At blubank, we are seeking talented, dynamic, and enthusiastic individuals for the position of Red Team Tech Lead to join our friendly and professional team. If you’re looking for a workplace where you can grow and continuously learn, this opportunity is for you!
Responsibilities:
- Conduct real-world attack simulations (network, cloud, web apps, physical, social engineering) using TTPs (Tactics, Techniques, Procedures) aligned with MITRE ATT&CK.
- Emulate advanced threat actors (APT groups, ransomware operators) to test detection and response capabilities.
- Exploit vulnerabilities in cloud environments and hybrid infrastructure.
- Work with Blue Teams to validate defenses, refine detection rules (SIEM/SOAR), and improve incident response playbooks.
- Provide actionable feedback to defenders after engagements (e.g., "EDR missed this lateral movement technique").
- Deliver clear, prioritized reports detailing exploitation paths, business impact, and remediation steps.
- Research and document novel attack techniques (e.g., AI-assisted phishing, cloud privilege escalation).
Qualifications:
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field
- +5 years of experience in information security
- Strong teamwork and communication skills across technical and non-technical teams
- Hands-on experience with MITRE ATT&CK and BAS tools
- Familiar with advanced AD attacks, defense evasion, and OPSEC techniques
- Knowledge of EDR bypass methods (C, C#, or Rust preferred)
- Experience with cloud security attacks (Kubernetes, containers, IAM)
- Skilled in web and network pentesting
- Ability to lead red/purple team operations and write detection rules
- Strong reporting and critical thinking abilities
- Familiar with scripting (Python is a plus)
- Nice to know: advanced initial access techniques beyond social engineering
- Excellent project/time management and adaptability in dynamic environments
Benefits:
- Work-from-home option
- Flexible working hours
- Training courses and professional development opportunities
- Military service project (Limited)
- Supplemental health insurance
- Team-building budget
- Performance-based bonuses
- Loans
- Lunch subsidies