Principal Security Operation Engineer
Job description
About the role
You will architect and execute red-blue confrontation drills that simulate advanced persistent threat campaigns against enterprise networks, applications, cloud environments, work networks, and core business systems. You will own the full lifecycle of attack simulation, designing realistic extranet breakthroughs, web vulnerability exploitation, phishing entrances, privilege escalation, lateral movement, data discovery, privilege maintenance, and defense bypass scenarios. You will lead or actively participate in exercises that evaluate detection, alarm analysis, traceability, emergency response, and recovery capabilities across distributed teams. Based on the outcomes of each engagement, you will drive the continuous optimization of security detection rules, response processes, asset governance, and security baselines. You will collaborate closely with engineering and operations partners to embed security into delivery workflows and harden the overall security posture. Your work will directly strengthen Bybit's resilience against real-world threats and support the protection of over 80 million users.
Key facts
What you'll do
Design and execute penetration testing, red-blue confrontation, and practical attack and defense drills that mirror realistic adversary behavior across enterprise networks, applications, cloud environments, work networks, and core business systems.
Lead or participate in red-blue confrontation exercises that assess the defense team's capability in attack detection, alarm analysis, traceability analysis, emergency response, and recovery.
Develop exercise scenarios based on real attack chains, covering extranet breakthrough, web vulnerability exploitation, phishing entrance, privilege escalation, lateral movement, data discovery, privilege maintenance, and defense bypass stages.
Construct high-fidelity attack simulations that stress detection engineering, monitoring coverage, and incident response playbooks in live and isolated environments.
Analyze exercise telemetry to identify gaps in visibility, alert fidelity, and response timelines, translating findings into concrete remediation actions.
Drive the continuous optimization of security detection rules, response processes, asset inventories, and security baselines based on empirical attack and defense evidence.
Coordinate with cross-functional stakeholders to integrate security validation into delivery pipelines, ensuring that hardening measures keep pace with rapid feature development.
Champion threat-informed defense by mapping adversary techniques to existing controls and validating the effectiveness of preventive and detective measures.
Maintain and evolve exercise toolkits, including custom payloads, emulation scripts, and instrumentation, to support evolving threat scenarios and testing objectives.
Act as a subject matter expert for security operations, providing guidance, mentorship, and technical leadership to internal teams on advanced threat detection and mitigation.
Requirements
Demonstrate hands-on experience in penetration testing, red team operations, or red-blue confrontation exercises across enterprise-scale environments.
Show proven ability to design and run realistic attack simulations that span extranet compromise, web exploitation, phishing, privilege escalation, lateral movement, data discovery, and defense bypass.
Possess deep knowledge of security detection mechanisms, SIEM platforms, alert analysis, traceability methodologies, and incident response lifecycle practices.
Hold strong technical skills in offensive security tools, scripting, and automation to build and execute complex attack chains safely and responsibly.
Have a track record of improving security controls through data-driven findings from attack and defense testing, including rule optimization and process refinement.
Exhibit meticulous attention to detail, rigorous documentation practices, and the ability to communicate technical findings to both technical and executive audiences.
Commit to operating within a fast-moving, high-performance environment while adhering to strict security standards and governance requirements.
Demonstrate ownership of security outcomes by proactively identifying risks, coordinating remediation, and validating the effectiveness of implemented fixes.
Maintain strict professionalism and integrity when handling sensitive findings, operational data, and confidential information.
Nice to have
Experience contributing to threat-informed defense programs and security control validation against adversarial tactics and techniques.
Familiarity with blockchain, digital asset custody, and exchange infrastructure threat models, though not required for this role.
Practical notes
This role operates from offices in Hong Kong SAR and Kuala Lumpur, Malaysia. No travel is specified in the source, and no visa information or application deadlines are provided.