JobOverview
Weseek a Penetration Testing with CAT1 clearance to lead VAPT for Singaporegovernment and critical infrastructure sectors. You will execute full-scopeattacks (networks, apps, cloud, OT), bypass advanced defenses, and deliveractionable remediation strategies. This role requires CREST/OSCP certification,deep exploit development skills, and experience with GovTech cybersecurityframeworks.
CoreResponsibilities
AdvancedThreat Emulation
- 1.CAT1-clearedengagements:
- 2.Network:Breach segmented govt networks (e.g., air-gapped systems)
- 3.Applications:Exploit web/mobile apps (SCADA interfaces, GovTech portals)
- 4.Cloud:Attack AWS GovCloud/Azure Government environments
- 5.OT:ICS/SCADA system penetration (Siemens, Rockwell)
- 6.Developcustom malware/exploits (C++, Python) to evade EDR/XDR.
RedTeam Operations
- 1.Leadmulti-vector campaigns:
- 2.Phishing(Evade Proofpoint/MS ATP)
- 3.Physicalsecurity bypass (RFID cloning, access control spoofing)
- 4.Wirelessattacks (802.1X, WPA3-Enterprise)
- 5.DocumentTTPs aligned with MITRE ATT&CK for IC S/Enterprise.
GovtCompliance & Reporting
- 1.Aligntests with IM8, CSA Red Teaming Guidelines, and NIST SP 800-115.
- 2.Deliverexecutive briefings to CISOs with exploit demos.
- 3.Createremediation playbooks
Research& Development
- 1.Reverseengineer firmware (Binwalk, Ghidra) for 0-day discovery.
- 2.Contributeto ASEAN CERT advisories (e.g., SingCERT).
TechnicalRequirements
Non-NegotiableCredentials
- 1.CAT1Security Clearance
- 2.ActiveCertifications: OSCP or CREST CRT/CCT (Inf/App)
- 3.2+years in pentesting
ToolProficiency
- 1.Exploitation- Metasploit Pro, Cobalt Strike, Burp Suite Pro, PowerSploit
- 2.Post-Exploit- BloodHound, Mimikatz, Impacket, Covenant C2
- 3.Forensics- Volatility, Wireshark, CHIRP (ICS)
- 4.Wireless- HackRF One, Proxmark3, Wi-Fi Pineapple
- 5.Cloud- Pacu (AWS), MicroBurst (Azure), GCP IAM Exploit Toolkit
PreferredQualifications
- 1.Certifications:OSCE³, CREST CCT Gold, OSCP
- 2.GovtFramework Experience: IM8 Penetration Test Guidelines, CSA Cyber Essentials
- 3.PublicContributions: CVEs, exploit-db submissions, conference talks (Black Hat Asia,DEFCON)