jobs in Dtcpay

Dtcpay Hiring! Full Time Senior Penetration Testing Engineer in - Ricebowl

Senior Penetration Testing Engineer

Dtcpay

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

Key Responsibilities

  • Conduct end-to-end penetration testing on web systems, mobile apps, and internal networks for the company and its clients, identifying and validating security vulnerabilities.
  • Independently execute the full pentest lifecycle: reconnaissance, vulnerability scanning, vulnerability validation, privilege escalation, and internal network lateral movement.
  • Perform in-depth analysis of common and OWASP Top 10 vulnerabilities (SQL injection, XSS, CSRF, command injection, deserialization, etc.) and provide remediation guidance.
  • Perform source code audits, covering Java frameworks (Spring, SpringBoot, SpringMVC, MyBatis) and common vulnerability patterns at the code level.
  • Conduct mobile (APP) security testing, including decompilation, hardening/packer detection, static/dynamic testing, and API-level penetration testing.
  • Independently author penetration test reports and liaise directly with project teams and clients.
  • Participate in red team / national-level cyber defense exercises, handling attack monitoring, traceback analysis, and remediation.
  • Support Multi-Level Protection Scheme (MLPS Level 3) security assessments.
  • Contribute to internal security awareness training programs.

Requirements

Basic Requirements

  • Bachelor's degree or above in Computer Science or a related field.
  • 5+ years of experience in penetration testing / information security, ideally spanning both in-house and security-services (consulting) roles.
  • Strong ability to work independently, including owning client and project-team communication as a project lead.

Technical Skills

  • Proficient in the full penetration testing methodology, including internal network lateral movement (tunneling via ICMP/LCX/SSH, pass-the-hash, pass-the-ticket, WMI/PsExec lateral movement, etc.).
  • Skilled with AWVS, Nmap, SqlMap, Burp Suite, AppScan, and other scanning/testing tools.
  • Capable of Java source code auditing, familiar with Fortify, Eclipse, and vulnerability tracing across common frameworks.
  • Proficient in Python; able to independently build security tools (directory brute-forcers, subdomain scanners, C-segment scanners, protocol crackers, PoCs/exploits, etc.).
  • Experienced in mobile security testing — APP decompilation (AndroidKiller, apktool), hardening/packer identification, dynamic testing with Drozer, etc.
  • Familiar with common middleware attack techniques and host security inspection procedures.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More