14 Penetration Testing jobs in Singapore
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
Seeking a skilled Cybersecurity Expert to enhance our team's security posture through thorough penetration testing and expert advice.
Job Title: Penetration TesterKey Responsibilities:
- Conduct comprehensive penetration tests on networks, web applications, and systems to identify vulnerabilities and recommend strategic improvements.
- Develop and execute custom test cases, scenarios, and scripts to simulate real-world attack vectors.
- Collaborate with stakeholders to improve the organization's overall security and client relationships.
- Stay up-to-date with the latest cybersecurity threats, trends, and technologies.
- Provide technical guidance on security best practices and strategies for securing information systems.
- Assist in threat modeling, security architecture reviews, and the implementation of secure solutions.
Requirements:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
- Proven experience in penetration testing across various domains (network, web, mobile, cloud, etc.).
- Strong knowledge of penetration testing tools such as Nmap, Metasploit, Burp Suite, Wireshark, Nessus, Kali Linux, etc.
- Deep understanding of network protocols, operating systems (Windows, Linux), and application security.
Preferred Qualifications:
- CRT (CREST Registered Tester) certification is preferred.
- Other relevant certifications such as OSCP, OSWE, CPT, CEH, GPEN, or CISSP.
- Knowledge of cloud security testing in platforms like AWS, Azure, or Google Cloud.
- Familiarity with container security (e.g., Docker, Kubernetes) and DevSecOps practices.
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
About the Role
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
- Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
- Propose measures to ensure that identified vulnerabilities are addressed.
- Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
- Simulate cyber attacks to evaluate defensive measures and improve security posture.
Requirements
- Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
- Experience conducting secure code review.
- Degree in computer science/computer engineering/information security or equivalent.
- Working knowledge of all aspects of information security is essential.
- Familiarity with systems and operational architecture of large internet companies or online business models.
- Good communication (spoken and written) skills, able to work independently and as a team.
- Certifications from either GIAC/Offensive Security/CREST required.
- Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
- Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
渗透测试专家
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统、应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性、确保合规性并降低运营风险,直接支持审计目标。
主要职责
- 对应用程序、数据库、系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
- 提出措施,确保已识别的漏洞得到解决。
- 与IT、风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
- 模拟网络攻击,评估防御措施并提升安全态势。
职位要求
- 至少5年Web应用程序、移动应用程序、API、网络、数据库和负载测试的渗透测试经。
- 具备安全代码审查经验。
- 计算机科学/计算机工程/信息安全或同等学历。
- 具备信息安全各方面的工作知识。
- 熟悉大型互联网公司或在线商业模式的系统和运营架构。
- 良好的沟通能力,能够独立工作和团队合作。
- 需持有GIAC/Offensive Security/CREST认证。
- 具有 Kali Linux、Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
- 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Information Security
Transaction Processing
Remediation
Oracle SQL
Mainframe
Assessor
Penetration Testing
Mobile Applications
DB2
Web Applications
Kali Linux
Small Business
Mortgage Banking
Databases
Field Work
Audit
Security Consultant (Penetration Testing)
Posted 5 days ago
Job Viewed
Job Description
NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse workforce of 13,000 has delivered large-scale, mission-critical, and multi-platform projects for governments and enterprises in Singapore and the APAC region.
As a Security Consultant provides expert IT security consultancy and advisory services, helping to
secure cyber assets, including networks, mobile applications, web applications, and IoT devices. The role involves security system configuration, source code review, and penetration testing.
What will you do?
- Conduct technical security assessments, including penetration testing, source code review, and security configuration analysis.
- Utilize industry-recognized processes and tools to identify and assess security vulnerabilities, aligning with strategic, tactical, and operational security objectives.
- Work closely with clients and internal teams to deliver eƯective security solutions and recommendations.
- Perform compliance audits and system reviews against industry best practices, security policies, and procedural guidelines.
- Clearly articulate security findings through detailed reports and presentations, tailored for both technical and non-technical stakeholders
The ideal candidate should possess:
- Experience in penetration testing, source code review, and host security assessments.
- Strong technical expertise in security testing methodologies, tools, and frameworks such as Metasploit, Kali Linux, Burp Suite, and Tenable Nessus.
- Proficiency in scripting languages (e.g., Python, Bash, or PowerShell) for security automation and testing.
- Solid understanding of web application technologies, network security principles, and the OSI model (including HTTP, DNS, SSH, FTP, etc.).
- Familiarity with established security testing methodologies, including the OWASP Web
- Security Testing Guide (OWSTG) and the Penetration Testing Execution Standard (PTES).Relevant industry certifications (e.g., OSCP, CREST CRT) are highly advantageous.
