7 Security Assessments jobs in Singapore
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
- Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
- Propose measures to ensure that identified vulnerabilities are addressed.
- Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
- Simulate cyber attacks to evaluate defensive measures and improve security posture.
- Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
- Experience conducting secure code review.
- Degree in computer science/computer engineering/information security or equivalent.
- Working knowledge of all aspects of information security is essential.
- Familiarity with systems and operational architecture of large internet companies or online business models.
- Good communication (spoken and written) skills, able to work independently and as a team.
- Certifications from either GIAC/Offensive Security/CREST required.
- Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
- Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统,应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性,确保合规性并降低运营风险,直接支持审计目标。
主要职责
- 对应用程序,数据库,系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
- 提出措施,确保已识别的漏洞得到解决。
- 与IT,风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
- 模拟网络攻击,评估防御措施并提升安全态势。
- 至少5年Web应用程序,移动应用程序,API,网络,数据库和负载测试的渗透测试经。
- 具备安全代码审查经验。
- 计算机科学/计算机工程/信息安全或同等学历。
- 具备信息安全各方面的工作知识。
- 熟悉大型互联网公司或在线商业模式的系统和运营架构。
- 良好的沟通能力,能够独立工作和团队合作。
- 需持有GIAC/Offensive Security/CREST认证。
- 具有 Kali Linux,Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
- 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
Seeking a skilled Cybersecurity Expert to enhance our team's security posture through thorough penetration testing and expert advice.
Job Title: Penetration TesterKey Responsibilities:
- Conduct comprehensive penetration tests on networks, web applications, and systems to identify vulnerabilities and recommend strategic improvements.
- Develop and execute custom test cases, scenarios, and scripts to simulate real-world attack vectors.
- Collaborate with stakeholders to improve the organization's overall security and client relationships.
- Stay up-to-date with the latest cybersecurity threats, trends, and technologies.
- Provide technical guidance on security best practices and strategies for securing information systems.
- Assist in threat modeling, security architecture reviews, and the implementation of secure solutions.
Requirements:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
- Proven experience in penetration testing across various domains (network, web, mobile, cloud, etc.).
- Strong knowledge of penetration testing tools such as Nmap, Metasploit, Burp Suite, Wireshark, Nessus, Kali Linux, etc.
- Deep understanding of network protocols, operating systems (Windows, Linux), and application security.
Preferred Qualifications:
- CRT (CREST Registered Tester) certification is preferred.
- Other relevant certifications such as OSCP, OSWE, CPT, CEH, GPEN, or CISSP.
- Knowledge of cloud security testing in platforms like AWS, Azure, or Google Cloud.
- Familiarity with container security (e.g., Docker, Kubernetes) and DevSecOps practices.
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
About the Role
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
- Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
- Propose measures to ensure that identified vulnerabilities are addressed.
- Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
- Simulate cyber attacks to evaluate defensive measures and improve security posture.
Requirements
- Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
- Experience conducting secure code review.
- Degree in computer science/computer engineering/information security or equivalent.
- Working knowledge of all aspects of information security is essential.
- Familiarity with systems and operational architecture of large internet companies or online business models.
- Good communication (spoken and written) skills, able to work independently and as a team.
- Certifications from either GIAC/Offensive Security/CREST required.
- Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
- Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
渗透测试专家
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统、应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性、确保合规性并降低运营风险,直接支持审计目标。
主要职责
- 对应用程序、数据库、系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
- 提出措施,确保已识别的漏洞得到解决。
- 与IT、风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
- 模拟网络攻击,评估防御措施并提升安全态势。
职位要求
- 至少5年Web应用程序、移动应用程序、API、网络、数据库和负载测试的渗透测试经。
- 具备安全代码审查经验。
- 计算机科学/计算机工程/信息安全或同等学历。
- 具备信息安全各方面的工作知识。
- 熟悉大型互联网公司或在线商业模式的系统和运营架构。
- 良好的沟通能力,能够独立工作和团队合作。
- 需持有GIAC/Offensive Security/CREST认证。
- 具有 Kali Linux、Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
- 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Information Security
Transaction Processing
Remediation
Oracle SQL
Mainframe
Assessor
Penetration Testing
Mobile Applications
DB2
Web Applications
Kali Linux
Small Business
Mortgage Banking
Databases
Field Work
Audit
Security Consultant (Penetration Testing)
Posted 4 days ago
Job Viewed
Job Description
NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse workforce of 13,000 has delivered large-scale, mission-critical, and multi-platform projects for governments and enterprises in Singapore and the APAC region.
