工作描述
7 天前
⭐ Key Responsibilities
Plan, execute, and report Red Team operations , including adversary simulation, attack path mapping, and exploitation.
Perform full‑scope penetration testing (infrastructure, AD, cloud, web/mobile applications).
Develop and execute custom attack scenarios aligned to MITRE ATT&CK frameworks.
Identify vulnerabilities and provide actionable remediation guidance to technology and business stakeholders.
Conduct phishing, social engineering, and lateral movement testing across enterprise environments.
Produce professional reports for cybersecurity leadership and regulatory reviews.
Stay current with emerging exploits, TTPs, and offensive tooling.
Requirements
4 – 8 years of hands‑on experience in offensive security / red teaming / pentesting .
Strong knowledge of exploitation techniques, AD attack paths, privilege escalation, lateral movement, and evasion.
Solid experience with offensive frameworks/tools such as:
Cobalt Strike, Metasploit, Empire, Havoc, Sliver, BloodHound, Impacket, Burp Suite, etc.
Hands‑on experience with Active Directory security , Windows/Linux exploitation, and cloud (Azure/AWS) attack simulation preferred.
Professional certifications are highly advantageous:
OSCP, OSEP, OSWE, OSCE3, CRTP, CRTE, CREST CRT/CPSA , or similar.
Experience in banking, fintech, or regulated environments (HKMA, GL20, C‑RAF) is a plus.
Strong communication skills in English ; Cantonese/Mandarin an advantage.
Full-time
Plan, execute, and report Red Team operations , including adversary simulation, attack path mapping, and exploitation.
Perform full‑scope penetration testing (infrastructure, AD, cloud, web/mobile applications).
Develop and execute custom attack scenarios aligned to MITRE ATT&CK frameworks.
Identify vulnerabilities and provide actionable remediation guidance to technology and business stakeholders.
Conduct phishing, social engineering, and lateral movement testing across enterprise environments.
Produce professional reports for cybersecurity leadership and regulatory reviews.
Stay current with emerging exploits, TTPs, and offensive tooling.
Requirements
4 – 8 years of hands‑on experience in offensive security / red teaming / pentesting .
Strong knowledge of exploitation techniques, AD attack paths, privilege escalation, lateral movement, and evasion.
Solid experience with offensive frameworks/tools such as:
Cobalt Strike, Metasploit, Empire, Havoc, Sliver, BloodHound, Impacket, Burp Suite, etc.
Hands‑on experience with Active Directory security , Windows/Linux exploitation, and cloud (Azure/AWS) attack simulation preferred.
Professional certifications are highly advantageous:
OSCP, OSEP, OSWE, OSCE3, CRTP, CRTE, CREST CRT/CPSA , or similar.
Experience in banking, fintech, or regulated environments (HKMA, GL20, C‑RAF) is a plus.
Strong communication skills in English ; Cantonese/Mandarin an advantage.
Full-time
更多来自 Venturenix Limited

Cybersecurity IAM Specialist (Access Management)
Venturenix Limited
网络安全
中西区, 香港
7 天前
全职
办公室工作
专业服务

Cloud Engineer / Cloud Architect
Venturenix Limited
网络和系统管理
中西区, 香港
7 天前
全职
办公室工作
专业服务

RPA Developer | Leading Financial Institution | 35-50K
Venturenix Limited
软件工程师
中西区, 香港
7 天前
全职
办公室工作
专业服务

Technical Specialist, Cybersecurity (PAM)
Venturenix Limited
网络安全
中西区, 香港
7 天前
全职
办公室工作
专业服务

IT Manager / Head of IT (Team 4) | Salesforce experience preferred | HKD 50K - 70K / mth | Leading NGO
Venturenix Limited
jobBoard.filter.role.option.ERP_CRM
中西区, 香港
7 天前
全职
办公室工作
专业服务
更多类似工作
🎉 Got an interview?