- Strong interpersonal and communication skills, with the ability to collaborate eƯectively in a team environment.
- A degree in cybersecurity, computer science, or a related field is preferred; however, candidates with a diploma or equivalent experience will be considered.
We are driven by our AEIOU beliefs—Adventure, Excellence, Integrity, Ownership, and Unity —and we seek individuals who embody these values in both their professional and personal lives. We are committed to our Impact: Valuing our clients, Growing our people, and Creating our future .
Together, we make the extraordinary happen .
Learn more about us at ncs.co and visit our LinkedIn career site.
Security Consultant (Penetration Testing)
Posted 5 days ago
Job Viewed
Job Description
The Security Consultant delivers penetration testing & offensive security projects to ensure a successful
outcome that at least meets or exceeds the expectations of our clients.
Role Outcomes:- The customer recognises you as a subject matter expert and they have confidence in the comprehensiveness of the testing methodology and the accuracy of the results.
- The client has prepared the testing environment prior to the project start date so that the engagement is executed smoothly and without delay.
- Penetration testing projects are delivered efficiently and on schedule.
- The quality of the Penetration Testing Report by ensuring it has been peer reviewed and approved for release to the client.
- All client data is managed in strict accordance with Vantage Point Security data security and protection policies throughout the project.
Cybersecurity Specialist - Cloud Penetration Testing
Posted today
Job Viewed
Job Description
Job Title:
Cybersecurity Specialist - Cloud Penetration Testing
Overview of the Role
This is a hands-on position that requires expertise in cloud security, particularly within AWS environments.
The successful candidate will be responsible for conducting comprehensive Cloud VAPT (Vulnerability Assessment and Penetration Testing) across AWS environments, identifying and exploiting vulnerabilities in cloud-based infrastructure, services, and configurations, and producing detailed assessment reports with actionable recommendations.
This role involves working closely with internal teams and clients to implement security improvements and providing expert-level guidance on offensive security best practices in cloud deployments.
The candidate will also support client-facing discussions and onsite engagements.
Required Skills and Qualifications
- Mandatory Certifications: OSCP (Offensive Security Certified Professional), AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate and/or Professional, AWS Certified Cloud Practitioner
- Technical Skills & Experience: Strong background in cloud-based penetration testing (AWS), Hands-on experience in vulnerability assessment, red teaming, and offensive security, Solid understanding of AWS cloud architecture and security configurations, Strong knowledge of network protocols, cloud IAM, encryption, and container security, Good reporting and documentation skills, Comfortable working onsite and directly with client teams, Excellent verbal and written communication skills
Key Responsibilities
- Conduct Cloud VAPT across AWS environments
- Identify and exploit vulnerabilities in cloud-based infrastructure, services, and configurations
- Produce detailed assessment reports with actionable recommendations
- Work closely with internal teams and clients to implement security improvements
- Provide expert-level guidance on offensive security best practices in cloud deployments
- Support client-facing discussions and onsite engagements
Penetration Tester - Cloud VAPT (Vulnerability Assessment and Penetration Testing)
Posted 5 days ago
Job Viewed
Job Description
Job Description:
- Need to have experience good experience in the specific Penetration Testing.
- Experience in Vulnerability Assessment, and Offensive Security.
- Proficient in network, web application, and API testing.
- Good communication skills.
- Mandatory to have OSCP Certification.
Also require certification in :
- AWS Certified Security Specialization
- AWS Certified Solutions Architect – Associate
- AWS Certified Solutions Architect – Professional
- AWS Certified Cloud Practitioner.
Be The First To Know
About the latest Penetration testing Jobs in Singapore !
Security Testing Specialist
Posted 2 days ago
Job Viewed
Job Description
Join to apply for the Security Testing Specialist role at OCBC .
Who We Are
As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. We provide support, services, solutions, and career paths tailored to our clients’ needs.
Today, we’re on a journey of transformation, leveraging technology and creativity to become a future-ready learning organisation. Our strategic ambition is to be Asia’s leading financial services partner for a sustainable future.
We invite you to build the bank of the future, innovate in financial services, work in supportive teams, and build lasting value in your community. Enjoy a vibrant, future-ready career with us.
Your Opportunity Starts Here.
Why Join
Protecting our customers' assets and data is central to our mission. As a Security Testing Specialist, you'll play a key role in safeguarding our systems from cyber threats, shaping the future of cybersecurity in finance.
