inhousefyi
← Back to listings

Principal Security Operation Engineer (Red Team)

BybitHong Kong, Hong Kong · Posted 25 days ago
Full-time
Apply now

Description

About Us

Established in 2018, Bybit is one of the world’s leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Powered by world-class technology and a user-first mindset, Bybit delivers a seamless ecosystem across trading, payments, wealth management, custody, institutional services, and Web3 — connecting users to the future of digital finance.
Our core values define how we build. We listen, care and improve to create products and experiences that put users first. Backed by a global team of ambitious builders, problem-solvers, and innovators, we foster a high-performance and fast-moving environment where talent is empowered to drive real impact at the global scale. Supported by 24/7 multilingual customer service and a strong commitment to innovation, we are shaping the future of finance through technology, collaboration, and bold execution.
Today, Bybit is recognized as one of the most trusted and transparent platforms in the digital asset industry, continuing to expand its global presence while building the infrastructure for the next generation of financial services.
Job responsibilities
Red-blue confrontation drill
  • Responsible for developing and executing penetration testing, red-blue confrontation, and practical attack and defense drills that simulate real attack scenarios, identifying potential security risks in enterprise networks, applications, cloud environments, work networks, and core business systems.
  • Lead or participate in red-blue confrontation exercises to evaluate the defense team's ability in attack detection, alarm analysis, traceability analysis, emergency response, and recovery.
  • Based on the real attack chain design exercise scenario, covering extranet breakthrough, web vulnerability exploitation, phishing entrance, privilege escalation, lateral movement, Data Discovery, privilege maintenance, and defense bypass stages.
  • Combining the attack review results, promote the continuous optimization of security detection rules, response processes, asset governance, and security base lines.
Attack Surface Analysis and Threat Research
  • Identify enterprise network exposure, internet assets, cloud assets, APIs, supply chain components, and third-party access risks, evaluate attack paths, and provide mitigation recommendations.
  • Monitor and collect threat intelligence, track vulnerability exploitation trends, APT attack methods, red team toolchain changes, and apply them to enterprise attack and defense exercises.
  • Combining business scenarios to model attack paths and discover feasible attack chains from external exposure surfaces to core assets.
  • Tracking AI-related security risks, including security issues in large-scale model applications, RAG systems, Agent systems, plug-in/tool calls, MCP services, AI code generation, and automated workflows.
AI Security and Large Model Attack and Defense
  • Responsible for the security evaluation of AI applications, intelligent agent systems, RAG Knowledge Base, AI Agent toolchain and model services within the enterprise.
  • Research and verify large-scale model-related attack techniques, including Prompt Injection, Jailbreak, Indirect Prompt Injection, data leakage, unauthorized tool invocation, security risks caused by model illusions, RAG poisoning, vector library pollution, sensitive information leakage, etc.
  • Design AI red team test cases and evaluation framework, and conduct security verification on model input and output, context isolation, permission control, tool call chain, and data access boundary.
  • Participate in the construction of AI security protection plan, including prompt word security policy, content security detection, tool call permission constraints, sensitive data desensitization, audit tracking, Agent sandbox isolation and security evaluation benchmark construction.
  • Explore the application of AI in red team automation, vulnerability analysis, attack path planning, PoC verification, and report generation, and promote the platformization, automation, and intelligence of attack and defense capabilities.
Tool and platform development
  • Develop and optimize Red Team-specific tools and scripts for vulnerability mining, information collection, privilege escalation, lateral movement, credential analysis, traffic disguise, defense bypass, and automated report generation.
  • Study and validate new attack techniques, and simulate real threats in combination with enterprise business scenarios.
  • Build or participate in the construction of automated security evaluation platform, integrated vulnerability scanning, audio fingerprint recognition, asset mapping, PoC verification, attack path analysis, AI Agent arrangement and other capabilities.
  • Combining LLM/Agent technology to explore automated penetration testing, intelligent vulnerability verification, code security auditing, and red team task scheduling.
Security evaluation and reporting
  • Conduct security evaluations on critical business systems, internal networks, cloud environments, work end points, API services, and AI applications, and output detailed technical reports, attack paths, impact analysis, and repair recommendations.
  • Output AI security evaluation reports for AI applications, including attack examples, risk levels, exploitable paths, data leakage risks, permission boundary issues, and governance recommendations.
  • Assist in improving enterprise security protection mechanisms, promote optimization of WAF, EDR, SIEM, NDR, HIDS, zero trust, identity permissions, and log auditing capabilities.
  • Transform attack and defense discovery into security detection rules, base line specifications, develop security requirements, and continuous governance mechanisms.
XFN collaboration
  • Collaborate with the blue team, security operation, infrastructure, R & D, algorithm, data, and business teams to complete attack review, vulnerability repair, detection rule optimization, and security capability building.
  • Provide security support to other departments of the enterprise, including emergency response drills, development security consulting, AI application pre-launch security review, and security training.
  • Participate in the security design review of AI applications and security products, and promote the advance of security capabilities in R & D, testing, and Pushonline.
Job requirements
Basic skills
  • Proficient in basic knowledge of cyber security, including TCP/IP protocol, network architecture, identity authentication, access control, principles and configurations of common security devices.
  • Proficient in common attack techniques and red team toolchains, such as Sliver, Cobalt Strike, NPS, Burp Suite, Metasploit, Nmap, Masscan, Frida, Impacket, etc.
  • Familiar with mainstream operating systems Windows, Linux, macOS security mechanism, log system, permission model and common use.
  • Familiar with common web frameworks, API architectures, microservice structures, containers, and security risks in Kubernetes environments.
Offensive and defensive technical capabilities
  • Proficient in penetration testing and red team processes, including information collection, vulnerability scanning, vulnerability exploitation, intranet penetration, privilege escalation, lateral movement, privilege maintenance, Data Discovery, and trace cleaning.
  • Familiar with the working principles and adversarial methods of enterprise-level security products, including WAF, EDR, SIEM, NDR, HIDS, zero-trust gateway, bastion host, and identity authentication system.
  • Possess independent vulnerability analysis and PoC writing capabilities, able to reproduce, verify, and assess the impact of public vulnerabilities and 0day/1day risks.
  • Proficient in one or more programming/scripting languages, such as Python, Go, Bash, PowerShell, JavaScript, etc., with experience in tool development and automation platform construction.
AI security capabilities
  • Familiar with the basic architecture of large-scale model applications, familiar with technical forms such as Prompt, RAG, Embedding, vector databases, Agent, Function Calling, MCP, and plugin systems.
  • Understand or practice AI security testing methods, including Prompt Injection, Jailbreak, RAG data poisoning, sensitive information leakage, unauthorized tool invocation, model output security, Agent permission escape, etc.
  • Able to design security test cases for AI applications, evaluate model input/output, context isolation, data boundaries, permission control, and tool invocation chain risks.
  • Experience in using AI to assist security work, including vulnerability analysis, code auditing, intelligence analysis, attack path planning, report generation, or automated testing.
  • Familiar with AI application security governance ideas, including model call auditing, prompt word security, sensitive data protection, content security detection, permission minimization, and sandbox isolation.
Experience requirements
  • More than 5 years of experience in red team, penetration tes

