Red Team Manager
Summary
CLP Group is hiring an in-house Red Team Manager in Hong Kong to scope and run red team exercises that test the company's cyber defences, develop custom offensive tooling and automation scripts, quality-assure technical reports, and brief senior leadership. Requires deep offensive security experience plus certifications such as OSCP and CRTO.
Working Location: Kai Tak, Kowloon, Hong Kong
Employment Duration: Permanent
The Red Team Manager is responsible for identifying and exploiting vulnerabilities in computer systems, applications, and networks. This role will work closely with various internal teams and security personnel to ensure that proper security measures are implemented throughout the organisation.
The primary focus of this role will be to help scope and perform Red Team exercises.
As such, it is expected that the successful candidate will possess Red Team skills and relevant experience.
Key Responsibilities
Assist to develop and execute a program of offensive campaigns (Red Team exercises) to test CLP’s cyber detective and protective controls.
Drive innovative thinking by researching, creating and testing new tools and techniques to identify vulnerabilities in the people, processes and technologies that CLP use.
Provide CLP with detailed reports that contain the necessary insight to support security fixes, patches, remediation, and training to ensure the same opportunities for exploitation do not exist in the future.
Perform quality assurance of technical reports (both Red Team and penetration testing reports).
Develop and execute custom scripts to automate and streamline testing procedures.
Work with development teams and security personnel to help prioritize and remediate identified vulnerabilities.
Stay current with emerging security threats, vulnerabilities, and share knowledge with other security team members.
Provide regular reports and assist with creating technical presentations for senior leadership.
Qualifications & Experience
Bachelor's degree in Computer Science, Information Technology, or a related field.
6-7 years of experience in scoping and executing Red Team exercises, penetration tests, and security tests.
Independent management experience covering penetration testing projects, including project planning, scoping, and quality assurance.
In-depth understanding of attacker TTPs (tactics, techniques, and procedures) and how these apply to Red Team exercises.
Strong understanding of network security, web application security, API security, cloud security, and mobile application security.
Experience performing EDR evasion, bespoke tool development, and associated research.
Experience reviewing Windows Active Directory security and cloud environments.
Knowledge of scripting languages such as Python, C/C++, .NET, or PowerShell.
Good command of spoken and written English.
Ability to explain technical issues to non-technical stakeholders.
Ability to work collaboratively with cross-functional teams.
Exhibit a high level of self-motivation and drive to achieve personal and team goals.
Actively shares technical knowledge and insights with team members to foster a collaborative environment.
Independent research experience performing vulnerability research and exploitation is a plus.
Embrace new ideas, approaches, and be willing to learn and adapt to evolving technologies.
Holding a relevant penetration testing certification such as OSCP, OSCE, OSEP, or OSCE3 is required.
Holding a Red Team certification (such as CRTO/CRTE/PACES) is required.