How you succeed
Stay ahead of emerging threats, collaborate with engineering teams to identify and mitigate risks, and develop strategies to enhance cybersecurity.
What you do
- Perform application penetration testing on web-based applications, APIs
- Conduct mobile application penetration testing across platforms
- Perform network penetration testing
- Exploit vulnerabilities to assess security risks
- Document security issues and recommend mitigations
- Research latest security topics and attack vectors
- Conduct compliance testing per standards like MAS TRMG
- Perform secure code reviews when needed
- Conduct thick client penetration testing as required
- Minimum 3 years of hands-on penetration testing experience
- Experience with secure code review
- Degree in computer science, security, or related field
- Knowledge of all aspects of information security
- Familiarity with MAS TRMG and regulatory requirements
- Strong communication skills, able to work independently and in teams
- Certifications from GIAC, Offensive Security, CREST
- Hands-on experience with Kali Linux, Burp Suite, Tenable, and similar tools
- Experience conducting penetration testing for banks in Singapore preferred
- Experience with legacy systems review is a plus
Senior Cyber Security Testing Specialist
Posted 1 day ago
Job Viewed
Job Description
Select how often (in days) to receive an alert:
Senior Cyber Security Testing SpecialistSeeking a highly skilled and motivated Senior Cyber Security Testing Specialist who is skilled in application and infrastructure penetration testing, vulnerability assessment and secure code review to conduct, guide and review the work of external and cross function team security testers. In this role, you will be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Your expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders
Make An Impact By
- Coordinate and Oversee Penetration Testing & Vulnerability Assessment Engagements:
- Manage and coordinate penetration testing and vulnerability assessment engagements with external vendors, ensuring effective communication and collaboration between internal stakeholders and vendors.
- Work closely with Domain security champions to review and tailor the scope, rules of engagement, testing methodologies, and reporting for external penetration tests and vulnerability assessments.
- Collaborate with cross-functional teams to provide guidance on Singtel's security standards, recommend best practices, and advise on effective remediation strategies.
- Review penetration testing reports, prioritize identified vulnerabilities, and coordinate efforts to address them in a timely manner.
- Track and report on the progress and outcomes of penetration testing and vulnerability assessments, ensuring that all findings are addressed appropriately.
- Maintenance of tools and Conduct Various Penetration Tests:
- Perform different types of penetration testing (e.g., AI models, application, API, Infrastructure, etc.) following recognized methodologies, including OWASP and Singtel’s internal standards, utilizing both manual and automated testing methods, as needed.
- Maintain and configure the tests required of automated testing tools to support black box and white box testing, and ensure alignment with latest industry test requirements e.g. OWASP, covering all forms of technologies e.g. Cloud Apps, On-prem Apps, COTS products, In-house developed Apps, AI models, APIs, OS, DB, VM, Network devices, etc.
- Identify gaps in automated testing tools and propose new tooling required to augment testing program as needed
- Bug Bounty Program Management:
- Oversee and manage the bug bounty program and associated platforms for identifying and addressing reported vulnerabilities.
- Validate/ triage the reported vulnerabilities, assess their impact on Singtel’s systems, and collaborate with relevant stakeholders to prioritize and remediate the issues.
- Track and report on findings and outcomes from the bug bounty program to ensure timely resolution.
- Develop engaging programs to boost the visibility and popularity of Singtel's bug bounty program.
- Manage and conduct secure code reviews using scanning tools and techniques to identify security weaknesses in software code.
- Analyze the results from code scans and work closely with development teams to implement necessary security fixes.
- Assist in the creation and implementation of secure coding practices across the organization.
- Vulnerability Retesting and Documentation:
- Retest security vulnerabilities arising from various sources e.g. Bug Bounty, Penetration testing, etc. after remediation and update reports with the latest results and outcomes.
- Develop and maintain comprehensive documentation for all vulnerability assessments, secured code reviews and penetration tests, including detailed findings, methodologies, and recommendations for improvements etc.
- Stay Current with Security Trends and Threats:
- Continuously monitor the latest security trends, emerging vulnerabilities, and attack techniques to ensure that security testing methodologies and tools remain up-to-date and effective.
Skills for Success:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Attained OSCP or CREST.
- At least 5 years of experience working in Cyber and Information security field
- Solid experience in application security testing, vulnerability assessment, secure code review and penetration testing.
- Proficiency in performing AI models, API and application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
- Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
- Out of which, at least 3 years experience in delivering various AI model, API, application, infrastructure penetration testing, vulnerability assessment and secure code review.
- Proficiency in performing AI model, API and application security assessment using manual techniques.
