Associate Engineer, Security Testing and Red Teaming

Ensign InfoSecurity

Singapore

On-site

SGD 60,000 - 90,000

Full time

46 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ensign InfoSecurity is seeking an Associate Consultant to conduct penetration testing engagements across web apps, networks, cloud, mobile, IoT, and OT in Singapore.

Under guidance of senior consultants, you will document findings, support reports, and participate in scoping calls and peer reviews, while continuously developing offensive security skills.

This role requires OSCP, strong methodology knowledge, and hands-on tool experience with Burp Suite, Nmap, Metasploit, BloodHound.

Qualifications

  • OSCP certification is required.
  • Strong understanding of penetration testing methodologies.
  • Foundations in Windows and Linux operating systems.
  • Exposure to common vulnerability classes and security concepts.
  • Experience with scripting or programming helps.

Responsibilities

  • Conduct penetration testing engagements under guidance of senior consultants.
  • Perform web app, network, cloud, mobile, IoT, and OT testing.
  • Identify, validate and exploit vulnerabilities using tools and manual techniques.
  • Document findings with evidence and remediation recommendations.
  • Assist in preparing high-quality technical reports and executive summaries.
  • Participate in kickoff calls, scoping discussions and post-engagement briefings.
  • Collaborate with team members during testing, including peer reviews and walkthroughs.
  • Maintain testing notes, logs and artifacts for QA and reporting.
  • Stay current with vulnerabilities, attack techniques, and tooling.
  • Contribute to broader offensive security activities such as red teaming and tooling development.

Skills

Penetration testing
Ethical hacking
Scripting (Python/Bash)
Documentation
Team collaboration

Tools

Burp Suite
Nmap
Metasploit
BloodHound

Job description

Associate Consultant, Security Testing and Red Teaming
Roles and Responsibilities

Conduct penetration testing engagements under the guidance of senior consultants, including:

  • Web application penetration testing
  • Network and infrastructure penetration testing (internal and external)
  • Cloud security testing (e.g. AWS, Azure, GCP)
  • Mobile application penetration testing
  • IOT penetration testing
  • OT penetration testing

Execute assigned testing activities responsibly and professionally, following defined scopes, rules of engagement, and methodologies.

Identify, validate, and exploit security vulnerabilities using industry-standard tools and manual techniques.

Document findings clearly and accurately, including technical details, evidence, and remediation recommendations.

Assist in preparing high-quality technical reports and contribute to executive-level summaries.

Participate in engagement activities such as kick-off calls, scoping discussions, and post-engagement briefings where appropriate.

Collaborate with team members during testing, including peer reviews and technical walkthroughs.

Maintain detailed testing notes, logs, and artifacts to support quality assurance and reporting.

Continuously develop technical skills across penetration testing, exploitation techniques, and security fundamentals.

Stay current with emerging vulnerabilities, attack techniques, and offensive security tooling.

Over time, support or participate in broader offensive security activities, such as:

  • Adversary simulation and red teaming exercises
  • Automation or tooling development
  • Security research and proof-of-concept development
Requirements

Offensive Security Certified Professional (OSCP) certification is required.

Strong understanding of penetration testing methodologies and ethical hacking principles.

Solid foundations in:

  • TCP/IP networking
  • Operating systems (Windows and Linux)
  • Web application architecture and common vulnerabilities

Exposure to scripting or programming (e.g. Python, Bash, PowerShell).

Familiarity with common vulnerability classes (e.g. OWASP Top 10, misconfigurations, credential abuse).

Basic understanding of Active Directory security concepts.

Exposure to cloud platforms or containerised environments will be useful.

Hands‑on experience using common penetration testing tools (e.g. Burp Suite, Nmap, Metasploit, BloodHound).

Ability to write clear, structured, and technically accurate documentation and reports.

Strong desire to grow into advanced offensive security and red teaming roles.

Strong analytical mindset and problem-solving skills.

Professional conduct, integrity, and respect for confidentiality.

About Ensign InfoSecurity

Ensign InfoSecurity is the largest pure-play cybersecurity service provider in Asia.

The company is headquartered in Singapore.

We specialise in the provision of these services; cybersecurity advisory and assurance, implementation and management of advanced cybersecurity controls, cybersecurity monitoring, threat hunting, and incident response.

Underpinning these competencies is in‑house research and development in cybersecurity.

What Makes Ensign Special?

We are a technology company with warmth and soul.

We are ambitious, propelled by our vision to be the cyber defender of choice, and fueled by the dedication and camaraderie of individuals who are eager to make a difference, and leave their footprints in the industry.

If you are a self‑motivated curious go‑getter, we want You!

Join Us!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Consultant, Security Testing and Red Teaming
Associate Consultant, Security Testing and Red Teaming

Ensign InfoSecurity • Singapore

On-site
SGD 60,000 - 90,000
Team Lead, Vulnerability Assessment and Penetration Testing
Team Lead, Vulnerability Assessment and Penetration Testing

Ensign InfoSecurity • Singapore

On-site
SGD 120,000 - 190,000
Associate Security Testing & Red Team Engineer
Associate Security Testing & Red Team Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 60,000 - 90,000
Consultant, Security Testing and Red Teaming
Consultant, Security Testing and Red Teaming

Ensign InfoSecurity • Singapore

On-site
SGD 100,000 - 160,000
Security Consultant
Security Consultant

SOFTSCHECK SINGAPORE PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
Red Teaming & Security Testing Consultant
Red Teaming & Security Testing Consultant

Ensign InfoSecurity • Singapore

On-site
SGD 100,000 - 160,000
Consultant, Security Testing and Red Teaming
Consultant, Security Testing and Red Teaming

re-zoo-me • Singapore

Hybrid
SGD 90,000 - 130,000
Senior Cybersecurity Consultant (IAM)
Senior Cybersecurity Consultant (IAM)

Ensign InfoSecurity • Singapore

Hybrid
SGD 120,000 - 180,000
Associate Software Engineer (AI Engineering)
Associate Software Engineer (AI Engineering)

Ensign InfoSecurity • Singapore

On-site
SGD 90,000 - 130,000
Intern, AI Engineer
Intern, AI Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 60,000 - 100,000