Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Security Operation Engineer

Full-time

Bybit

About Us

Established in 2018, Bybit is one of the world’s leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Powered by world-class technology and a user-first mindset, Bybit delivers a seamless ecosystem across trading, payments, wealth management, custody, institutional services, and Web3 — connecting users to the future of digital finance.

Our core values define how we build. We listen, care and improve to create products and experiences that put users first. Backed by a global team of ambitious builders, problem-solvers, and innovators, we foster a high-performance and fast-moving environment where talent is empowered to drive real impact at the global scale. Supported by 24/7 multilingual customer service and a strong commitment to innovation, we are shaping the future of finance through technology, collaboration, and bold execution.

Today, Bybit is recognized as one of the most trusted and transparent platforms in the digital asset industry, continuing to expand its global presence while building the infrastructure for the next generation of financial services.

Job responsibilities Red-blue confrontation drill
  • Responsible for developing and executing penetration testing, red-blue confrontation, and practical attack and defense drills that simulate real attack scenarios, identifying potential security risks in enterprise networks, applications, cloud environments, work networks, and core business systems.
  • Lead or participate in red-blue confrontation exercises to evaluate the defense team's ability in attack detection, alarm analysis, traceability analysis, emergency response, and recovery.
  • Based on the real attack chain design exercise scenario, covering extranet breakthrough, web vulnerability exploitation, phishing entrance, privilege escalation, lateral movement, Data Discovery, privilege maintenance, and defense bypass stages.
  • Combining the attack review results, promote the continuous optimization of security detection rules, response processes, asset governance, and security base lines.
Attack Surface Analysis and Threat Research
  • Identify enterprise network exposure, internet assets, cloud assets, APIs, supply chain components, and third-party access risks, evaluate attack paths, and provide mitigation recommendations.
  • Monitor and collect threat intelligence, track vulnerability exploitation trends, APT attack methods, red team toolchain changes, and apply them to enterprise attack and defense exercises.
  • Combining business scenarios to model attack paths and discover feasible attack chains from external exposure surfaces to core assets.
  • Tracking AI-related security risks, including security issues in large-scale model applications, RAG systems, Agent systems, plug-in/tool calls, MCP services, AI code generation, and automated workflows.
AI Security and Large Model Attack and Defense
  • Responsible for the security evaluation of AI applications, intelligent agent systems, RAG Knowledge Base, AI Agent toolchain, and model services within the enterprise.
  • Research and verify large-scale model-related attack techniques, including Prompt Injection, Jailbreak, Indirect Prompt Injection, data leakage, unauthorized tool invocation, security risks caused by model illusions, RAG poisoning, vector library pollution, sensitive information leakage, etc.
  • Design AI red team test cases and evaluation framework, and conduct security verification on model input and output, context isolation, permission control, tool call chain, and data access boundary.
  • Participate in the construction of AI security protection plan, including prompt word security policy, content security detection, tool call permission constraints, sensitive data desensitization, audit tracking, Agent sandbox isolation and security evaluation benchmark construction.
  • Explore the application of AI in red team automation, vulnerability analysis, attack path planning, PoC verification, and report generation, and promote the platformization, automation, and intelligence of attack and defense capabilities.
Tool and platform development
  • Develop and optimize Red Team-specific tools and scripts for vulnerability mining, information collection, privilege escalation, lateral movement, credential analysis, traffic disguise, defense bypass, and automated report generation.
  • Research and validate new attack techniques, and simulate real threats in combination with enterprise business scenarios.
  • Build or participate in the construction of automated security evaluation platform, integrated vulnerability scanning, audio fingerprint recognition, asset mapping, PoC verification, attack path analysis, AI Agent arrangement and other capabilities.
  • Combining LLM/Agent technology to explore automated penetration testing, intelligent vulnerability verification, code security auditing, and red team task scheduling.
Security evaluation and reporting
  • Conduct security evaluations on critical business systems, internal networks, cloud environments, work end points, API services, and AI applications, and output detailed technical reports, attack paths, impact analysis, and repair recommendations.
  • Output AI security evaluation reports for AI applications, including attack examples, risk levels, exploitable paths, data leakage risks, permission boundary issues, and governance recommendations.
  • Assist in improving enterprise security protection mechanisms, promote optimization of WAF, EDR, SIEM, NDR, HIDS, zero trust, identity permissions, and log auditing capabilities.
  • Transform attack and defense discovery into security detection rules, base line specifications, develop security requirements, and continuous governance mechanisms.
XFN collaboration
