工作描述
7 天前
⭐ Key Responsibilities
Plan, execute, and report Red Team operations , including adversary simulation, attack path mapping, and exploitation.
Perform full‑scope penetration testing (infrastructure, AD, cloud, web/mobile applications).
Develop and execute custom attack scenarios aligned to MITRE ATT&CK frameworks.
Identify vulnerabilities and provide actionable remediation guidance to technology and business stakeholders.
Conduct phishing, social engineering, and lateral movement testing across enterprise environments.
Produce professional reports for cybersecurity leadership and regulatory reviews.
Stay current with emerging exploits, TTPs, and offensive tooling.
Requirements
4 – 8 years of hands‑on experience in offensive security / red teaming / pentesting .
Strong knowledge of exploitation techniques, AD attack paths, privilege escalation, lateral movement, and evasion.
Solid experience with offensive frameworks/tools such as:
Cobalt Strike, Metasploit, Empire, Havoc, Sliver, BloodHound, Impacket, Burp Suite, etc.
Hands‑on experience with Active Directory security , Windows/Linux exploitation, and cloud (Azure/AWS) attack simulation preferred.
Professional certifications are highly advantageous:
OSCP, OSEP, OSWE, OSCE3, CRTP, CRTE, CREST CRT/CPSA , or similar.
Experience in banking, fintech, or regulated environments (HKMA, GL20, C‑RAF) is a plus.
Strong communication skills in English ; Cantonese/Mandarin an advantage.
Full-time
Plan, execute, and report Red Team operations , including adversary simulation, attack path mapping, and exploitation.
Perform full‑scope penetration testing (infrastructure, AD, cloud, web/mobile applications).
Develop and execute custom attack scenarios aligned to MITRE ATT&CK frameworks.
Identify vulnerabilities and provide actionable remediation guidance to technology and business stakeholders.
Conduct phishing, social engineering, and lateral movement testing across enterprise environments.
Produce professional reports for cybersecurity leadership and regulatory reviews.
Stay current with emerging exploits, TTPs, and offensive tooling.
Requirements
4 – 8 years of hands‑on experience in offensive security / red teaming / pentesting .
Strong knowledge of exploitation techniques, AD attack paths, privilege escalation, lateral movement, and evasion.
Solid experience with offensive frameworks/tools such as:
Cobalt Strike, Metasploit, Empire, Havoc, Sliver, BloodHound, Impacket, Burp Suite, etc.
Hands‑on experience with Active Directory security , Windows/Linux exploitation, and cloud (Azure/AWS) attack simulation preferred.
Professional certifications are highly advantageous:
OSCP, OSEP, OSWE, OSCE3, CRTP, CRTE, CREST CRT/CPSA , or similar.
Experience in banking, fintech, or regulated environments (HKMA, GL20, C‑RAF) is a plus.
Strong communication skills in English ; Cantonese/Mandarin an advantage.
Full-time
更多來自 Venturenix Limited

Cybersecurity IAM Specialist (Access Management)
Venturenix Limited
網絡安全
中西區, 香港
7 天前
全職
辦公室工作
專業服務

Cloud Engineer / Cloud Architect
Venturenix Limited
網絡和系統管理
中西區, 香港
7 天前
全職
辦公室工作
專業服務

RPA Developer | Leading Financial Institution | 35-50K
Venturenix Limited
軟件工程師
中西區, 香港
7 天前
全職
辦公室工作
專業服務

Technical Specialist, Cybersecurity (PAM)
Venturenix Limited
網絡安全
中西區, 香港
7 天前
全職
辦公室工作
專業服務

IT Manager / Head of IT (Team 4) | Salesforce experience preferred | HKD 50K - 70K / mth | Leading NGO
Venturenix Limited
jobBoard.filter.role.option.ERP_CRM
中西區, 香港
7 天前
全職
辦公室工作
專業服務
更多相似工作
🎉 Got an interview?







