- Singapore
工作地点
职位描述
岗位职责
Location: Singapore
Eligibility: Singapore Citizens only
ITSEC Asia is looking for a Cybersecurity Consultant (Offensive Security) to join our growing Singapore team.
We are primarily looking for candidates with around 3 years of hands-on penetration-testing experience, although we also welcome applications from strong junior pentesters and early-career professionals who can demonstrate solid technical foundations and a genuine passion for ethical hacking.
Due to the nature of the projects supported by this role, applicants must be Singapore Citizens. Candidates with prior experience supporting Singapore Government, highly classified, critical-infrastructure or other security-sensitive projects will be particularly advantageous.
About ITSEC GroupITSEC Group is a cybersecurity organisation operating across the Asia-Pacific region and beyond, with offices in Singapore, Indonesia, Australia, the UAE and Mauritius.
We provide cybersecurity consulting and security services to clients across government, critical infrastructure, financial services, telecommunications, healthcare, technology and other industries.
Joining ITSEC provides exposure to diverse technology environments, complex security challenges and a broad range of consulting engagements, while developing both technical and client-facing capabilities.
Key Responsibilities• Conduct penetration testing and vulnerability assessments across web applications, APIs, mobile applications, networks, cloud environments and other technology platforms.
• Support security assessments involving IT, Operational Technology (OT), Internet of Things (IoT) and other specialised environments.
• Identify, validate and assess the technical and business impact of security vulnerabilities.
• Document testing activities, technical evidence, proof-of-concept results and assessment conclusions.
• Prepare clear and professional penetration-testing reports covering findings, risk implications and practical remediation recommendations.
• Present technical findings to clients and explain security risks and remediation approaches to technical and non-technical stakeholders.
• Conduct remediation verification and retesting to confirm that identified vulnerabilities have been effectively addressed.
• Explore and responsibly apply AI-assisted security testing, automation, scripting and emerging technologies to improve research, reconnaissance, testing, analysis and reporting workflows.
• Keep up to date with emerging vulnerabilities, attack techniques, security tools, technologies and industry methodologies.
• Contribute to the development of the team's testing methodologies, knowledge base, tooling and technical capabilities.
Requirements• Must be a Singapore Citizen.
• Diploma or degree in Cybersecurity, Information Security, Computer Science, Engineering or a related discipline.
• Ideally around 3 years of relevant hands-on penetration-testing or offensive-security experience.
• Strong junior candidates with less experience are also encouraged to apply if they can demonstrate good practical offensive-security skills and a strong willingness to learn.
• CREST Registered Tester (CRT), Offensive Security Certified Professional (OSCP), or another recognised offensive-security certification is preferred.
• Practical knowledge of penetration-testing methodologies, tools and techniques.
• Hands-on experience in areas such as web application, API, network, Active Directory, mobile or cloud penetration testing will be advantageous.
• Experience or knowledge in OT, ICS, IoT or critical-infrastructure security testing is highly advantageous.
• Previous experience supporting Singapore Government or highly classified/security-sensitive projects is strongly preferred.
• Strong analytical, troubleshooting and problem-solving capabilities.
• Ability to produce clear, accurate and professional technical reports.
• Good communication skills and the ability to explain technical findings clearly to clients.
• Interest in AI, automation, scripting and emerging offensive-security technologies, with the ability to learn and adapt quickly.
• Willingness to take ownership, work collaboratively and develop professionally within a cybersecurity consulting environment.
What You Can ExpectITSEC provides on-the-job training, technical mentorship and exposure to experienced cybersecurity professionals to help consultants continue developing their capabilities.
You will have opportunities to work on diverse and technically challenging security engagements, deepen your expertise across IT, cloud, OT and emerging technologies, strengthen your consulting and report-writing skills, and gain practical exposure to AI-assisted and automated security-testing approaches.
Please note: This position is open to Singapore Citizens only due to project eligibility requirements.
重要安全守则
申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。