- Proficient in using and managing various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, Guardrails AI, Giskard, Moonshot, Deepcheck, Evidently, Pyrit, Adversarial Robustness Toolbox (ART), PyRIT, etc.
Rewards that Go Beyond
- Full suite of health and wellness benefits
- Ongoing training and development programs
- Internal mobility opportunities
Are you ready to say hello to BIG Possibilities?
Take the leap with Singtel to unlock new opportunities and accelerate your growth. Apply now and start your empowering career!
#J-18808-LjbffrSenior Cyber Security Testing Specialist
Posted 1 day ago
Job Viewed
Job Description
Seeking a highly skilled and motivated Senior Cyber Security Testing Specialist who is skilled in application and infrastructure penetration testing, vulnerability assessment and secure code review to conduct, guide and review the work of external and cross function team security testers. In this role, you will be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Your expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders.
Make An Impact By
- Coordinate and Oversee Penetration Testing & Vulnerability Assessment Engagements:
- Manage and coordinate penetration testing and vulnerability assessment engagements with external vendors, ensuring effective communication and collaboration between internal stakeholders and vendors.
- Work closely with Domain security champions to review and tailor the scope, rules of engagement, testing methodologies, and reporting for external penetration tests and vulnerability assessments.
- Collaborate with cross-functional teams to provide guidance on Singtel's security standards, recommend best practices, and advise on effective remediation strategies.
- Review penetration testing reports, prioritize identified vulnerabilities, and coordinate efforts to address them in a timely manner.
- Track and report on the progress and outcomes of penetration testing and vulnerability assessments, ensuring that all findings are addressed appropriately.
- Maintenance of tools and Conduct Various Penetration Tests:
- Perform different types of penetration testing (e.g., AI models, application, API, Infrastructure, etc.) following recognized methodologies, including OWASP and Singtel’s internal standards, utilizing both manual and automated testing methods, as needed.
- Maintain and configure the tests required of automated testing tools to support black box and white box testing, and ensure alignment with latest industry test requirements e.g. OWASP, covering all forms of technologies e.g. Cloud Apps, On-prem Apps, COTS products, In-house developed Apps, AI models, APIs, OS, DB, VM, Network devices, etc.
- Identify gaps in automated testing tools and propose new tooling required to augment testing program as needed.
- Bug Bounty Program Management:
- Oversee and manage the bug bounty program and associated platforms for identifying and addressing reported vulnerabilities.
- Validate/ triage the reported vulnerabilities, assess their impact on Singtel’s systems, and collaborate with relevant stakeholders to prioritize and remediate the issues.
- Track and report on findings and outcomes from the bug bounty program to ensure timely resolution.
- Develop engaging programs to boost the visibility and popularity of Singtel's bug bounty program.
- Manage and conduct secure code reviews using scanning tools and techniques to identify security weaknesses in software code.
- Analyze the results from code scans and work closely with development teams to implement necessary security fixes.
- Assist in the creation and implementation of secure coding practices across the organization.
- Vulnerability Retesting and Documentation:
- Retest security vulnerabilities arising from various sources e.g. Bug Bounty, Penetration testing, etc. after remediation and update reports with the latest results and outcomes.
- Develop and maintain comprehensive documentation for all vulnerability assessments, secured code reviews and penetration tests, including detailed findings, methodologies, and recommendations for improvements etc.
- Stay Current with Security Trends and Threats:
- Continuously monitor the latest security trends, emerging vulnerabilities, and attack techniques to ensure that security testing methodologies and tools remain up-to-date and effective.
Skills for Success:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Attained OSCP or CREST.
- At least 5 years of experience working in Cyber and Information security field.
- Solid experience in application security testing, vulnerability assessment, secure code review and penetration testing.
- Proficiency in performing AI models, API and application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
- Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
- Out of which, at least 3 years experience in delivering various AI model, API, application, infrastructure penetration testing, vulnerability assessment and secure code review.
- Proficiency in performing AI model, API and application security assessment using manual techniques.
- Proficient in using and managing various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, Guardrails AI, Giskard, Moonshot, Deepcheck, Evidently, Pyrit, Adversarial Robustness Toolbox (ART), PyRIT, etc.
Rewards that Go Beyond
- Full suite of health and wellness benefits.
- Ongoing training and development programs.
- Internal mobility opportunities.
Are you ready to say hello to BIG Possibilities?
Take the leap with Singtel to unlock new opportunities and accelerate your growth. Apply now and start your empowering career!
#J-18808-Ljbffr