Consultant, Advanced Adversarial Simulation

Ensign InfoSecurity

Singapore

On-site

SGD 100,000 - 160,000

Full time

39 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ensign InfoSecurity is seeking an experienced security consultant to plan and execute Red Team and Purple Team engagements across diverse environments. You will translate threats into realistic attack scenarios and develop tooling to meet engagement objectives, while maintaining strict operational security and coordinating with customer teams.

The role requires hands-on offensive security experience, strong knowledge of MITRE ATT&CK, and the ability to communicate complex risks to technical and

Qualifications

  • OSCP certification is required.
  • Experience in Red/ Purple Teaming, adversarial simulation, or offensive security.
  • Strong knowledge of MITRE ATT&CK and attack techniques.
  • Hands-on experience with network, Active Directory, Windows, Linux, web apps, cloud, and identity-based attacks.
  • Experience collaborating with defensive security teams to validate and improve controls.
  • Ability to translate findings into clear business risks and actionable remediation recommendations.
  • Excellent report-writing, presentation, and stakeholder-management skills.
  • Willingness to work at customer premises when required and to obtain security clearance if needed.

Responsibilities

  • Plan and conduct authorised Red Team engagements, adversarial simulations, and objective-based assessments.
  • Translate threats and risks into realistic attack scenarios across networks, endpoints, cloud, and identities.
  • Perform recon, initial-access testing, privilege escalation, lateral movement, persistence, and data access simulations when authorised.
  • Assess security controls and expose attack paths that could affect critical assets.
  • Develop or adapt tools, scripts, payloads, and supporting infra to achieve engagement objectives.
  • Maintain operational security and minimise disruption risk throughout engagements.
  • Collaborate with Blue Teams and SOCs in Purple Team engagements; map activities to MITRE ATT&CK.
  • Produce clear technical reports and executive summaries with prioritized remediation.
  • Support remediation planning, validation, and retesting with customers.

Skills

OSCP
Red Teaming
Purple Teaming
MITRE ATT&CK
Python
PowerShell
Bash
C#
Gn proficiency in security reports
Report writing
Stakeholder management
Security clearance eligibility
OSEP
OSED
OSWE
CRTO
CRTE
CREST CRT/CCT
GPEN
GXPN

Education

Degree in cybersecurity/computer science/IT

Tools

Metasploit
Nmap
Burp Suite
Cobalt Strike

Job description

- Plan and conduct authorised Red Team engagements, adversarial simulations, and objective-based security assessments.

- Translate relevant threats and customer risks into realistic attack scenarios.

- Perform reconnaissance, initial-access testing, social engineering, privilege escalation, lateral movement, persistence, and data-access simulations where authorised.

- Assess security controls across networks, endpoints, applications, cloud platforms, identity systems, and operational processes.

- Identify and demonstrate attack paths that could expose critical systems or business assets.

- Develop or adapt tools, scripts, payloads, and supporting infrastructure to achieve engagement objectives.

- Maintain operational security and minimise the risk of unintended disruption throughout each engagement.

Purple Team Engagements

- Collaborate with Blue Teams, Security Operations Centres, incident response teams, and other defensive stakeholders.

- Design and execute controlled attack scenarios to validate preventive, detective, and responsive security controls.

- Map simulated adversary behaviours to recognised frameworks such as MITRE ATT&CK.

- Evaluate security alerts, telemetry, logging coverage, investigation workflows, and response procedures.

- Help defensive teams develop and refine detection rules, use cases, playbooks, and response processes.

- Facilitate knowledge-sharing sessions to explain attacker techniques and strengthen defensive capabilities.

- Conduct validation and retesting to confirm that identified security gaps have been addressed.

- Document improvements and remaining areas of security exposure.

Engagement Planning and Governance

- Define engagement objectives, scope, assumptions, success criteria, and rules of engagement with relevant stakeholders.

- Ensure all activities are conducted within approved legal, ethical, safety, and customer-defined boundaries.

- Follow applicable change-control, data-handling, access-control, and escalation procedures.

- Maintain accurate records of actions, evidence, findings, and attack paths.

- Communicate critical findings, operational concerns, and potential business risks promptly.

- Coordinate with project managers, internal teams, and customer stakeholders throughout the engagement lifecycle.