As a Security Consultant provides expert IT security consultancy and advisory services, helping to
secure cyber assets, including networks, mobile applications, web applications, and IoT devices. The role involves security system configuration, source code review, and penetration testing.
What will you do?
- Conduct technical security assessments, including penetration testing, source code review, and security configuration analysis.
- Utilize industry-recognized processes and tools to identify and assess security vulnerabilities, aligning with strategic, tactical, and operational security objectives.
- Work closely with clients and internal teams to deliver eƯective security solutions and recommendations.
- Perform compliance audits and system reviews against industry best practices, security policies, and procedural guidelines.
- Clearly articulate security findings through detailed reports and presentations, tailored for both technical and non-technical stakeholders
The ideal candidate should possess:
- Experience in penetration testing, source code review, and host security assessments.
- Strong technical expertise in security testing methodologies, tools, and frameworks such as Metasploit, Kali Linux, Burp Suite, and Tenable Nessus.
- Proficiency in scripting languages (e.g., Python, Bash, or PowerShell) for security automation and testing.
- Solid understanding of web application technologies, network security principles, and the OSI model (including HTTP, DNS, SSH, FTP, etc.).
- Familiarity with established security testing methodologies, including the OWASP Web
- Security Testing Guide (OWSTG) and the Penetration Testing Execution Standard (PTES).Relevant industry certifications (e.g., OSCP, CREST CRT) are highly advantageous.
- Strong interpersonal and communication skills, with the ability to collaborate eƯectively in a team environment.
- A degree in cybersecurity, computer science, or a related field is preferred; however, candidates with a diploma or equivalent experience will be considered.
We are driven by our AEIOU beliefs—Adventure, Excellence, Integrity, Ownership, and Unity —and we seek individuals who embody these values in both their professional and personal lives. We are committed to our Impact: Valuing our clients, Growing our people, and Creating our future .
Together, we make the extraordinary happen .
Learn more about us at ncs.co and visit our LinkedIn career site.
Security Consultant (Penetration Testing)
Posted 4 days ago
Job Viewed
Job Description
The Security Consultant delivers penetration testing & offensive security projects to ensure a successful
outcome that at least meets or exceeds the expectations of our clients.
Role Outcomes:- The customer recognises you as a subject matter expert and they have confidence in the comprehensiveness of the testing methodology and the accuracy of the results.
- The client has prepared the testing environment prior to the project start date so that the engagement is executed smoothly and without delay.
- Penetration testing projects are delivered efficiently and on schedule.
- The quality of the Penetration Testing Report by ensuring it has been peer reviewed and approved for release to the client.
- All client data is managed in strict accordance with Vantage Point Security data security and protection policies throughout the project.
Penetration Tester - Cloud VAPT (Vulnerability Assessment and Penetration Testing)
Posted 4 days ago
Job Viewed
Job Description
Job Description:
- Need to have experience good experience in the specific Penetration Testing.
- Experience in Vulnerability Assessment, and Offensive Security.
- Proficient in network, web application, and API testing.
- Good communication skills.
- Mandatory to have OSCP Certification.
Also require certification in :
- AWS Certified Security Specialization
- AWS Certified Solutions Architect – Associate
- AWS Certified Solutions Architect – Professional
- AWS Certified Cloud Practitioner.
