Offensive Security Engineer

Vancouver, Canada

BitMEX logo
BitMEX
Trade Bitcoin and other cryptocurrencies with up to 100x leverage. Fast execution, low fees, Bitcoin futures and swaps: available only on BitMEX.
Apply now Apply later

BitMEX is the world’s leading cryptocurrency derivatives trading platform, which has pioneered cryptocurrency trading through relentless commitment to change, and continues to set benchmarks for innovation, liquidity, and security today.

As the world's most advanced peer-to-peer crypto-products trading platform and API, BitMEX gives knowledge, confidence, and precision to hundreds of thousands of traders, transacting billions of USD a day.

Role Overview

The goal of an Offensive Security Engineer is to proactively identify and help mitigate technical risk across all BitMEX systems, people, and processes. They will achieve this through a combination of penetration testing, adversary simulation, red/purple teaming, ongoing vulnerability assessment activities and tools development while working closely alongside the Detection & Response, AppSec and Infrastructure Security teams.

Responsibilities

  • Discover vulnerabilities in BitMEX Corporate infrastructure before a malicious external actor does.
  • Discover vulnerabilities in BitMEX Production infrastructure before a malicious external actor does.
  • Discover vulnerabilities in BitMEX Physical (office, badging) infrastructure before a malicious external actor does.
  • Discover vulnerabilities in BitMEX Executive infrastructure (homes, private/home offices) before a malicious external actor does.

Qualifications

  • 5+ years of experience in security testing, vulnerability and/or red team assessment at a top tech or finance company.
  • Experience performing physical penetration tests.
  • Experience performing “Purple Team” exercises using the Mitre ATT&CK Framework.
  • Strong software development skills in Python, Golang, NodeJS, Ruby, C, C++, or similar.
  • Deep knowledge of Amazon Web Services, GCP, and general Cloud infrastructure security.
  • Deep understanding of DevOps/CICD environments, attack vectors and mitigating controls. Familiarity with Docker/Kubernetes.
  • Comfortable operating across a wide variety of platforms, operating systems, and technologies.
  • Ability to work collaboratively and cross functionally with the other security teams.

Join us, as we build a thriving cryptocurrency ecosystem through strategic investments in emerging cryptocurrency technology, and create the future of digital financial services.

Job region(s): North America
Job stats:  11  0  0
  • Share this job via
  • or

Explore more Information Security career opportunities