Cymetrics is one of the leading cybersecurity solution providers in Asia, offering exclusive high-end cybersecurity products. We specialize in professional red teaming, penetration testing and vulnerability scanning services, assembling a team with engineering expertise and cybersecurity specialization.
🏢 About Cymetrics
Team members possess professional knowledge in cybersecurity risk management and penetration testing, with extensive experience in major consulting firms, leading cybersecurity service providers, and renowned brand OEMs. They actively participate in international CTF (Capture The Flag) competitions, achieving top three places globally. Our clientele spans diverse industries, including government, finance, manufacturing, high-tech, and e-commerce, among others. Additionally, our team assists the group in obtaining ISO 27001 and ISO 27017 certifications, reinforcing the group's cybersecurity governance. The core values of our team lie in innovation, professionalism, and collaboration, aiming to deliver efficient cybersecurity solutions.
🎯 The Role
As a Cybersecurity Engineer at Cymetrics, you will serve as the primary attacker in red teaming and penetration testing, deeply probing vulnerabilities, and collaborating with mid and junior-level partners to complete projects. You will contribute professional insights and opinions to our proprietary product development, engaging in discussions to optimize project execution effectiveness.
✅ Key Responsibilities
Planning and executing redteam project and penetration tests, aiding clients in identifying vulnerabilities, verifying remediation, and validating fix outcomes.
Conducting project meetings with clients, engaging in effective communication, clarifying issues, and assisting clients in problem resolution.
Assisting in the development of automated security tools, collaborating with the software engineering team to complete proprietary SaaS products.
Collaborating with the product development team to enhance cybersecurity products and platforms.
Researching vulnerabilities in websites or open-source projects and documenting findings in articles published on the company's TechBlog.
📌 Required Qualifications
Three or more years of practical experience in red teaming, penetration testing and lateral movement in internal networks.
Familiarity with modern web frameworks (such as React, Angular, Vue.js) and client-side security vulnerabilities (e.g., XSS, CSRF, CSP bypass, GraphQL).
Familiarity with OWASP testing guides and other security testing methodologies, with a deep understanding of web vulnerabilities, operating systems, network architecture, and underlying principles.
Ability to articulate and document test results, provide remediation suggestions clearly, and effectively communicate with teams and clients.
Fluency in spoken and written English to explain penetration test reports to clients.
⭐ Desirable Experience
Interest in blockchain-related cybersecurity technology.
Experience in bug bounty programs from reputable companies or participation in international CTFs (or equivalent CVE vulnerabilities).
Possession of OSWE, OSEP or OSCP certifications (or other equivalent information security certifications).
Proficiency in writing technical articles related to cybersecurity (vulnerability research, CTF write-ups, etc.).
Involvement in open-source projects, demonstrating contributions to and collaboration within the security community.