Interesting Opportunity Information Security Consultant - Penetration Testing
Posted today
Job Viewed
Job Description
- The ideal candidate for this position should have a strong foundation in subject knowledge related to Information security, Cyber Security, and Data Privacy. Proficiency in Security Analysis, Network Security, and a good understanding of technology is essential, with IT certification being preferred.A minimum educational qualification of Graduation is required for this role. The candidate should possess 4 to 10 years of experience in Information Security, with a minimum of 2 years specifically in information security within the BFSI Insurance sector. Certifications such as OSCP, CEH, CISSP, CISA, CISM, and ISO 27001:2013 LA would be advantageous.As a part of this role, you will be responsible for managing Information Security Projects, Audits, and assessments. Conducting Technology Risk Assessments for processes and technologies, developing and reviewing IS standards, guidelines for new technologies, and performing periodic audits and assessments as per the Infosec calendar will be key responsibilities.You will also be accountable for establishing IS Standards, Checklists, and Guidelines, including managing internal and third-party Ethical hacking, Vulnerability Assessment, Penetration Testing, and Red Team assessment activities. Developing methodologies and checklists for performing Technology Risk Assessments and approval matrix based on the results, as well as defining BCP/DR standards, application security standards, and Vendor risk assessment standards are crucial aspects of this role.Collaboration with business teams to define roles within each application, reviewing training requirements for SOC/LAM/DLP teams, managing Information Security Projects and assessments, performing daily InfoSec operational activities, conducting Cyber security drills, monitoring and managing Information/Cyber Security Incidents, and supporting response and investigation activities related to cyber crises are part of the job responsibilities.Additionally, you will be required to assign detailed responsibilities and action steps to manage cyber crises, identify active risks and threat vectors, review regulatory impact and compliance obligations, and undertake any other tasks, activities, or projects delegated by the Chief Risk Officer (CRO) or Chief Information Security Officer (CISO).This position is based in Mumbai.,
- Job Tags information security, cyber security
- Interesting Opportunity Information Security Consultant - Penetration Testing
Sign-in & Get noticed by top recruiters and get hired fast
Data Privacy, Security Analysis, Network Security,Good understanding of technology
Information Security, Analytical Skills, Leadership Skills, Communication Skills,Cybersecurity, Problemsolving Skills
Business Impact Analysis, Risk Management, Identity , Access Management, Infrastructure Security, Application Security, Cloud Security, SOX, ISO, PII, Privacy Regulations, MS Office, Compliance, ITIL, GCP, Azure, AWS, Penetration Testing,Cyber Security Auditor, Corrective Action Plan, Information Security Policy, Data Governance , Security, Third Party Risk Management, PCI, NIST CSF, NIST 80053, NIST RMF, MS Teams, Threat Hunting, DFIR, Zero Trust Architectures, Network Protection
Application Security, Malware Analysis, Communication Skills, Presentation Skills, Adaptability,Cybersecurity, Cybersecurity Principles, IT Industry
Data Privacy, Security Analysis, Network Security,Good understanding of technology
Information Security, Analytical Skills, Leadership Skills, Communication Skills,Cybersecurity, Problemsolving Skills
Business Impact Analysis, Risk Management, Identity , Access Management, Infrastructure Security, Application Security, Cloud Security, SOX, ISO, PII, Privacy Regulations, MS Office, Compliance, ITIL, GCP, Azure, AWS, Penetration Testing,Cyber Security Auditor, Corrective Action Plan, Information Security Policy, Data Governance , Security, Third Party Risk Management, PCI, NIST CSF, NIST 80053, NIST RMF, MS Teams, Threat Hunting, DFIR, Zero Trust Architectures, Network Protection
Application Security, Malware Analysis, Communication Skills, Presentation Skills, Adaptability,Cybersecurity, Cybersecurity Principles, IT Industry
ACTIVELY HIRING
Information Security Consultant Related Jobs #J-18808-LjbffrBe The First To Know
About the latest Security assessments Jobs in Singapore !