCBC Bank Full time

    Job Description - Security Testing Specialist (240001 P6)Roles and Responsibilities: Perform application penetration testing on web-based applications and APIs. Perform network penetration testing on systems. Exploit vulnerabilities to gain access and expand access to remote systems. Document and explain the technical details of the security issues...


  • Singapore SINGAPORE MARITIME INSTITUTE Full time

    Job Title: Digital Security SpecialistThe Singapore Maritime Institute is looking for a skilled Digital Security Specialist to join their R&D Digital Translation team. The ideal candidate will have experience in application security, cloud computing, and software development. They will be responsible for providing security consultancy and support to...

  • Security engineer

    4 days ago


    Singapore LZ Security & Service GmbH Full time

    Job Responsibilities: Formulation and implementation of security response plan and security assurance for the whole life cycle of the system. Handle 7 × 24 hour security incident response. Vulnerability management; anti-phishing tasks. Requirements: 5 years+ security experience. Experienced in intrusion detection, event tracing and log analysis. Familiar...

  • Security engineer

    5 days ago


    Singapore LZ Security & Service GmbH Full time

    Job Responsibilities:Formulation and implementation of security response plan and security assurance for the whole life cycle of the system. Handle 7 × 24 hour security incident response. Vulnerability management; anti-phishing tasks. Requirements:5 years+ security experience. Experienced in intrusion detection, event tracing and log analysis. Familiar...


  • Singapore The Chemical Engineer Full time

    About us At Exxon Mobil, our vision is to lead in energy innovations that advance modern living and a net-zero future. As one of the world’s largest publicly traded energy and chemical companies, we are powered by a unique and diverse workforce fueled by the pride in what we do and what we stand for. The success of our Upstream, Product Solutions and Low...


  • Singapore Accor Full time

    Company Description Sofitel Singapore City Centre, an iconic hotel which opens in October 2017, will form part of a mixed-use development at Tanjong Pagar Centre, a multi-billion dollar development, which will become Singapore’s tallest building at 290 meters set around landscaped parkland and direct MRT station access. The 223-room Sofitel Singapore City...


  • Singapore OCBC Full time

    Roles and Responsibilities: Perform application penetration testing on web-based applications, APIs Perform mobile application penetration testing across different mobile platforms Perform network penetration testing on systems. Exploit vulnerabilities to gain access and expand access to remote systems. Document and explain the technical details of...


  • Singapore DRAGNET SMARTECH SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesCore Roles and Responsibilities: Possess a solid understanding and working knowledge of IP/Analog CCTV systems, Access Control, and Remote sensor systems. Proficient in installing and configuring Ethernet-based network equipment and systems (both remote and local). Familiar with IoT sensors/hubs and their interface with web...


  • Singapore ROBERT BOSCH SECURITY SOLUTIONS PTE. LTD. Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Security Systems Engineer to join our team at Robert Bosch Security Solutions PTE. LTD.Job DescriptionAs a Senior Security Systems Engineer, you will be responsible for designing and implementing cost-competitive security solutions that meet the needs of our clients. Your primary focus will...