Consultant, Security Testing and Red Teaming

Ensign InfoSecurity

Singapore

On-site

SGD 90,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ensign InfoSecurity seeks a Consultant, Security Testing and Red Teaming to independently run penetration tests across web apps, networks, cloud, and Active Directory, delivering actionable findings for clients.

You will contribute to playbooks, reports, and client discussions, while growing into broader offensive security disciplines such as adversary simulation, tooling development, and research.

Qualifications

  • OSCP is required.
  • Advanced certifications such as OSWE, OSEP, OSED are a plus.
  • 3–5 years of hands-on pentesting experience in consulting or equivalent.
  • Strong understanding of pentesting methodologies and ethical hacking.

Responsibilities

  • Deliver end-to-end penetration testing engagements with minimal supervision.
  • Perform manual vulnerability discovery, validation, and exploitation.
  • Identify attack paths and assess real-world business impact.
  • Produce high-quality technical findings with actionable remediation guidance.
  • Develop structured testing reports and support client walkthroughs.

Skills

Penetration testing
Scripting (Python/PowerShell/Bash)
Report writing
Client-facing communication

Education

OSCP
OSWE
OSEP
OSED

Tools

Burp Suite
Nmap
Metasploit
BloodHound

Job description

Consultant, Security Testing and Red Teaming
Description

The Consultant, Security Testing and Red Teaming is a core delivery role within the offensive security practice, responsible for independently executing penetration testing engagements and contributing to advanced offensive security activities.

This role has a strong emphasis on hands-on penetration testing across web applications, infrastructure, Active Directory, and cloud environments. Consultants are expected to operate with a high degree of autonomy on scoped engagements, apply sound technical judgement, and produce high-quality, defensible findings and reports for clients.

While penetration testing is the primary focus, Consultants are also expected to demonstrate the curiosity and technical breadth to grow into broader offensive security disciplines over time, including adversary simulation, red teaming, tooling development, and security research.

Roles and Responsibilities
  • Deliver end-to-end penetration testing engagements with minimal supervision, including:
    • Internal and external network penetration testing
    • Cloud and hybrid environment testing
    • IOT penetration testing
    • OT penetration testing
  • Perform manual vulnerability discovery, validation, and exploitation beyond automated scanning.
  • Identify attack paths, chain vulnerabilities, and assess real-world business impact.
  • Exercise sound judgement in exploitation depth, data handling, and risk management during testing.
  • Maintain clear, detailed testing notes, evidence, and attack logs to support reporting and quality review.
  • Produce high-quality technical findings with accurate severity assessment and actionable remediation guidance.
  • Develop structured penetration testing reports, and support client walkthroughs and debriefs.
  • Engage professionally with clients during kick-off sessions, testing clarification, and results discussions.
  • Participate in peer reviews of testing approaches and reports to uphold delivery quality standards.
  • Continuously develop technical depth across offensive security techniques, platforms, and tooling.
  • Contribute to security testing playbooks, internal knowledge sharing and peer learning.
  • Where appropriate, contribute to broader offensive security initiatives, such as:
    • Adversary simulation and red teaming exercises
    • Custom tooling, scripting, or automation
    • Internal research, labs, or capability development
Requirements
  • Offensive Security Certified Professional (OSCP) is required.
  • To hold at least one advanced or specialist certifications such as OSWE, OSEP, OSED
  • Approximately 3 to 5 years of hands-on penetration testing experience in consulting, internal security, or equivalent practical environments.
  • Strong understanding of penetration testing methodologies, rules of engagement, and ethical hacking principles.
  • Solid technical foundations in:
    • TCP/IP networking and common protocols
    • Windows and Linux operating systems
    • Web application architecture and common vulnerability classes
  • Demonstrated experience testing:
    • Web applications, including authentication, authorization, and business logic flaws
    • Network and infrastructure environments
    • Active Directory domains
    • Mobile applications
  • Proficiency with common penetration testing tools (e.g. Burp Suite, Nmap, Metasploit, BloodHound).
  • Experience with scripting or programming (e.g. Python, PowerShell, Bash) to support testing and automation.
  • Exposure to cloud security testing (AWS, Azure, GCP) and modern identity platforms.
  • Experience with post-exploitation, lateral movement, and attack path analysis.
  • Demonstrated interest in expanding beyond traditional penetration testing into broader offensive security and red teaming.
  • Ability to clearly communicate technical findings in written reports and verbal discussions.
  • Strong professionalism, integrity, and attention to detail.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Consultant, Security Testing and Red Teaming
Associate Consultant, Security Testing and Red Teaming

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

On-site
SGD 52,000 - 82,000
Senior Security Consultant - OSCP
Senior Security Consultant - OSCP

TECHKNOWLEDGEY PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Penetration Testers/ Red Teamers
Penetration Testers/ Red Teamers

KERRY CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Pentester
Cybersecurity Pentester

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Penetration Tester
Penetration Tester

LANTU EMPLOYMENT AGENCY PTE. LTD. • Singapore

On-site
SGD 70,000 - 100,000
Penetration Testing Consultant
Penetration Testing Consultant

SWARMNETICS PTE. LTD. • Singapore

On-site
SGD 60,000 - 100,000
Penetration Testing & Red Team Consultant
Penetration Testing & Red Team Consultant

Ensign InfoSecurity • Singapore

On-site
SGD 90,000 - 150,000
Cyber Security Consultant (VAPT) - OSCP and CREST required
Cyber Security Consultant (VAPT) - OSCP and CREST required

TESCOM (SINGAPORE) SOFTWARE SYSTEMS TESTING PTE LTD. • Singapore

On-site
SGD 70,000 - 110,000
Offensive Security Consultant, Red Team, Mandiant Consulting - Singapore
Offensive Security Consultant, Red Team, Mandiant Consulting - Singapore

GOOGLE ASIA PACIFIC PTE. LTD. • Singapore

On-site
SGD 150,000 - 210,000
Red Team Specialist, Financial Services
Red Team Specialist, Financial Services

Kerry Consulting • Singapore

On-site
SGD 120,000 - 190,000