Red Team Engineer, Security Assurance
Singapore
ByteDance
ByteDance is a technology company operating a range of content platforms that inform, educate, entertain and inspire people across languages, cultures and geographies.Responsibilities
About the Company
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Why Join Us
Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible.
Together, we inspire creativity and enrich life - a mission we aim towards achieving every day.
To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve.
Join us.
About the Team
The Security Assurance Team is researching offensive and defensive technology and skills to continuously improve the company's fundamental security, data security, and business security levels. We strive to minimize the impact of 0-day vulnerabilities and incidents. Our team provides a range of security services, including SDLC, vulnerability management, extreme critical risks discovery, supply chain security, network defense, red teaming, underground market crackdown, threat detection, emergency response, threat intelligence, and information security investigation.
Job Responsibilities
- Propose, plan, and execute Red Team Operations to determine if infrastructure components, systems and applications meet confidentiality, integrity, authentication, availability, authorisation, and nonrepudiation standards based on realistic threats to the organization.
- Maintain a deep understanding of ByteDance Enterprise Products, how they work, and how they could be attacked or abused.
- Conducts security exercises that emulate real-world threats, TTPs that are most relevant to our organization.
- Translate requirements into test plan, write and execute test scripts or codes in line with standards and procedures to determine vulnerability to attacks.
- Certify infrastructure components, systems and applications that meet security standards.
- Write detailed reports covering the goals and outcomes of Red Team operations, including significant observations and recommendations.
- Collaborate across multiple defense/product teams to propose enhancements and improve current security offerings.
Qualifications
Minimum Qualifications
- Background in Computer Science, Computer Engineering, Information Systems or other STEM disciplines.
Strong knowledge in some of these various disciplines: red team operations, infrastructure security, MITRE, TTPs.
- An adversarial mindset to emulate a real-world attacker.
- Excellent and professional communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
Preferred Requirements
- Red Team Experience in an enterprise environment.
- CTF players, live competitions and hacking events experience.
- CVEs (excluding vulnerabilities such as XSS, CSRF in random CMS) are preferred.
- BugBounty experience with reputable statistics in HackerOne, BugCrowd etc.
ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Computer Science CSRF CTF Red team SDLC STEM Threat detection Threat intelligence TTPs Vulnerabilities Vulnerability management XSS Zero-day
Perks/benefits: Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.