Overview
IT – Manager, Red Team (Offensive Security) Jobs in Hong Kong, Hong Kong SAR at FortisHill Consulting
Title: IT – Manager, Red Team (Offensive Security)
Company: FortisHill Consulting
Location: Hong Kong, Hong Kong SAR
Our client is a leading Hong Kong homegrown FinTech and payments platform, operating at massive scale across transit, retail, e-commerce, and cross-border use cases. They are hiring a Manager, Information Security (Red Team) to build and lead an in-house offensive security capability, running adversary simulation and penetration testing to validate controls, strengthen detection/response, and elevate security readiness across cloud, mobile, endpoint, and enterprise environments.
Key Responsibilities
Build and Lead the Internal Red Team Function
- Establish, lead, and develop an internal red-team capability, including tooling, methodologies, and operating cadence.
- Mentor team members and drive a culture of technical excellence and continuous improvement.
Plan and Execute Red-Team / Threat Simulation Exercises
- Design and run red-team campaigns, partnering with stakeholders to define objectives, scope, rules of engagement, and success criteria.
- Conduct penetration testing and adversary simulations to test real-world resilience across network, application, cloud, and endpoint environments.
- Stay ahead of emerging attacker techniques and threat actor behaviours to continuously enhance testing approaches.
Validate Security Controls and Improve Detection
- Validate the effectiveness of security controls using red-team techniques and provide actionable remediation recommendations.
- Review and analyse EDR alerts to identify suspicious activity, advanced attack attempts, and potential breach indicators.
- Perform compromise assessments to identify evidence of prior/ongoing unauthorised access and improve detection capability.
Purple Teaming and Collaboration with Blue Team
- Coordinate purple-team exercises and work closely with SOC / blue team and other security functions to improve detection and response outcomes.
- Translate offensive findings into practical improvements in monitoring, alerting, playbooks, and response readiness.
Reporting and Executive Communication
- Produce clear technical reports and executive-ready summaries on findings, risk impact, and remediation priorities.
- Present results and recommendations to senior stakeholders with a focus on measurable security uplift.
Security Coverage Across Modern Technology Domains
- Maintain awareness of evolving technology risks (cloud, mobile, endpoint, identity) and advise on corresponding security challenges and controls.
Requirements
- Degree in Information Security, IT, Computer Science, or related discipline.
- Minimum 6 years’ experience in IT security (or equivalent), including 3+ years in offensive security / red teaming.
- Proven hands-on experience across offensive security disciplines such as penetration testing, exploit development, and adversary simulation.
- Strong knowledge of attack techniques across network, application, cloud, and endpoint environments.
- Familiar with frameworks such as MITRE ATT&CK, OWASP, and threat intelligence integration.
- Hands-on experience with tools such as Cobalt Strike, Metasploit, Burp Suite, and/or custom attack frameworks.
- Knowledge across: TCP/IP, Linux/UNIX and Windows administration, Active Directory security, network security, cloud security, mobile/application security, virtualization; database knowledge is a plus.
- Good problem-solving and troubleshooting ability; strong communication and stakeholder management skills.
- Self-motivated, team-oriented, able to work under pressure, and passionate about cyber security.
Preferred
- Programming knowledge (Core Java / C / C++ / Python).
- Experience in security auditing, cybercrime and/or incident investigation.
- Familiarity with standards/frameworks such as ISO 27001 and HKMA C-RAF.
- Offensive security certifications such as CEH, OSCP, OSCE, OSEP, GPEN, CREST CRT.
- Additional security certifications such as CISA, CISM, CISSP (or equivalent).