Reporting and Stakeholder Communication

- Produce clear technical reports, executive summaries, attack narratives, and prioritised remediation recommendations.

- Explain technical findings in terms of their operational and business impact.

- Present engagement outcomes to technical teams, senior management, and executive stakeholders.

- Deliver engagement debriefs and remediation workshops where required.

- Support remediation planning, validation, and retesting.

Capability Development

- Contribute to the improvement of Red Team and Purple Team methodologies, tools, procedures, and knowledge bases.

- Research emerging threats, vulnerabilities, attack techniques, defensive approaches, and security technologies.

- Share technical knowledge, lessons learned, and good practices with team members.

- Support the development of reusable attack scenarios and detection-validation content.

Customer Engagement and Adaptability

- Deliver assignments of varying scope, complexity, and duration based on customer and business needs.

- Work at customer premises when required.

- Adapt to different industries, technologies, operating environments, and levels of security maturity.

- Remain flexible in supporting planned and ad-hoc project requirements.

- Communicate effectively with internal teams and customer stakeholders throughout each assignment.

Requirements:

- Offensive Security Certified Professional (OSCP) is required.

- Advanced or specialist certifications, such as OSEP, OSED, OSWE, CRTO, CRTE, CREST CRT/CCT, GPEN, GXPN, would be advantageous.

- Demonstrated experience in Red Teaming, Purple Teaming, adversarial simulation, penetration testing, or a related offensive security role.

- Strong knowledge of adversary tactics, techniques, and procedures, including the MITRE ATT&CK framework.

- Hands-on experience with network, Active Directory, Windows, Linux, web application, cloud, and identity-based attack techniques.

- Experience collaborating with defensive security teams to validate and improve security controls.

- Understanding of defensive technologies and processes, including SIEM, endpoint detection and response, network monitoring, security logging, threat hunting, and incident response.

- Proficiency with relevant commercial or open-source offensive security tools and frameworks.

- Ability to develop or modify tools and scripts using languages such as Python, PowerShell, Bash, C#, or another relevant programming language.

- Ability to analyse complex attack paths and translate technical findings into clear business risks and actionable recommendations.

- Strong report-writing, presentation, communication, and stakeholder-management skills.

- Sound professional judgement and a strong commitment to ethics, confidentiality, operational security, and authorised testing boundaries.

- Ability to work independently and collaboratively within multidisciplinary teams.

- Willingness and ability to undertake customer-facing assignments of varying duration, including working at customer premises when required.

- Flexibility to support ad-hoc assignments and changing project requirements.

- Eligibility to obtain any security clearance or customer-specific access approval required for assigned engagements.

- A degree or diploma in cybersecurity, computer science, information technology, or a related discipline is preferred; equivalent practical experience will also be considered.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Consultant, Security Testing and Red Teaming
Consultant, Security Testing and Red Teaming

Ensign InfoSecurity • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Pentester
Cybersecurity Pentester

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Senior Security Consultant - OSCP
Senior Security Consultant - OSCP

TECHKNOWLEDGEY PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Penetration Testers/ Red Teamers
Penetration Testers/ Red Teamers

KERRY CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Offensive Security Expert Engineer (Red Team)
Offensive Security Expert Engineer (Red Team)

Shopee • Singapore

On-site
SGD 120,000 - 180,000
Offensive Security Consultant, Red Team, Mandiant Consulting - Singapore
Offensive Security Consultant, Red Team, Mandiant Consulting - Singapore

GOOGLE ASIA PACIFIC PTE. LTD. • Singapore

On-site
SGD 150,000 - 210,000
Lead Red & Purple Team Security Consultant
Lead Red & Purple Team Security Consultant

Ensign InfoSecurity • Singapore

On-site
SGD 100,000 - 160,000
Senior Cyber Ops Specialist (Security Services)
Senior Cyber Ops Specialist (Security Services)

SCIENTE • Singapore

On-site
SGD 120,000 - 180,000
Penetration Tester
Penetration Tester

LANTU EMPLOYMENT AGENCY PTE. LTD. • Singapore

On-site
SGD 70,000 - 100,000
Senior Red Team Expert
Senior Red Team Expert

Planet Nine • Singapore

On-site
SGD 100,000 - 150,000