About the Role
We are seeking a Senior Manager to lead our Cyber Offense / Red Team function. This role drives advanced adversarial simulations, provides independent oversight of Technology Information Services (SOC, DFIR, Threat Hunting, VM), and strengthens the organisation's offensive security capabilities in alignment with regulatory requirements (BNM RMiT, Labuan FSA, PayNet) and the Group CISO's cyber risk strategy.
Key Responsibilities
- Lead and execute Red Team campaigns using threat‑modelling and MITRE ATT&CK frameworks.
- Design, research, and perform real‑world attack simulations across infrastructure, applications, and services.
- Incorporate latest threat intelligence, advisories, and research into offensive testing.
- Develop or customise exploits and payloads to evaluate and bypass existing security controls.
- Produce clear and comprehensive Red Team reports with technical and business‑aligned recommendations.
- Work with stakeholders to strengthen defences, improve detection capability, and reduce exposure.
- Conduct targeted testing during security incidents, intelligence alerts, or regulator notifications.
- Perform OSINT-based threat hunting to identify leaked credentials, sensitive data exposure, and external risks.
- Provide offensive security insights to the Group VP, CISO, senior management, and Board.
Requirements
- Bachelor's degree in IT, Cybersecurity, Computer Science, or related field.
- Minimum 5 years experience in cybersecurity, offensive security (VAPT/Red Team), security operations, or threat hunting.
- Strong hands‑on skills in:
- C2 frameworks (e.g., Cobalt Strike)
- EDR/NDR/DLP/WAF evasion techniques
- Custom exploit/payload development
- Unix/Linux/Windows/Mac OS, bash & PowerShell
- Strong knowledge of attacker TTPs, Cyber Kill Chain, DevSecOps, and offensive tools.
- Experience leading offensive security or simulated attack teams.
- Experience with OSINT collection and analysis.
- Excellent reporting and communication skills.
- Highly desirable certifications: OSCP, OSCE, GPEN, GXPN, CRTO, CREST CCSAM, etc.