jobs in Dtcpay

全职 Senior Penetration Testing Engineer 工作, 薪水, Dtcpay 公司招聘中 - Ricebowl

Senior Penetration Testing Engineer

Dtcpay

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

Key Responsibilities

  • Conduct end-to-end penetration testing on web systems, mobile apps, and internal networks for the company and its clients, identifying and validating security vulnerabilities.
  • Independently execute the full pentest lifecycle: reconnaissance, vulnerability scanning, vulnerability validation, privilege escalation, and internal network lateral movement.
  • Perform in-depth analysis of common and OWASP Top 10 vulnerabilities (SQL injection, XSS, CSRF, command injection, deserialization, etc.) and provide remediation guidance.
  • Perform source code audits, covering Java frameworks (Spring, SpringBoot, SpringMVC, MyBatis) and common vulnerability patterns at the code level.
  • Conduct mobile (APP) security testing, including decompilation, hardening/packer detection, static/dynamic testing, and API-level penetration testing.
  • Independently author penetration test reports and liaise directly with project teams and clients.
  • Participate in red team / national-level cyber defense exercises, handling attack monitoring, traceback analysis, and remediation.
  • Support Multi-Level Protection Scheme (MLPS Level 3) security assessments.
  • Contribute to internal security awareness training programs.

Requirements

Basic Requirements

  • Bachelor's degree or above in Computer Science or a related field.
  • 5+ years of experience in penetration testing / information security, ideally spanning both in-house and security-services (consulting) roles.
  • Strong ability to work independently, including owning client and project-team communication as a project lead.

Technical Skills

  • Proficient in the full penetration testing methodology, including internal network lateral movement (tunneling via ICMP/LCX/SSH, pass-the-hash, pass-the-ticket, WMI/PsExec lateral movement, etc.).
  • Skilled with AWVS, Nmap, SqlMap, Burp Suite, AppScan, and other scanning/testing tools.
  • Capable of Java source code auditing, familiar with Fortify, Eclipse, and vulnerability tracing across common frameworks.
  • Proficient in Python; able to independently build security tools (directory brute-forcers, subdomain scanners, C-segment scanners, protocol crackers, PoCs/exploits, etc.).
  • Experienced in mobile security testing — APP decompilation (AndroidKiller, apktool), hardening/packer identification, dynamic testing with Drozer, etc.
  • Familiar with common middleware attack techniques and host security inspection procedures.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多