Offensive Security Engineer

  • 100x Group
  • San Francisco
  • May 17, 2021
Full time Engineering Security & Privacy

Job Description

The Company

100x Group is the result of the phenomenal success of BitMEX, the world’s leading cryptocurrency derivatives trading platform, which has pioneered cryptocurrency trading through relentless commitment to change, and continues to set benchmarks for innovation, liquidity, and security today. The BitMEX trading platform represents the cornerstone of 100x. As the world's most advanced peer-to-peer crypto-products trading platform and API, BitMEX gives knowledge, confidence, and precision to hundreds of thousands of traders, transacting billions of USD per day.

Join us, as we build a thriving cryptocurrency ecosystem of 100x Group companies, through strategic investments in emerging cryptocurrency technology, and create the future of digital financial services.

Purpose of This Job:

The goal of an Offensive Security Engineer is to proactively identify and help mitigate technical risk across all BitMEX systems, people, and processes. They will achieve this through a combination of penetration testing, adversary simulation, red/purple teaming, ongoing vulnerability assessment activities and tools development while working closely alongside the Detection & Response, AppSec and Infrastructure Security teams.

Key Responsibilities:

  • Discover vulnerabilities in BitMEX Corporate infrastructure before a malicious external actor does.

  • Discover vulnerabilities in BitMEX Production infrastructure before a malicious external actor does.

  • Discover vulnerabilities in BitMEX Physical (office, badging, ..) infrastructure before a malicious external actor does.

  • Discover vulnerabilities in BitMEX Executive infrastructure (homes, private/home offices) before a malicious external actor does.

Qualifications:

  • 5+ years of experience in security testing, vulnerability and/or red team assessment at a top tech or finance company.

  • Experience performing physical penetration tests.

  • Experience performing “Purple Team” exercises using the Mitre ATT&CK Framework.

  • Strong software development skills in Python, Golang, NodeJS, Ruby, C, C++, or similar.

  • Deep knowledge of Amazon Web Services, GCP, and general Cloud infrastructure security.

  • Deep understanding of DevOps/CICD environments, attack vectors and mitigating controls. Familiarity with Docker/Kubernetes.

  • Comfortable operating across a wide variety of platforms, operating systems, and technologies.

  • Ability to work collaboratively and cross functionally with the other security teams.

  • Ability to travel to our Hong Kong office on a quarterly basis.