NG
Hiring from
Malaysia
Work type
Remote
Posted
Sep 25, 2026
Is this job info correct?

Breach Simulation Analyst At Provido , we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence. Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world. As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact. If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here. 👉 Why We Need You The Breach Simulation Analyst (Red Teamer) is responsible for planning, executing, and reporting on offensive security engagements that emulate real-world adversary behavior against the organization’s systems, applications, infrastructure, and personnel. This role supports proactive identification of exploitable weaknesses through penetration testing, red team operations, breach and attack simulation, adversary emulation, and authorized social engineering exercises aligned to frameworks such as MITRE ATT&CK. The analyst will work alongside blue team, detection engineering, and incident response functions to validate detection coverage, test control effectiveness, and deliver actionable remediation guidance. The role requires strong technical depth, disciplined documentation, and the ability to coordinate with global security operations, defensive teams, and business stakeholders. 👉 What You’ll Be Doing Plan, scope, and execute red team engagements, penetration tests, and breach simulation exercises across networks, web and mobile applications, cloud environments, endpoints, Active Directory, and internal infrastructure. Emulate adversary tactics, techniques, and procedures (TTPs) aligned to MITRE ATT&CK to test detection and response capabilities of the SOC and incident response teams. • Conduct authorized social engineering exercises, including phishing, vishing, and where in scope, physical intrusion testing, to evaluate human and process controls. Develop and maintain custom tooling, scripts, and payloads to support offensive operations, while operating strictly within authorized scope and agreed rules of engagement. Identify, exploit, and document vulnerabilities, misconfigurations, and control weaknesses, producing clear technical findings and executive-ready reports with prioritized remediation guidance. Collaborate with blue team, detection engineering, and incident response on purple team exercises to validate and improve detection and response coverage. Maintain accurate records of engagement scope, methodology, evidence, exploitation steps, escalations, and remediation tracking for audit, reporting, and continuous improvement purposes. Maintain awareness of emerging offensive techniques, threat actor TTPs, vulnerability disclosures, and tooling relevant to the organization’s technology stack and operating environments in Malaysia, Southeast Asia, and across multinational footprints. 👉 What You Bring to the Team Bachelor's degree or completed studies in Cybersecurity, Information Technology, Computer Science, or a related technical discipline. 4+ years of hands-on experience in penetration testing, red teaming, breach simulation, offensive security, or a closely related technical role. Working knowledge of common attack techniques across network, web application, Active Directory, cloud (AWS, Azure, or GCP), and endpoint domains, including privilege escalation, lateral movement, and post exploitation. Hands-on experience with offensive tooling such as Cobalt Strike, Metasploit, Burp Suite, BloodHound, Impacket, Nmap, or equivalent commercial and open-source frameworks. Scripting or programming ability in Python, PowerShell, Bash, or similar, sufficient to build custom tooling and automate offensive workflows. Ability to scope engagements, document findings clearly, and translate technical exploitation into actionable remediation recommendations for both technical and executive audiences. Strong written and verbal English proficiency to support multinational stakeholders and prepare clear engagement reporting. 👉 Preferred Skills Professional certifications such as OSCP, OSEP, OSWE, CRTO, CRTP, GPEN, GXPN, GWAPT, CEH Practical, or equivalent offensive security credentials. Experience supporting red team operations, purple team exercises, adversary emulation, breach and attack simulation programs, or managed offensive security service environments. Exposure to breach and attack simulation platforms (e.g., AttackIQ, SafeBreach, Cymulate), command-and control frameworks, and EDR / AV evasion techniques. Understanding of Active Directory attack paths, Kerberos abuse (Kerberoasting, AS-REP roasting, delegation attacks), lateral movement, privilege escalation, and post-exploitation tradecraft. Knowledge of the MITRE ATT&CK framework, cyber kill chain, threat actor emulation profiles, purple team methodology, and the intelligence-led offensive testing lifecycle. Understanding of compliance-focused environments and the importance of documented methodology, rules-of-engagement adherence, data handling discipline, and audit support. 👉 Why You’ll Love Working with Us ☐ Employee Benefits & Advantages At Provido, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment. ☐ Competitive Compensation & Performance Incentives Provido offers an attractive salary package and performance-based bonuses to recognize and reward your contribution. ☐ Flexible Working Options We support remote and hybrid working models to help you maintain a healthy work-life balance. ☐ Health & Well-being Support We provide comprehensive health insurance, wellness initiatives, and resources to support both physical and mental well-being. ☐ Career Advancement & Development Programs We invest in continuous learning through training programs, mentorship, and clearly defined career development paths. ☐ Team-Oriented & Inclusive Workplace Our culture is built on diversity, inclusion, and collaboration. Every voice matters and innovation is encouraged. ☐ Team Events & Social Activities We organize regular team-building activities and social events to strengthen relationships and create a positive, connected workplace. Division Provido Location Malaysia Remote status Fully Remote Employment type Contract Job Category Tech Job About Provido Provido provides wholesale IT, network, data storage and processing infrastructure services: the layer applications stand on. Every service level is defined up front, then measured and reported, month after month. Applicant tracking system by Teamtailor

Similar jobs

Apply for this job