Similar jobs

BDAWoodinville, Washington, United States

Est. 120,000 USD

Most companies claim to have the best people. We say to them, "Keep dreaming." Our people are second to none. They set us apart with their entrepreneurial spirit and ambition. They come to us from the likes of Amazon, Mi…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
GovTechSingapore, Singapore

The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (…

Full-time
NebiusIsrael

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…

Full-time
VaricentToronto, Ontario, Canada

At Varicent, we’re not just transforming the Sales Performance Management (SPM) market—we’re redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to desig…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
GovTechSingapore, Singapore

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the…

Full-time
Yondr GroupDallas, Texas, United States

Est. 120,000 USD

About Yondr Yondr is a disruptor. We challenge convention and simplify complexity. A global developer, owner operator and service provider of data centers, we deliver complex data center capacity needs for the world’s la…

Full-time
The Nuclear CompanyWashington, District of Columbia, United States

Est. 140,000 USD

The Nuclear Company is the fastest growing AI tech-enabled startup in the nuclear and energy space, pioneering a fleet-scale approach to building the next generation of nuclear reactors. Through our design-once, build-ma…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
PubMaticRedwood City, California, United States

Est. 250,000 USD

About the Role: PubMatic is seeking a Director of Information Security to lead and evolve our global security program across enterprise infrastructure, cloud platforms, products, corporate systems, and emerging AI techno…

Full-time
TruvetaHyderabad, India

Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough med…

Full-time
DevSecOps Engineer11 months ago
ValtechRemote

Why Valtech? We’re the experience innovation company - a trusted partner to the world’s most recognized brands. To our people we offer growth opportunities, a values-driven culture, international careers and the chance t…

Full-timeRemote
CHAOS IndustriesSan Francisco, California, United States

Est. 144,000 USD

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warf…

Full-time
CHAOS IndustriesEl Segundo, California, United States

Est. 144,000 USD

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warf…

Full-time
CHAOS IndustriesWashington, District of Columbia, United States

Est. 144,000 USD

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warf…

Full-time
NebiusTel Aviv, Israel

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to…

Full-time
Cato NetworksWarsaw, Masovian Voivodeship, Poland

Est. 120,000 PLN

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
Cato NetworksAmsterdam, North Holland, Netherlands

Est. 90,000 EUR

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
Cato NetworksTel Aviv, Tel Aviv District, Israel

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
CHAOS IndustriesWashington, District of Columbia, United States

Est. 120,000 USD

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warf…

Full-time
CisionRemote

Est. 80,000 EUR

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thriv…

Full-timeRemote
CHAOS IndustriesLondon, England, United Kingdom

Est. 65,000 GBP

CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warf…

Full-time
GovTechSingapore, Singapore

GovTech supports various Government Agencies in carrying out ICT delivery services and appoints Agency Chief Information Security Officers (ACISO) to oversee information security management within these agencies. The ACI…

Full-time
Cato NetworksTel Aviv, Tel Aviv District, Israel

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
Toshiba Global Commerce Solutions - ExternalFrisco, Texas, United States

Est. 144,000 USD

Toshiba Global Commerce Solutions is seeking a hands-on Lead Software Engineer to drive end-to-end solution delivery for major retail platforms. In this role, you will own hands-on implementation (feature development, te…

Full-time
Cato NetworksLondon, England, United Kingdom

Est. 80,000 GBP

Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by n…

Full-time
HelsingWashington, District of Columbia, United States

Est. 144,000 USD

Who we are Helsing develops artificial intelligence-enabled capabilities to protect and defend democracies. We build Altra, an AI-powered drone software platform, and HX-2, our autonomous drone. We are growing our US ope…

Full-time
Anduril IndustriesWaltham, Massachusetts, United States

Est. 124,000 USD

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century…

Full-time
Anduril IndustriesBroomfield, Colorado, United States

Est. 124,000 USD

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century…

Full-time