  • Collaborate with the blue team, security operation, infrastructure, R & D, algorithm, data, and business teams to complete attack review, vulnerability repair, detection rule optimization, and security capability building.
  • Provide security support to other departments of the enterprise, including emergency response drills, development security consulting, AI application pre-launch security review, and security training.
  • Participate in the security design review of AI applications and security products, and promote the advance of security capabilities in R & D, testing, and Pushonline.
Job requirements Basic skills
  • Proficient in basic knowledge of cyber security, including TCP/IP protocol, network architecture, identity authentication, access control, principles and configurations of common security devices.
  • Proficient in common attack techniques and red team toolchains, such as Sliver, Cobalt Strike, NPS, Burp Suite, Metasploit, Nmap, Masscan, Frida, Impacket, etc.
  • Familiar with mainstream operating systems Windows, Linux, macOS security mechanism, log system, permission model and common use.
  • Familiar with common web frameworks, API architectures, microservice structures, containers, and security risks in Kubernetes environments.
Offensive and defensive technical capabilities
  • Proficient in penetration testing and red team processes, including information collection, vulnerability scanning, vulnerability exploitation, intranet penetration, privilege escalation, lateral movement, privilege maintenance, Data Discovery, and trace cleaning.
  • Familiar with the working principles and adversarial methods of enterprise-level security products, including WAF, EDR, SIEM, NDR, HIDS, zero-trust gateway, bastion host, and identity authentication system.
  • Possess independent vulnerability analysis and PoC writing capabilities, able to reproduce, verify, and assess the impact of public vulnerabilities and 0day/1day risks.
  • Proficient in one or more programming/scripting languages, such as Python, Go, Bash, PowerShell, JavaScript, etc., with experience in tool development and automation platform construction.
AI security capabilities
  • Familiar with the basic architecture of large-scale model applications, familiar with technical forms such as Prompt, RAG, Embedding, vector databases, Agent, Function Calling, MCP, plugin systems, etc.
  • Understand or practice AI security testing methods, including Prompt Injection, Jailbreak, RAG data poisoning, sensitive information leakage, unauthorized tool invocation, model output security, Agent permission escape, etc.
  • Able to design security test cases for AI applications, evaluate model input/output, context isolation, data boundaries, permission control, and tool invocation chain risks.
  • Experience in using AI to assist security work, including vulnerability analysis, code auditing, intelligence analysis, attack path planning, report generation, or automated testing.
  • Familiar with AI application security governance ideas, including model call auditing, prompt word security, sensitive data protection, content security detection, permission minimization, and sandbox isolation.
Experience requirements
  • More than 5 years of experience in red team, penetration testing, security research, or offensive and defensive exercises.
  • Candidates with experience in large-scale enterprise attack and defense drills, red-blue confrontation, HW/major support, cloud attack and defense, or intranet penetration are preferred.
  • Candidates with experience in AI security, large-scale model security, intelligent agent security, automated penetration testing platform or security tool platform construction are preferred.
  • Familiar with enterprise security construction system, able to promote defense capability, detection capability, and governance process optimization from an attack perspective.
Other capabilities
  • Priority will be given to those who hold security-related certifications such as ♀ P, OSCE, CISSP, CISP, CEH, CISSP, CCSP, etc.
  • Possess strong document writing and expression abilities, able to output high-quality technical reports, review documents, attack chain analysis, and security construction plans.
  • Possess good problem analysis ability, learning ability, teamwork ability, and stress resistance.
  • Be sensitive to new technologies, new Attack Surfaces, and new tools, and be able to proactively research and share internally.
Bonus points
  • Familiar with Cloud Computing Platform security and cloud attack and defense technologies, such as AWS, Azure, GCP, Tencent Cloud, Alibaba Cloud, etc.
  • Familiar with Kubernetes, containers, Service Mesh, CI/CD, DevSecOps and supply chain security.
  • Possess experience in zero trust, secure operation, threat hunting, Attack Surface management, and vulnerability management platform construction.
  • Familiar with MCP Server, AI Agent framework, RAG system, vector database, LLM API gateway, model security evaluation framework.
  • Experience in Automated Red Team, AI Penetration Testing, Intelligent Vulnerability Verification, Agent Orchestration, Security Knowledge Base or Security RAG System Construction.
  • Experience in vulnerability submission, CVE, technical articles, open source projects, topic sharing, or tool release in the security community.
  • Familiar with security frameworks such as MITRE ATT & CK, OWASP Top 10, OWASP LLM Top 10, NIST AI RMF, etc.
Why Join Us At Bybit, we are committed to fostering a supportive and enriching work environment. Our benefits include:
  • Study Growth Fund: We support your professional development and continuous learning.
  • Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
  • Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
  • Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
  • Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.
Vacancy posted 14 days ago
Similar jobs that could be interesting for youBased on the Principal Security Operation Engineer in Remote vacancy
  • $192k - $240k

