Senior Offensive Security Engineer
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 6+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are recruiting a Senior Offensive Security Engineer to proactively eliminate threats before they become incidents. This role requires a mindset aligned with adversaries rather than auditors and demands hands-on leadership in offensive security operations over a vast infrastructure, applications, cloud environments, and human elements. The objective is not merely to prove vulnerability but to enhance platform intelligence through every simulated attack.
Company Mission Context
Deriv aims to enable trading for anyone, anywhere, and anytime, supporting millions of traders globally, across multiple regulatory frameworks. Given the platform operates continuously handling vast transactional volume, any security loophole can compromise trader funds and invite regulatory scrutiny.
Security Environment
Unlike conventional perimeter defense, the role involves protection of a distributed, live system processing transactions nonstop. This necessitates embedding advanced AI and automation across security layers for effective detection and response.
Challenges Presented
With a monthly transaction volume of $600 billion, the platform attracts sophisticated threat actors including state-sponsored and financially motivated adversaries. The environment is real, high-pressure, and demands rigorous, end-to-end adversary simulation without shortcuts or superficial testing.
Responsibilities
- Lead comprehensive red team engagements covering initial access, privilege escalation, lateral movement, persistence, and objectives aligned with the MITRE ATT&CK framework.
- Design and execute social engineering and physical/insider threat simulations founded on practical tactics, techniques, and procedures.
- Identify vulnerabilities and escalate privileges across cloud platforms (AWS, GCP), Kubernetes, and CI/CD pipelines prior to external exploitation.
- Perform application-level security evaluations including source code analysis and exploitation within trading, payments, and internal platforms.
- Red team AI-related technologies focusing on prompt injections, abuse of tool-calling, trust boundary breaches between agents, and credential exposures.
- Create and maintain innovative offensive security tooling, command and control infrastructure, and stealth payloads that defeat modern detection solutions.
- Produce detailed engagement reports and executive-level summaries that drive actual remediation efforts.
- Collaborate with SOC and Threat Hunting teams to conduct purple-team exercises aimed at closing observable detection gaps.
- Mentor junior security operators and contribute strategically to the development roadmap of offensive security capabilities.
Candidate Profile
- Minimum six years’ experience in extensive offensive security operations, including comprehensive red team exercises rather than isolated penetration tests.
- Must hold the OSCP certification; additional recognized adversary simulation qualifications (OSCE, OSEP, OSED, CRTO, or equivalent) provide a competitive advantage.
- Demonstrated expertise in at least three of these domains: internal Active Directory/network exploitation, cloud attack pathways (AWS/GCP), web/API exploitation, custom command and control development, social engineering/physical security, or mobile security.
- Proficient in developing custom tools and implants using programming languages such as Python, Go, or Rust, beyond default commercial toolkits like Cobalt Strike.
- Experience operating in environments monitored by modern endpoint detection and response systems with effective evasion techniques.
- An understanding of operational impact in a regulated fintech environment enabling controlled disruption without compromising business stability.
- Exceptional reporting skills that foster remediation rather than mere documentation.
Additional Insights
The position sits within a Security & AI Engineering unit that values offensive security as an enduring technical discipline, working globally with teams in Dubai and Malaysia. The successful candidate will have direct influence on closing vulnerabilities and shaping the offensive security approach towards emerging AI agent threats.
Level
Senior
Industry
FinTech