Working Location: Kai Tak, Kowloon, Hong Kong
Employment Duration: Permanent
The Red Team Manager is responsible for identifying and exploiting vulnerabilities in computer systems, applications, and networks. This role will work closely with various internal teams and security personnel to ensure that proper security measures are implemented throughout the organisation.
The primary focus of this role will be to help scope and perform Red Team exercises.
As such, it is expected that the successful candidate will possess Red Team skills and relevant experience.
Key Responsibilities
Assist to develop and execute a program of offensive campaigns (Red Team exercises) to test CLP’s cyber detective and protective controls.
Drive innovative thinking by researching, creating and testing new tools and techniques to identify vulnerabilities in the people, processes and technologies that CLP use.
Provide CLP with detailed reports that contain the necessary insight to support security fixes, patches, remediation, and training to ensure the same opportunities for exploitation do not exist in the future.
Perform quality assurance of technical reports (both Red Team and penetration testing reports).
Develop and execute custom scripts to automate and streamline testing procedures.
Work with development teams and security personnel to help prioritize and remediate identified vulnerabilities.
Stay current with emerging security threats, vulnerabilities, and share knowledge with other security team members.
Provide regular reports and assist with creating technical presentations for senior leadership.
Qualifications & Experience
Bachelor's degree in Computer Science, Information Technology, or a related field.
6-7 years of experience in scoping and executing Red Team exercises, penetration tests, and security tests.
Independent management experience covering penetration testing projects, including project planning, scoping, and quality assurance.
In-depth understanding of attacker TTPs (tactics, techniques, and procedures) and how these apply to Red Team exercises.
Strong understanding of network security, web application security, API security, cloud security, and mobile application security.
Experience performing EDR evasion, bespoke tool development, and associated research.
Experience reviewing Windows Active Directory security and cloud environments.
Knowledge of scripting languages such as Python, C/C++, .NET, or PowerShell.
Good command of spoken and written English.
Ability to explain technical issues to non-technical stakeholders.
Ability to work collaboratively with cross-functional teams.
Exhibit a high level of self-motivation and drive to achieve personal and team goals.
Actively shares technical knowledge and insights with team members to foster a collaborative environment.
Independent research experience performing vulnerability research and exploitation is a plus.
Embrace new ideas, approaches, and be willing to learn and adapt to evolving technologies.
Holding a relevant penetration testing certification such as OSCP, OSCE, OSEP, or OSCE3 is required.
Holding a Red Team certification (such as CRTO/CRTE/PACES) is required.
About Us
Skills Required
- Bachelor's degree in Computer Science, Information Technology, or related field
- 6+ years of cybersecurity experience, including 4 years performing Red Team exercises
- Independent management experience covering Red Team exercises and penetration testing including project planning, scoping, and QA
- Strong understanding of network security, web application security, API security, and mobile application security
- Experience with Microsoft enterprise technologies (Windows, Active Directory, TMG, IIS)
- Experience with Linux and virtualization technologies (VMware, Hyper-V)
- Hands-on experience in TCP/IP networking, firewalls, VPN, intrusion prevention systems, network security monitoring, and vulnerability scanning
- Experience performing manual and automated penetration testing using tools such as Burp Suite, Metasploit, and Nmap
- Knowledge of scripting languages such as Python, Ruby, or PowerShell
- Excellent written and verbal communication skills; ability to explain technical issues to non-technical stakeholders
- Good command of spoken and written English
- Relevant Red Team certification (e.g., CRTO, CRTE, PACES)
- Relevant penetration testing certification (e.g., OSCP, OSCE)
- Independent vulnerability research and exploitation experience
- Experience with Operational Technology (OT) applications and systems
- Willingness to learn, adapt, and actively share technical knowledge with team members
What We Do
The CLP Group is one of the largest investor-owned power businesses in Asia Pacific with investments across Hong Kong, Mainland China, Australia, India, Taiwan Region and Thailand. Hong Kong-listed CLP Holdings Limited is the holding company for the CLP Group, which has a diversified portfolio of generating assets that uses a wide range of fuels including coal, gas, nuclear and renewable sources. Through CLP Power Hong Kong Limited, the Group operates a vertically integrated electricity supply business that provides a highly reliable supply of electricity to 80% of Hong Kong’s population. The CLP Group is the largest external investor in the energy sector in Mainland China. The Group’s wholly-owned subsidiary EnergyAustralia is a leading integrated energy company in Australia, providing gas and electricity to about 2.46 million households and businesses. Apraava Energy, in which CLP has a 50% interest, is one of India’s biggest renewable energy producers with operations in power generation and transmission. CLP Holdings is included in the Global Dow – an index of the world’s leading blue-chip companies, in addition to sustainability-focused indices including the Dow Jones Sustainability Asia Pacific Index (DJSI Asia Pacific), the Hang Seng Corporate Sustainability Index Series and the FTSE4Good Index series.








