Security Engineer (Penetration Testing - Red Team)
All-in-one Philippine e-wallet and cryptocurrency exchange combining crypto trading with payments, bills, QR checkout, mobile load, and remittances.
Funding history
About Coins.ph
Coins.ph is a regulated digital-asset and payments platform operating under the Coins.ph brand. Its services include buying, selling, and holding cryptocurrency; peso wallets; bill payments; mobile load; QR payments; money transfers; and remittances. The current user agreement identifies Betur, Inc. and DCPay Philippines, Inc. as the entities doing business as coins.ph.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Conduct comprehensive penetration testing on company applications and systems, organize attack-defense drills, test blue-team defenses, research offensive and defensive technologies, introduce security tools, and build detection, monitoring, intrusion-traceability, and threat-informed countermeasure capabilities.
Requirements
- Possess more than 5 years of practical experience in attack and defense, and be able to independently complete penetration testing work
- Familiar with common internal network attack ideas and methods, with internal network penetration and domain penetration capabilities and successful cases
- Have practical experience in AWS cloud environment penetration, container and Kubernetes security attack and defense
- Familiar with Linux and Windows system principles, databases, command execution, and privilege escalation techniques
- Familiar with mainstream web frameworks and capable of code auditing and vulnerability mining in Java, Go, and Python
- Have practical experience in red and blue team exercises
- Be able to write scripts or tools for automated exploitation and basic tool development
Responsibilities
- Conduct comprehensive penetration testing on company applications and systems
- Organize regular attack-defense drills
- Test and bypass the defense technologies of the company's blue team to enhance the security protection level
- Research offensive and defensive technologies and track and analyze cutting-edge industry technologies
- Introduce excellent security technologies and tools
- Participate in the construction of security capabilities, including detection rules, monitoring strategies, and intrusion traceability
- Build and drill countermeasures and TTPs based on real threat intelligence and industry APT behavior models
