Senior Offensive Security Engineer
On-siteCyberjaya, Selangor, Malaysia
Job Summary
Execute full-kill-chain red team engagements across cloud, Kubernetes, CI/CD, and AI agent stacks, mapping attacks to MITRE ATT&CK. Design social engineering and physical/insider simulations, then conduct source code analysis and application-layer exploitation against trading and payment platforms. Build custom tooling, C2 infrastructure, and payloads to evade modern detection stacks while red-teaming AI agent trust boundaries. Partner with SOC and Threat Hunting to run purple-team exercises that close detection gaps, and mentor L1/L2 operators. Write engagement reports that drive actual remediation. Operate within a Security & AI Engineering org in Dubai and Malaysia, directly influencing how we red-team AI agents and shape offensive security capabilities.
Required Qualifications
- 6+ years doing actual offensive security
- Full-scope red team
- OSCP required
- OSCE, OSEP, OSED, CRTO or equivalent adversary simulation cert
- Real depth in at least three of: internal AD/network exploitation, cloud attack paths (AWS/GCP), web/API exploitation, custom C2 development, social engineering/physical, mobile
- You can write your own tooling and implants in Python, Go, or Rust
- You've operated against modern EDR-instrumented environments
- You understand blast radius in a regulated fintech
- You can write a report that gets fixed
Desired Qualifications
- OSCE, OSEP, OSED, CRTO or equivalent adversary simulation cert gets you a real look
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.