Cyber Security Specialist - Red Team
hace 5 días
Valencia
ppHBX Group is a leading independent B2B travel technology marketplace connecting travel businesses globally through advanced technology, data-driven solutions, and a network of interconnected products and services. Our Cyber Security team is responsible for protecting global platforms, cloud infrastructure, corporate environments, data assets, and emerging AI-enabled services. /p h3Role Overview /h3 pThe Red Team Security Expert is responsible for proactively assessing and validating HBX Group's security posture across corporate, cloud, application, and AI-enabled environments. /p pThe role combines penetration testing, adversary emulation, offensive security assessments, Purple Team activities, security research, and AI security testing. The successful candidate will work closely with Blue Team, Security Architecture, DevOps, Engineering, Data, and AI teams to identify weaknesses, validate security controls, and strengthen cyber resilience. /p h3Offensive Security Assessments /h3 ul liConduct penetration testing activities across web applications, APIs, cloud platforms, infrastructure services and corporate environments. /li liIdentify, validate and assess security vulnerabilities, attack paths and exposure risks affecting business services and technology platforms. /li liPerform security assessments throughout the technology lifecycle to support secure development and deployment practices. /li liCollaborate with engineering and infrastructure teams to ensure vulnerabilities are effectively remediated and validated. /li /ul h3AI Security Emerging Threats /h3 ul liAssess risks related to Generative AI, Large Language Models (LLMs), AI agents, and machine learning systems. /li liIdentify and mitigate threats such as: /li liAI supply chain attacks /li liSensitive data leakage through AI platforms /li liShadow AI usage /li liPartner with AI and Data teams to implement secure-by-design AI solutions. /li liContribute to AI governance, monitoring, and security controls. /li liStay up to date on emerging AI security frameworks and industry best practices. /li /ul h3Adversary Emulation Red Team Operations /h3 ul liPlan and execute realistic Red Team engagements that emulate real-world threat actors and attack scenarios. /li liLeverage MITRE ATTCK methodologies to assess detection, prevention and response capabilities. /li liEvaluate security controls across on-premises, cloud and hybrid environments. /li liSupport cyber resilience initiatives through controlled attack simulations and adversary emulation exercises. /li /ul h3Application Security Code Review /h3 ul liPerform web application, API and source code security assessments. /li liIdentify weaknesses associated with authentication, authorisation, session management and secure coding practices. /li liSupport agile delivery teams by providing security findings and remediation guidance during development cycles. /li liHelp improve the organisation's ability to identify and mitigate vulnerabilities early in the software development lifecycle. /li liPerform offensive security assessments across AWS, Azure and GCP environments. /li liAssess Kubernetes clusters, Docker environments and cloud-native architectures. /li liReview Infrastructure-as-Code deployments and cloud configurations for security weaknesses. /li liIdentify privilege escalation opportunities, misconfigurations and potential attack paths. /li liSupport cloud security validation and architecture review activities. /li /ul h3Security Research Automation /h3 ul liResearch emerging attack techniques, exploitation methods and offensive security tools. /li liDevelop and maintain automation, scripts and testing utilities to improve offensive security capabilities. /li liSupport continuous improvement of Red Team methodologies and testing approaches. /li liContribute to knowledge sharing, research initiatives and internal security innovation. /li liCollaborate with Blue Team teams to validate detections and strengthen defensive capabilities. /li liSupport the development and testing of monitoring rules, alerting mechanisms and incident response processes. /li liSimulate realistic attack techniques to improve visibility and detection coverage. /li liPromote continuous improvement through joint Red Team and Blue Team exercises. /li /ul h3What You Will Bring /h3 ul liPrevious experience in a Red Team, Penetration Testing, Offensive Security, Application Security or equivalent security-focused role. /li liStrong understanding of offensive security methodologies, attack techniques and adversary emulation practices. /li liUp-to-date knowledge of cyber security threats, exploitation techniques and offensive tooling.Experience performing vulnerability assessments, penetration testing and security validation activities. /li liKnowledge of application security, secure development practices and source code reviews.Good understanding of DevOps and Agile principles, with the ability to support security activities in fast-moving delivery environments. /li liKnowledge of cloud and container technologies, including Kubernetes, Docker and cloud environments such as AWS, GCP or Azure. /li liExperience using scripting languages and automation tools to improve offensive security capabilities and testing efficiency. /li /ul h3Desired skills /h3 ul liAbility to translate technical security findings into clear risk-based recommendations. /li liStrong analytical mindset, with the ability to investigate complex attack scenarios and identify realistic exploitation paths. /li liGood collaboration skills, with the ability to work effectively with Security, Engineering, DevOps and infrastructure teams. /li liProactive approach to learning and staying current with emerging threats, attack techniques and security technologies. /li liAbility to balance security requirements with business priorities in agile and cloud-based environments. /li /ul h3Personal attributes /h3 ul liOwnership and accountability when managing security findings, assessments and remediation activities. /li liClear communication style, especially when explaining technical risks to non-security stakeholders. /li liContinuous improvement mindset, with a focus on advancing offensive security practices and organisational resilience. /li liTeam-oriented approach and willingness to collaborate across technical and business areas. /li /ul /p #J-18808-Ljbffr