Penetration Test & Vulnerability Assessment Specialist
Full Time
Singapore
Posted
Job description
What the role is
The Government Technology Agency (GovTech) seeks to transform the delivery of Government Digital Services by taking an "outside-in" view, putting citizens and businesses at the heart of everything we do. We also develop the Smart Nation infrastructure and applications, and facilitate collaboration with the public to co-develop technologies. Join us as we support Singapore’s vision of building a Smart Nation - a nation of possibilities empowered through info-communications technology and related engineering. Do you want to play a critical role in securing our smart nation initiatives by uncovering weaknesses in various domains of cybersecurity programs even before the real threat actors come to play? And are you up to race against the real threat actors before organisations are compromised? We are seeking a cybersecurity specialist in penetration testing & vulnerability assessment to join our Cyber Security Group’s Red Team. You will be part of the team that helps to protect our government’s assets from cyber-attacks. In addition, you will also have the opportunities to be involved in assessing the cybersecurity aspects of new developments in our smart nation initiatives, and demonstrate ability to quickly assimilate to knowledge in new technologies. As part of this team, you will perform penetration testing and vulnerability assessment that span across infrastructure, web application, mobile application, source code security review, etc. This role will also involve you in carrying targeted Adversary Simulations.
What you will be working on
• Conduct Penetration Testing (PT), Vulnerability Assessment (VA) and Source code security review on IT assets • Support in the documentation of findings, analysis, report preparation and presentation • Develop customised tools to conduct PT and VA • Support stakeholders such as security engineers and developers in providing guidance to remediate security risks from security testing and assessments. • Support stakeholders such as security engineers and developers in providing guidance in design and security controls in application, infrastructure, network, etc. • Develop Application Security related awareness programme/training/courses to uplift application security capabilities and competencies of GovTech officers • Familiar with security principles, policies and industry best practices
What we are looking for
• Degree in Information Security, Computer Science/Engineering, IT, or equivalent • Passionate in cybersecurity • Good understanding of web application, system and infrastructure architecture • Good communication & presentation skills • Collaborative and team player, self-motivated, creative and versatile Added advantage if you possess the following: • Penetration testing-specific certifications such as GPEN, CREST, OSCP is an advantage • At least 1-year hands-on experience performing PT/VA • Familiar with scripting language, for example, Perl, Python, VBscript, Javascript or Powershell, Ruby • Public disclosure of vulnerabilities or relevant awards/participations from Capture-The-Flags (CTF) competitions • Experience using tools such as Nexpose/Nessus, BurpSuite, Metasploit, etc. • Experience in security risk assessments on application, infrastructure, network, etc.
apartamentosquality.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, apartamentosquality.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, apartamentosquality.com is the ideal place to find your next job.