- 18 HOWARD ROAD Central Region (Singapore) Singapore
Working Location
Job Description
Responsibilities
Job Overview
We seek a Penetration Testing with CAT1 clearance to leadVAPT for Singapore government and critical infrastructure sectors. You willexecute full-scope attacks (networks, apps, cloud, OT), bypass advanceddefenses, and deliver actionable remediation strategies. This role requiresCREST/OSCP certification, deep exploit development skills, and experience withGovTech cybersecurity frameworks.
Core-Responsibilities
Advanced Threat Emulation:
1. CAT1-clearedengagements:
2. Network: Breach segmented govt networks(e.g., air-gapped systems)
3. Applications: Exploit web/mobile apps(SCADA interfaces, GovTech portals)
4. Cloud: Attack AWS GovCloud/AzureGovernment environments
5. OT:ICS/SCADA system penetration(Siemens, Rockwell)
6. Develop custom malware/exploits (C++,Python) to evade EDR/XDR.
Reteam Operations:
1. Lead multi-vector campaigns:
2. Phishing (Evade Proofpoint/MS ATP)
3. Physical security bypass (RFID cloning,access control spoofing)
4. Wireless attacks (802.1X,WPA3-Enterprise)
5. Document TTPs aligned with MITREATT&CK for ICS/Enterprise.
Govt Compliance & Reporting:
1. Align tests with IM8, CSA Red TeamingGuidelines, and NIST SP *************.
2. Deliver executive briefings to CISOswith exploit demos.
3. Create remediation playbooks
Research & Development:
1. Reverse engineer firmware (Binwalk,Ghidra) for 0-day discovery.
2. Contribute to ASEAN CERT advisories(e.g., Sing CERT).
Technical Requirements
Non-Negotiable Credentials
1. CAT1Security Clearance
2. Active Certifications: OSCP or CRESTCRT/CCT (Inf/App)
3. 2+years in pentesting
Tool Proficiency
1. Exploitation- Metasploit Pro, CobaltStrike, Burp Suite Pro, Powersport
2. Post-Exploit- Bloodhound, Mimi Katz,Impacket, Covenant C2
3. Forensics- Volatility, Wireshark, CHIRP(ICS)
4. Wireless- HackRF One, Proxmark3, Wi-FiPineapple
5. Cloud- Pacu (AWS), MicroBurst (Azure),GCP IAM Exploit Toolkit
Preferred Qualifications
1. Certifications:OSCE³, CREST CCT Gold,OSCP
2. Govt Framework Experience: IM8Penetration Test Guidelines, CSA Cyber Essentials
3. Public Contributions: CVEs, exploit-dbsubmissions, conference talks (Black Hat Asia, DEFCON)
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.