     ...founders and finance teams to accelerate operations, gain real-time visibility, and control...  ...support you need to grow your career.Engineering at BrexEngineering at Brex is about building...  .... Our teams span Software, Data, Security, and IT, and operate with high autonomy... 
    Suggested
    Work at office
    Remote work
    Work from home

    Brex

    New York, NY
    2 days ago
  • Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-edge...  .... Cohere is a team of researchers, engineers, designers, and more, who are all passionate...  ...and Paris. Join us!As a Senior Security Operations Engineer you will:Serve as trusted... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work
    Home office
    Flexible hours

    Cohere

    New York, NY
    2 days ago
  •  ...change. Constantly grow as you work hard for a mission that matters at a company where you matter.Your Impact As a Senior Security Operations Engineer II, you will play a key role in building secure, reliable, and developer-friendly infrastructure that enables teams to... 
    Suggested
    Work at office
    Remote work

    Axon

    Scottsdale, AZ
    1 day ago
  • $86.8k - $198k

    Security Operations Center EngineerThe Opportunity: As a Security Operations Center Engineer, you’ll build and improve the systems that enable security teams to detect, investigate, and respond to cyber threats. We need an engineer who can combine cybersecurity knowledge... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $145k - $175k

    Job DescriptionWe are seeking an experienced Security Operations Engineer to help advance the next generation of security capabilities across our enterprise. This role is a technical leader responsible for designing, implementing, and continuously improving enterprise... 
    Suggested
    Temporary work
    Work at office
    Remote work

    Bessemer Trust

    Woodbridge, NJ
    22 hours ago
  • $160.3k - $240.5k

     ...la recherche d’un(e) développeur(se) principal(e) en sécurité, à l’aise dans un rôle...  ...SecOps team is seeking a senior, hands-on security engineer to serve as the team’s technical lead...  ...’re Looking ForExperience in Security Operations, Incident Response, Detection... 
    Principal
    Full time
    Work at office
    Remote work
    Worldwide

    Unity Technologies

    Texas
    2 days ago
  • $142.8k - $274.8k

     ...s current and future on-line services. This role is for a Principal Security Engineer with a background in security protocols and secure hardware...  ...Developed firmware for embedded devices running Real-Time Operating Systems (RTOS), utilizing OS primitives such as task... 
    Principal
    Ongoing contract
    Work at office
    Local area
    Worldwide
    3 days per week

