Job Description:
On behalf of a top-tier, global, consulting firm we are interested in speaking with experienced cyber security professionals who have hands on experience with both red-team and blue-team exercises. This is a team leadership role with significant career and professional growth potential, including ongoing learning support and the Opportunity to attend overseas Cyber Security Events.
Role:
- Lead cyber-attack simulation projects using red team / blue team / purple team exercises.
- Conduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware / ransomware.
- Lead advanced security assessment and infrastructure penetration tests across multiple, complex, platforms.
- Develop client proposals, project scoping, and project reviews.
- Drive continuous improvement in security assessment methodologies.
- Mentor and develop team members and drive team growth.
- Lead business development activities by building propositions, identifying new target clients, building business relationships and representing the company at industry events and conferences.
Requirements:
- At least one professional qualification required: CREST Certified Simulated Attack Manager, GXPN, OSCE3, OSEE or other relevant, recognized. Qualification(s).
- Experience working in Red Teaming, Purple Teaming, simulation attack, iCAST, Web/Mobile/Network/OT/IoT/other Penetration Tests, Vulnerability Assessment, Source Code Review, Appliance/System/Cloud Configuration Review, Malware development, Social Engineering.
- Knowledge of threat intelligence, reverse engineering, security products, incident response, SOC operation or other related areas will be an advantage.
- Experience with enterprise technologies and operations, enterprise networking, internet application security, database security evaluation and architectures.
- Team leadership experience is preferred.
- Excellent English language (oral and written) with the ability to present ideas and results to technical and non-technical audiences. Business level, or above in Cantonese and/or Mandarin is very much preferred.
- Degree in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline.