G
Deputy Director, Offensive Security
govtech
sg
1d ago
61%
Good
Job description
Role Purpose This role is built for a technical leader who can orchestrate and scale high-concurrency red team engagements , managing multiple distinct victim operations simultaneously. The Director ensures the continuous development of sophisticated custom malware and resilient Command and Control (C2) architecture, while serving as the primary operational coordinator who translates active attack campaigns into clear, actionable risk insights for diverse stakeholder groups. Key Responsibilities High-Concurrency Operational Management Directly manage multiple offensive teams executing simultaneous, distinct victim operations across separate target networks or business entities. De-conflict operational resources, timelines, and personnel to ensure high-fidelity, continuous testing across multiple concurrent environments. Handle the inherent ambiguity of shifting variables across multiple live runs, ensuring every operation maintains rigid operational security (OPSEC). C2 Architecture & Advanced Malware Development Oversee the design, deployment, and operational management of complex Command and Control (C2) frameworks capable of supporting multi-tenant, simultaneous operations. Enforce best practices in C2 server segregation, obfuscation, and traffic routing to prevent defensive detection across various target environments. Drive the engineering lifecycle for custom, evasive malware and custom tooling to ensure operations bypass modern enterprise controls (EDR/NDR). Threat-Aligned Operation Execution Maintain an expert, up-to-the-minute understanding of real-world threat actor behaviors, actively applying global threat intelligence to live operational scenarios. Ensure that simultaneous red team campaigns realistically mimic the specific Tactics, Techniques, and Procedures (TTPs) of modern Advanced Persistent Threats (APTs) targeting the respective victims. Stakeholder Interface & Operational Coordination Act as the primary interface for all affected stakeholders, providing regular, precise updates on active exploitation paths and findings during live runs. Coordinate complex, multi-stakeholder rating exercises, ensuring seamless collaboration and communication before, during, and after a specific operational run. Translate highly technical, multi-stage attack paths into risk-based executive briefings for non-technical leadership. Job Requirements Technical Experience & Qualifications Multi-Team Operational Leadership: Proven experience directly managing multiple technical offensive units or red teams, with a track record of executing concurrent attack campaigns. Live Operations Mastery: Expert-level knowledge in running routine, high-velocity red team operations, including post-exploitation, lateral movement, and data exfiltration. Malware & C2 Infrastructure Engineering: Deep technical background in developing custom malware and managing robust C2 server environments tailored for stealth and resilience. Threat Landscapes: Mastery of modern adversarial TTPs and a precise understanding of what real-world threat actors are currently exploiting in the wild. Soft Skills & Core Competencies Stakeholder Diplomacy: Outstanding capability to interface with, update, and manage expectations across a wide array of stakeholders during high-stakes operational runs. Crisis & Ambiguity Management: Calm under pressure; able to switch contexts rapidly between multiple live victim operations and make split-second operational decisions. Clear Articulation: Ability to synthesize complex technical execution chains into concise, impactful operational reports and executive summaries. Cultivating Technical Camaraderie & Shared Team Spirit Culture & Team Builder: Proven ability to build camaraderie and high esprit de corps among eccentric, highly specialized technical professionals, transforming isolated experts into a cohesive, mission-driven unit. Forge a Collaborative "Crew" Identity: Cultivate a tight-knit, high-trust team culture where multi-team silos are broken down. Encourage a collaborative environment where vulnerability researchers and red team operators actively swap insights, techniques, and tools to win operations together. Drive Shared Technical Victories: Build deep team spirit by establishing peer-review structures, collaborative hackathons, and collective post-operation debriefs. Ensure that a breakthrough by one operator (e.g., a novel C2 bypass or custom malware variant) is celebrated and adopted as a collective win for the entire unit. Foster an Environment of Mutual Respect: Lead with the technical credibility required to earn the respect of deeply analytical engineers, creating a flat, open culture where the best technical argument wins, regardless of hierarchy. Unite Around a Common Adversary: Foster high morale and collective purpose by aligning the team against a clear, shared mission—outsmarting real-world threat actors and securing complex ecosystems through elite, unified offensive tradecraft.