    Microsoft

    Redmond, WA
    4 days ago
  • $128.13k - $180.99k

     ...The Senior Security Operations Engineer is responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You will lead hands-on deployment and tuning of DLP controls, including... 
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Home office

    Included Health

    Remote
    3 days ago
  • $120.5k - $231k

     ....What you’ll be doing...The Verizon Network Security team is looking for a highly motivated and experienced Principal Engineer to join the Net-Sec Defense Organization under...  ...scripts and tools to enhance security operations and play a key role in monitoring, analyzing... 
    Principal
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work
    3 days per week

    Verizon

    Ashburn, VA
    3 days ago
  •  ...millions of Americans to achieve more.About the RoleThe Principal Identity Security Engineer will lead the design and evolution of Happen Bank's enterprise...  ...how identity services are designed, governed, and operated across the bank.What You'll DoSet the technical direction... 
    Principal
    Full time
    For contractors
    Work at office
    Local area
    Remote work
    Relocation
    Flexible hours

    Lending Club

    San Francisco, CA
    1 day ago
  •  ...Job DescriptionFannie Mae is seeking a highly experienced Principal Security Engineer to serve as a senior technical authority for enterprise...  ...systemic risks and drive remediation from design through operations.• Develop strategic recommendations on security technologies... 
    Principal
    Full time
    Work at office
    Remote work

    Fannie Mae

    Reston, VA
    3 days ago
  • Senior Security Operations Engineer (Viator) AWS GCP Security Operations Incident Response SIEM As a Senior Security Operations Engineer at Viator, a Tripadvisor company, you will play a crucial role in advancing our security processes. Your responsibilities will span... 
    Remote work
    Flexible hours

    TripAdvisor

    New York, NY
    2 days ago
  • $160k - $185k

     ...Redhorse transforms the way government uses data and technology. To support this mission, we are seeking a Principal Information System Security Engineer (ISSE) who is a recognized authority in the field. This is a high-impact role where you will tackle unusually complex... 
    Principal
    Full time
    Contract work

    Redhorse Llc

    Remote
    22 hours ago
  • $114k - $171k

     ...making history.Northrop Grumman’s Space Sector is seeking a Principal Operations Systems Engineer - Level 3 to join our team in Aurora, CO. This position...  ...to obtain and maintain a U.S. Government Top Secret security clearance, SCI access, and complete a... 
    Principal
    Full time
    Remote work
    Relocation package
    Shift work
    Night shift
    Rotating shift

    Northrop Grumman

    Aurora, CO
    22 hours ago
  •  ...and yourself. You will: Provide operational support for SecOps tool alerts, triaging...  ...Monitor email and the ticketing system for security-related issues and follow through until...  ...be an expert in: System security engineering or information security engineering.... 
    Full time

    LivePerson

    Remote
    4 days ago
  •  ...largest licensed Stablecoin-based infrastructure provider operating across over 60 countries. From Stablecoin payment...  ...underscoring the company’s extensive international reach. The Security Operations Engineer is the operational backbone of the Security Operations... 
    Full time
    Local area
    Remote work

    Yellow Card

    Remote
    9 days ago
  •  ...considered for employment.What You'll Do:Join our dynamic Security Engineering team as an Associate Principal and make a significant impact on our organization's...  ...each primary duty satisfactorily.Provide 24x7 operational support for the suite of privileged management... 
    Principal
    Full time
    Remote work
    2 days per week

    The Options Clearing Corporation

    Chicago, IL
    1 day ago
  • $107.5k - $204.5k

     ...and maintain a U.S. government issued security clearance is required.​ U.S. citizenship...  ...market leading businesses, world-class operations and investments in research and development...  ...100 years of experience and renowned engineering expertise to meet the needs of today’s... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Raytheon

    Andover, MA
    4 days ago
  • $107.5k - $204.5k

     ...Requirements:Active and transferable U.S. government issued security clearance is required prior to start date.​ U.S....  ...challenging.The Product Cybersecurity Engineering DoD East Massachusetts team is hiring a Principal Embedded Systems Security Engineer to support programs... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Boston, MA
    22 hours ago
  • Our client operates a core banking platform designed specifically for digital assets...  ...onchain infrastructure. The platform secures over €100B in assets and powers...  ...institutions. Our client is seeking a Principal Security Engineer to lead product security across the entire... 
    Principal
    Full time

    Mlabs

    Remote
    16 days ago
  • $132.4k - $251.6k

     ...transferable U.S. government issued security clearance is required prior...  ...of experience and renowned engineering expertise to meet the needs...  ...is seeking a Senior Principal Systems Security Engineer (Anti...  ...switches, firewalls, servers, operating systems, applications, and... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Tewksbury, MA
    2 days ago
  • Principal Cloud Security Operations Engineer (Scripting, AWS, DevOps, CISM, CCSA, CISSP, CCIE Security, CEH) in San Francisco, CA AWS, CEH, CISA, CISSP, DevOps, Python, scripting, Security Operations, SIEM Location: California Job Function: Information Security Date... 
    Principal
    Permanent employment
    Full time
    Work experience placement
    Remote work
    Relocation

    DBA Web Technologies

    San Francisco, CA
    more than 2 months ago
  • $107.5k - $204.5k

     ...maintain a U.S. government issued security clearance is required.​ U.S. citizenship...  ...leading businesses, world-class operations and investments in research and...  ...team is recruiting a Principal Embedded Systems Security Engineer for leading all phases of the Secure... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Cedar Rapids, IA
    4 days ago
  • The Product Security Engineer - Secure Development Lifecycle is a senior individual contributor responsible for defining, maturing, and integrating...  ...scalable, risk-informed, AI powered, and developer-aligned operating model. The individual will partner with Secure Development... 
    Principal
    Internship
    Monday to Friday

    Navy Federal Credit Union

    Vienna, VA
    1 day ago
  • $221.2k - $387.1k

     ...It all started when engineer Fred Luddy wrote code that automated...  ...About SSO The ServiceNow Security Organization (SSO) delivers...  ...the least possible impact on operations, and shifts the perception of...  ...to enabler. Role As Principal Engineer for AI Security Governance... 
    Principal
    Permanent employment
    Full time
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    ServiceNow

    Washington DC
    9 days ago
  • $221.2k - $387.1k

    Company DescriptionIt all started when engineer Fred Luddy wrote code that automated a tedious...  ...people.Job DescriptionThe ServiceNow Security Organization (SSO) The ServiceNow...  ...the world's largest enterprises. You'll operate with minimal direction and broad latitude... 
    Principal
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    Santa Clara, CA
    2 days ago
  • $118.3k - $224.9k

     ...transferable U.S. government issued security clearance is required prior...  ...businesses, world-class operations and investments in research...  ...of experience and renowned engineering expertise to meet the needs...  ...defense.Raytheon is seeking a Principal Systems Security Engineer (... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Goleta, CA
    3 days ago
  • $128k - $200k

     ...infrastructure for the AI era. At Cribl, we partner with IT and Security teams at many of the world’s biggest enterprises, including...  ...herd. Why You’ll Love This Role The Staff Security Operations Engineer will be a pivotal member of Cribl’s Information Security... 
    Full time
    Temporary work
    Remote work

    Cribl

    Remote
    6 days ago
  •  ...We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions – at the high end we are looking for deep experience defending highly contested critical... 
    Full time
    Local area
    Remote work
    Worldwide

    Canonical Ltd.

    Remote
    a month ago
  •  ...Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global...  ...ID device migration and providing Entra ID engineering support across the organization. The Staff Security Operations Engineer serves as a key technical... 
    Temporary work
    Work at office
    Remote work
    Home office
    Flexible hours
    Shift work

    Sandisk

    Irvine, CA
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Security Operation Engineer. Be the first to apply!