Offensive Security Engineer

3 days ago


Central Singapore PayPal Full time

**The Company**

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy.

We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.

We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards. Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade.

Our beliefs are the foundation for how we conduct business every day. We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do - and they push us to ensure we take care of ourselves, each other, and our communities.

Job Description Summary: This offensive security engineer will lead and execute security engagements that combine both red team and purple team methodologies. Your role will involve designing and executing sophisticated cyberattacks, simulating advanced persistent threats and collaborating closely with the defense (blue) teams to improve detection, response, and overall security posture. You will work to challenge, assess, and enhance the organization’s security operations, ensuring that defenses are robust and responsive to current and evolving threats.

**Job Description**:
**Key Responsibilities**:
**Red Team**:

- Execute adversarial simulations mimicking real-world threat actors (APTs, insider threats, etc.).
- Research and simulate evolving cyber threats, vulnerabilities, and tactics, techniques, and procedures (TTPs) of adversaries.
- Develop custom scripts, tools, and payloads to bypass security controls and detection.
- Evade detection while conducting stealthy operations to assess the maturity of monitoring capabilities.

**Purple Team**:

- Collaborate with the blue team to optimize detection and response mechanisms.
- Facilitate knowledge sharing and training during real-time testing engagements, emphasizing skill development across red, blue, and purple teams.
- Test the effectiveness of existing security controls, offer insights for enhancement, and assist in adjusting strategies.
- Provide real-time attack/defense simulations to measure the accuracy and effectiveness of the blue team’s response.

***:
**Reporting and Documentation**:

- Prepare detailed, actionable reports that communicate findings, risks, and remediation recommendations to both technical and non-technical stakeholders.
- Work with leadership to develop strategic security roadmaps based on testing results.

**Required Skills & Qualifications**:

- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience.
- 5+ years of experience in offensive security (Red Teaming, Penetration Testing, or related fields).
- Deep understanding of adversary tactics, techniques, and procedures (TTPs), such as those outlined by MITRE ATT&CK.
- Strong proficiency with offensive security tools (e.g., Cobalt Strike, Metasploit, Burp Suite, BloodHound, Mimikatz).
- Knowledge of both Windows and Linux operating systems, scripting (e.g., Python, PowerShell, Bash), and familiarity with cloud environments (AWS, Azure, GCP).
- Experience working collaboratively in a purple team environment with a focus on improving defensive capabilities.
- Strong analytical and problem-solving skills, with a proactive and collaborative mindset.
- Industry certifications such as OSCP, OSCE, CRTO, CRTP, CRTE, CEH, GPEN,GXPN or similar.

**Prefer



  • Singapore Shopee Full time

    Offensive Security Engineer (Red Team) - Information Security Join to apply for the Offensive Security Engineer (Red Team) - Information Security role at Shopee . Job Responsibilities Design and perform APT adversary emulation to assess infrastructure, systems, and applications against confidentiality, integrity, authentication, availability, authorization,...


  • Singapore Assurity Trusted Solutions Pte Ltd Full time

    A government-facilitated cybersecurity firm in Singapore seeks a Senior/Lead Offensive Cybersecurity Engineer to lead VAPT initiatives and provide expert consultancy. The ideal candidate will have over 8 years in cybersecurity, proven VAPT leadership skills, and relevant certifications. This role is integral for enhancing client security postures and guiding...


  • Singapore REVUP PROSERVICES PTE. Ltd Full time

    Description Offensive Security Consultant Permanent role Work location: CBD area The Opportunity Support sales as needed: attend meetings, estimate effort, provide timelines. Develop security acceptance test plans. Provide technical support during testing activities. Prepare test environments: configure/install security tools. Execute manual and automated...


  • Singapore REVUP PROSERVICES PTE. LTD. Full time

    Offensive Security Consultant Permanent role Work location: CBD area The Opportunity Support sales as needed: attend meetings, estimate effort, provide timelines. Develop security acceptance test plans. Provide technical support during testing activities. Prepare test environments: configure/install security tools. Execute manual and automated security...


  • Singapore REVUP PROSERVICES PTE. Ltd Full time

    Description Offensive Security Consultant Permanent role Work location: CBD area The Opportunity Support sales as needed: attend meetings, estimate effort, provide timelines. Develop security acceptance test plans. Provide technical support during testing activities. Prepare test environments: configure/install security tools. Execute manual and automated...

  • Red Team Lead

    1 week ago


    Singapore Bitdefender S.R.L. Full time

    A cybersecurity leader is seeking an experienced Cybersecurity Red Team Consultant in Singapore to conduct offensive security assessments. This role involves leading red team engagements, mentoring team members, and collaborating closely with clients to improve their security posture. Ideal candidates will have significant experience in cybersecurity and a...


  • Singapore Assurity Trusted Solutions Pte Ltd Full time

    A trusted technology solutions company in Singapore is seeking a Senior/Lead Offensive Cybersecurity Engineer to lead vulnerability assessments and penetration testing initiatives. The ideal candidate will have extensive experience in cybersecurity, particularly in VAPT, and strong leadership skills. This role involves mentoring junior team members and...


  • Singapore Affinidi Full time

    **Affinidi **is a technology company dedicated to changing data ownership for good. We empower businesses and individuals with control and ownership of their data, with a comprehensive approach to managing their holistic identity - accounting for all aspects of their digital footprint while ensuring privacy and security. Affinidi's technology enables users...


  • Singapore JPMorganChase Full time

    Lead Cybersecurity Architect, Offensive/Defensive Security Join to apply for the Lead Cybersecurity Architect, Offensive/Defensive Security role at JPMorganChase Lead Cybersecurity Architect, Offensive/Defensive Security 1 day ago Be among the first 25 applicants Join to apply for the Lead Cybersecurity Architect, Offensive/Defensive Security role at...


  • Singapore Assurity Trusted Solutions Pte Ltd Full time

    A cybersecurity solutions provider in Singapore is looking for an Offensive Cybersecurity Engineer to conduct vulnerability assessments and penetration tests, provide cybersecurity consultancy, and contribute to the development of standards and methodologies. Candidates should have at least 3 years of relevant experience, strong technical expertise, and...