26984754 Senior Penetration Tester (Cyber Security)

CITIBANK N.A.

Singapore

On-site

SGD 120,000 - 180,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

None

Job summary

Citi Singapore is seeking a Senior Penetration Tester with deep expertise in vulnerability research, whitebox testing, and source code review to identify complex security issues across applications and APIs.

You will work with development teams to provide remediation guidance and contribute to tooling, automated testing, and ongoing security posture improvements.

Qualifications

  • 6+ years of experience in penetration testing with a focus on whitebox testing.
  • Proven vulnerability research skills and exploit development.
  • Strong programming skills in Java, C#, Python.
  • Familiarity with OWASP Top 10 and API security best practices.
  • Industry certifications such as OSCE, GIAC GWAPT, GPEN, GXPN, or similar.

Responsibilities

  • Vulnerability Research & Exploitation: research to discover new attack vectors and develop POC exploits.
  • Whitebox Penetration Testing: use source code and internal knowledge to uncover flaws.
  • Source Code Review: review code across languages to identify security issues.
  • Third-Party Component Analysis: assess third-party libraries and open-source components.
  • Remediation Guidance: provide actionable fixes to development teams.
  • Tooling & Automation: develop security testing tools and automation.
  • Reporting & Communication: deliver detailed risk reports to technical and non-technical audiences.
  • Stay Current: research latest threats and best practices.

Skills

Penetration testing
Ethical hacking
Application security
Whitebox testing
Source code review
Vulnerability research
Programming (Java, C#, Python)
SAST/DAST tools
Communication
Team collaboration

Tools

SAST tools
DAST tools
Static analysis tools

Job description

Discover your future at Citi


Citi is a preeminent banking partner for institutions with cross-border needs, a global leader in wealth management, and a valued personal bank in its home market of the United States. Citi does business in more than 160 countries and jurisdictions, providing corporations, governments, investors, institutions, and individuals with a broad range of financial products and services.


About the job


Citi is seeking a highly skilled and experienced penetration tester with a specialized focus on vulnerability research, third-party component analysis, and advanced whitebox testing methodologies, including comprehensive source code review. The successful candidate will play a critical role in identifying, exploiting, and providing remediation guidance for complex security vulnerabilities within Citi's diverse technology landscape. This role demands deep technical expertise, a proactive approach to security challenges, and the ability to work collaboratively with development teams to enhance the security posture of our applications and infrastructure.


Who we are


This team specializes in conducting deep-dive penetration testing on a variety of Citi applications (Web, Mobile, Thick Client, and APIs) by manually identifying, researching, validating, and exploiting various known and unknown application security vulnerabilities.


What You’ll Do


As a Senior Penetration Tester on our Offensive Security & Vulnerability Management team, you are responsible for:



  • Vulnerability Research & Exploitation: Conduct in-depth research to discover new attack vectors and zero-day vulnerabilities in enterprise applications, systems, and third-party components. Develop proof-of-concept exploits to effectively demonstrate risk.


  • Whitebox Penetration Testing: Perform comprehensive whitebox penetration tests, leveraging access to source code, design documentation, and internal system knowledge to uncover sophisticated security flaws that blackbox testing might miss.


  • Source Code Review: Conduct manual and automated source code reviews across various programming languages (e.g., Java, C#, Python, JavaScript) to identify security vulnerabilities, misconfigurations, and adherence to secure coding practices.


  • Third-Party Component Analysis: Evaluate the security of third-party libraries, frameworks, and open-source components integrated into Citi's applications. Identify known vulnerabilities (e.g., CVEs) and assess potential risks.


  • Remediation Guidance: Provide clear, concise, and actionable remediation recommendations to development teams, offering expert advice on secure coding, configuration, and architectural solutions.


  • Tooling & Automation: Utilize and contribute to the development of advanced security testing tools, AI-augmented static analysis, and dynamic analysis (DAST) solutions to improve efficiency and coverage.


  • Reporting & Communication: Prepare detailed technical reports outlining findings, risk levels, and recommended mitigations for both technical and non-technical audiences.


  • Stay Current: Continuously research and stay abreast of the latest security threats, vulnerabilities, attack techniques, and industry best practices.



Job Skills/Qualifications:



  • 6+ years of experience in penetration testing, ethical hacking, or application security, with a significant focus on whitebox testing and/or source code review.


  • Proven expertise in vulnerability research, including the ability to identify novel vulnerabilities and develop reliable exploits.


  • Strong proficiency in at least one major programming language (e.g., Java, C#, Python) and familiarity with others.


  • In-depth understanding of common web application vulnerabilities (OWASP Top 10) and API security best practices.


  • Experience with static application security testing (SAST) tools and dynamic application security testing (DAST) tools.


  • Excellent written and verbal communication skills, with the ability to articulate complex security issues to diverse audiences.


  • Ability to work independently and as part of a team in a fast-paced, dynamic environment.


  • Relevant industry certifications such as OSCE, GIAC GWAPT, GPEN, GXPN, or similar.


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Tester (Cyber Security) Vice President
Senior Penetration Tester (Cyber Security) Vice President

Citi • Singapore

On-site
SGD 150,000 - 210,000
Senior Penetration Tester (Cyber Security) Vice President
Senior Penetration Tester (Cyber Security) Vice President

Citigroup Inc. • Singapore

On-site
SGD 180,000 - 240,000
Senior Penetration Tester: Whitebox & AppSec Leader
Senior Penetration Tester: Whitebox & AppSec Leader

Citigroup Inc. • Singapore

On-site
SGD 180,000 - 240,000
Penetration Tester
Penetration Tester

LANTU EMPLOYMENT AGENCY PTE. LTD. • Singapore

On-site
SGD 70,000 - 100,000
Senior Penetration Tester: Whitebox Security & Code Review
Senior Penetration Tester: Whitebox Security & Code Review

Citi • Singapore

On-site
SGD 150,000 - 210,000
Penetration Testing Consultant
Penetration Testing Consultant

SWARMNETICS PTE. LTD. • Singapore

On-site
SGD 60,000 - 100,000
Cybersecurity Pentester
Cybersecurity Pentester

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Penetration Test and Vulnerability Assessment Expert
Penetration Test and Vulnerability Assessment Expert

The Digital and Intelligence Service (DIS) • Singapore

On-site
SGD 90,000 - 150,000
26989093 Information Security Technology Senior Analyst, Penetration Testing
26989093 Information Security Technology Senior Analyst, Penetration Testing

CITIBANK N.A. • Singapore

On-site
SGD 70,000 - 120,000
Penetration Testing Delivery Specialist
Penetration Testing Delivery Specialist

CITIBANK N.A. • Singapore

On-site
SGD 70,000 - 120,000