Skip to main content
Bybit

Principal Security Operation Engineer

Remote50 countries
Published
Role
Security
Experience
Principal
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to 50 countries. Set where you work from to check your eligibility.

No BS summary

Principal Security Operations Engineer, 5+ yrs experience in red team and penetration testing. Must have expertise in AI security and large-scale model applications. Remote in APAC, preferably based in Kuala Lumpur.

Required skills

TCP/IPPromptRAGEmbeddingVector databasesAgentFunction CallingMCPPlugin systemsPrompt InjectionJailbreakRAG data poisoningAWSAzureGCPTencent CloudAlibaba CloudKubernetesContainersService MeshCI/CDDevSecOpsMCP ServerAI Agent frameworkLLM API gatewayMITRE ATT&CKOWASP Top 10OWASP LLM Top 10NIST AI RMF

Optional skills

AWSAzureGCPTencent CloudAlibaba CloudKubernetesContainersService Mesh

What you'll do

  • Develop and execute penetration testing, red-blue confrontation, and attack and defense drills simulating real attack scenarios.
  • Lead or participate in red-blue confrontation exercises to evaluate detection, analysis, emergency response, and recovery capabilities.
  • Design attack-chain exercise scenarios covering external breakthrough, web exploitation, phishing, privilege escalation, lateral movement, data discovery, persistence, and defense bypass.
  • Promote optimization of security detection rules, response processes, asset governance, and security baselines.
  • Identify risks in enterprise networks, internet assets, cloud assets, APIs, supply chain components, and third-party access.
  • Monitor threat intelligence, vulnerability exploitation trends, APT methods, and red team toolchain changes.
  • Model attack paths from external exposure surfaces to core assets.
  • Track AI-related security risks in LLM applications, RAG systems, Agent systems, plugins, MCP services, AI code generation, and automated workflows.
  • Evaluate security of AI applications, intelligent agent systems, RAG knowledge bases, AI Agent toolchains, and model services.
  • Research and verify LLM attack techniques such as prompt injection, jailbreaks, indirect prompt injection, data leakage, unauthorized tool invocation, RAG poisoning, vector database pollution, and sensitive information leakage.
  • Design AI red team test cases and evaluation frameworks.
  • Build AI security protection plans including prompt security policy, content security detection, tool permission constraints, sensitive data desensitization, audit tracking, sandbox isolation, and benchmarks.
  • Develop and optimize red team tools and scripts for vulnerability mining, information collection, privilege escalation, lateral movement, credential analysis, traffic disguise, defense bypass, and report generation.
  • Build or contribute to automated security evaluation platforms with vulnerability scanning, asset mapping, PoC verification, attack path analysis, and AI Agent orchestration.
  • Conduct security evaluations of business systems, internal networks, cloud environments, endpoints, API services, and AI applications.
  • Produce technical and AI security evaluation reports with attack paths, impact analysis, and remediation recommendations.
  • Improve enterprise security mechanisms including WAF, EDR, SIEM, NDR, HIDS, zero trust, identity permissions, and log auditing.
  • Collaborate with blue team, security operations, infrastructure, R&D, algorithm, data, and business teams.
  • Provide emergency response drills, development security consulting, AI pre-launch security reviews, and security training.
  • Participate in security design reviews for AI applications and security products.

What they require

  • Proficient in basic cybersecurity knowledge including network architecture, identity authentication, access control, and common security device principles and configurations.
  • More than 5 years of experience in red team, penetration testing, security research, or offensive and defensive exercises.
  • Familiar with large-scale model application architecture.
  • Understand or have practiced AI security testing methods.
  • Able to design security test cases for AI applications and evaluate model input/output, context isolation, data boundaries, permission control, and tool invocation chain risks.
  • Experience using AI to assist security work such as vulnerability analysis, code auditing, intelligence analysis, attack path planning, report generation, or automated testing.
  • Familiar with AI application security governance ideas such as model call auditing, prompt security, sensitive data protection, content security detection, permission minimization, and sandbox isolation.
  • Experience in large-scale enterprise attack and defense drills, red-blue confrontation, major support, cloud attack and defense, or intranet penetration is preferred.
  • Experience in AI security, large-scale model security, intelligent agent security, automated penetration testing platform, or security tool platform construction is preferred.
  • Familiar with enterprise security construction systems and able to promote defense, detection, and governance optimization from an attack perspective.
  • Security-related certifications such as OSCP, OSCE, CISSP, CISP, CEH, or CCSP are preferred.
  • Strong document writing and communication abilities.
  • Good problem analysis ability, learning ability, teamwork ability, and stress resistance.
  • Sensitive to new technologies, new attack surfaces, and new tools, with ability to proactively research and share internally.
  • Experience in zero trust, secure operations, threat hunting, attack surface management, and vulnerability management platform construction is a bonus.
  • Experience in Automated Red Team, AI Penetration Testing, Intelligent Vulnerability Verification, Agent Orchestration, Security Knowledge Base, or Security RAG System construction is a bonus.
  • Experience in vulnerability submission, CVE, technical articles, open source projects, topic sharing, or tool release in the security community is a bonus.

Benefits

  • Study Growth Fund for professional development and continuous learning.
  • Internal events including team-building activities, workshops, and collaboration events.
  • Global collaboration with an international team.
  • Career advancement opportunities within a rapidly expanding global company.
  • Internal mobility opportunities.

Established in 2018, Bybit is one of the world’s leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Bybit delivers an ecosystem across trading, payments, wealth management, custody, institutional services, and Web3.

CryptoEnterprisebybit.com/en/

Details

Apply routeGreenhouse
Salary not disclosed