Deriv.com logo
Deriv.comPosted 1 month ago

Senior Offensive Security Engineer

On-siteCyberjaya, Selangor, Malaysia

Part TimeSenior LevelLarge

Job Summary

Execute full-kill-chain red team engagements across cloud, Kubernetes, CI/CD, and AI agent stacks, mapping attacks to MITRE ATT&CK. Design social engineering and physical/insider simulations, then conduct source code analysis and application-layer exploitation against trading and payment platforms. Build custom tooling, C2 infrastructure, and payloads to evade modern detection stacks while red-teaming AI agent trust boundaries. Partner with SOC and Threat Hunting to run purple-team exercises that close detection gaps, and mentor L1/L2 operators. Write engagement reports that drive actual remediation. Operate within a Security & AI Engineering org in Dubai and Malaysia, directly influencing how we red-team AI agents and shape offensive security capabilities.

Required Qualifications

  • 6+ years doing actual offensive security
  • Full-scope red team
  • OSCP required
  • OSCE, OSEP, OSED, CRTO or equivalent adversary simulation cert
  • Real depth in at least three of: internal AD/network exploitation, cloud attack paths (AWS/GCP), web/API exploitation, custom C2 development, social engineering/physical, mobile
  • You can write your own tooling and implants in Python, Go, or Rust
  • You've operated against modern EDR-instrumented environments
  • You understand blast radius in a regulated fintech
  • You can write a report that gets fixed

Desired Qualifications

  • OSCE, OSEP, OSED, CRTO or equivalent adversary simulation cert gets you a real look

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce