Penetration Tester & Security Researcher

Planet Nine

Singapore

Hybrid

SGD 120,000 - 180,000

Full time

19 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

BNF SG in Singapore is seeking a Mid-to-Senior Penetration Tester & Security Researcher to tackle complex security challenges across web apps, infrastructure, cloud/Kubernetes, AI systems, mobile apps, and source code. We expect researchers to dig deep beyond standard testing and produce real security research.

You’ll report to the Team Lead and collaborate with a small, international team on live client engagements, applying independent thinking and a proactive approach to identify risks and

Qualifications

  • 3+ years of hands-on experience in penetration testing and/or security research.
  • Deep expertise in web app, infrastructure/network, and code review.
  • OSCP or CREST CRT certification mandatory.
  • Based in Singapore with valid work authorization.
  • Hybrid work model in Singapore.

Responsibilities

  • Conduct penetration testing and security research across web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code.
  • Take ownership of security reporting. Use AI tools to accelerate drafting, but ensure final output is technically accurate with root-cause analysis and business impact.
  • Present vulnerabilities, findings, and recommendations clearly to clients and their technical teams.
  • Build internal security tools, methodologies, automation, and agentic workflows that enable the team to work faster and go deeper.
  • Contribute to red team and adversary emulation engagements.
  • Independently investigate unfamiliar technologies, attack surfaces, and complex technical problems.

Skills

Penetration testing
Security research
Web app pen testing
Infrastructure pen testing
Source code review
AI-enabled security testing
Independent working
English communication

Education

OSCP or CREST CRT certification
Bachelor's degree in CS/InfoSec/Engineering or equivalent

Tools

Python
Node.js

Job description

We are looking for a Mid-to-Senior Penetration Tester & Security Researcher to join our team in Singapore.

At BNF SG, we work on complex security challenges where going beyond standard testing methodologies is essential. Our engagements are typically grey-box or white-box, often with access to source code, and we expect our researchers to dig deep and uncover vulnerabilities others may miss.

Our work spans web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code. For us, penetration testing is not just about running tools — it’s about understanding how systems work, challenging assumptions, and conducting real security research.

You’ll report to the Team Lead and work alongside a small team of security researchers in an international, collaborative, and highly technical environment. You’ll work independently on complex problems and together with the team on live client engagements.

We’re looking for someone curious and hungry to learn — someone who goes deep without being told to, would rather understand the system than simply run the tool, and genuinely enjoys security research.

Responsibilites:
  • Conduct penetration testing and security research across web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code.
  • Take ownership of security reporting. We use AI tools to accelerate drafting, but you are accountable for the final output — including technical accuracy, root-cause analysis, and real-world business impact.
  • Present vulnerabilities, findings, and recommendations clearly to clients and their technical teams.
  • Build internal security tools, methodologies, automation, and agentic workflows that enable the team to work faster and go deeper.
  • Contribute to red team and adversary emulation engagements.
  • Independently investigate unfamiliar technologies, attack surfaces, and complex technical problems.
Requirements:
Must Have
  • 3+ years of hands-on experience in penetration testing and/or security research (mandatory).
  • Deep expertise in at least two of the following areas:
  • Web application penetration testing.
  • Infrastructure and network penetration testing, including Active Directory, with real fluency in Windows and Linux internals, the protocols underneath, and privilege escalation.
  • Manual source code review and vulnerability research.
  • OSCP or CREST CRT certification (mandatory).
  • Strong research mindset, technical curiosity, and the ability to independently investigate unfamiliar technologies and attack surfaces.
  • Hands-on experience using AI tools to support security testing, research, automation, or tool development, with a strong interest in exploring new AI-driven security workflows.
  • Ability to work independently on deep technical problems and collaboratively on live client engagements.
  • Excellent written and verbal English communication skills.
  • Currently based in Singapore with valid work authorization (mandatory).
  • Availability to work in a hybrid model in Singapore, including regular work at client sites.
Nice to Have
  • Existing CAT1 or CAT2A security clearance.
  • Proficiency in Python or Node.js.
  • CREST CCT APP or CCT INF, or Offensive Security certifications beyond OSCP, such as OSWE, OSEP, or OSED.
  • Security research publications, strong CTF performance, or a demonstrated bug bounty track record.
  • Experience with mobile application penetration testing across Android and iOS, as well as thick-client testing.
  • Cloud penetration testing experience across AWS, Azure, or GCP, including containers and Kubernetes.
  • Red team experience, including reconnaissance, adversary emulation, and stealth techniques.
  • AI security expertise, including prompt injection and indirect prompt injection, jailbreaks, RAG and agent security, and the OWASP Top 10 for LLM Applications.
  • Degree in Computer Science, Information Security, Engineering, or a related discipline — or equivalent practical experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

TECHKNOWLEDGEY PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
Penetration Tester
Penetration Tester

TechKnowledgey Pte Ltd • Singapore

On-site
SGD 65,000 - 90,000
Senior Cybersecurity Engineer (Python/Penetration Testing)
Senior Cybersecurity Engineer (Python/Penetration Testing)

manpower staffing services (singapore) pte ltd • Singapore

On-site
SGD 120,000 - 180,000
Contract position
Extension potential
Singapore-based role
SECURITY CONSULTANT (Penetration Testing)
SECURITY CONSULTANT (Penetration Testing)

Atos SE • Singapore

On-site
SGD 90,000 - 150,000
Security Consultant
Security Consultant

SOFTSCHECK SINGAPORE PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
Penetration Tester
Penetration Tester

VOUCH RECRUITMENT PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
Consultant, Security Testing and Red Teaming
Consultant, Security Testing and Red Teaming

Ensign InfoSecurity • Singapore

Hybrid
SGD 100,000 - 160,000
Penetration Tester, Advanced Cybersecurity Division
Penetration Tester, Advanced Cybersecurity Division

sggovterp • Singapore

On-site
SGD 120,000 - 180,000
Penetration Tester (VAPT)
Penetration Tester (VAPT)

Vouch Recruitment • Singapore

On-site
SGD 70,000 - 120,000
Senior Red Team Expert
Senior Red Team Expert

Planet Nine • Singapore

On-site
SGD 100,000 - 150,000