An application made for this job — a tailored resume and cover letter that speak straight to the posting.
PwC Singapore seeks an experienced offensive security professional to deliver end-to-end Security Testing engagements including Red Teaming, Purple Teaming, BAS, penetration testing, cloud and AI security. The role sits in Technology Risk Services to help clients strengthen security postures.
The candidate should have hands-on offensive security operations experience, strong TTP knowledge, and the ability to communicate findings clearly to clients and internal stakeholders; CI/CD security and
At PwC, we help clients build trust and reinvent so they can turn complexity into competitive advantage. We're a tech-forward, people-empowered network with more than 370,000 people in 149 countries. Across audit and assurance, tax and legal, deals and consulting we help clients build, accelerate and sustain momentum. Find out more at www.pwc.com.
We are looking for an experienced offensive security professional to take on a role in delivering end-to-end Security Testing engagements (RedTeaming,Purple Teaming,BAS, Penetration Testing,Cloud Security, AI Securityetc.) while contributing to business development efforts.The ideal candidate combines strong technicalexpertisein security assessments with proven project management capabilities.This role sits within ourTechnology RiskServicespractice, where the team helps organizations analyze and strengthen the security posture of their information technology systems and environments.
Red Team consultantshould have hands-on experience inoffensive security operationsalong with asolidunderstanding of attacker tactics, techniques, and procedures (TTPs).This role combines offensive securityexpertisewithstrong communicationskills to work closely with blue teams to strengthen monitoring, detection, and response capabilities.
Emulatereal-world threat actorsandtheir behaviour throughtactics,techniquesand procedures (TTPs)on clients' environment.
Conduct purple team exercises in collaboration with blue team to assess detections, improve logging coverage, and enhance response processes.
Use frameworks such as MITRE ATT&CK to map adversary techniques
WorkwithPwC's threat intelligence team tosupport attack simulation/emulations operations
Develop custom tools,payloadsand automation scripts to support engagements whereappropriate.
Stay updated with emerging threats, adversary tradecraft, and offensive security techniques
Conducting vulnerability assessment and penetration testing (VAPT) and source code review whenrequired
Dealwith clients to address concerns,issuesor escalations; track and drive to closure any issuesthatimpactthe service and its value to clients
Develop comprehensive andaccuratereports and presentations for both technical and executive audiences
Preferred qualifications& Requirements:
Bachelor's degree in a technical discipline (or equivalent work experience)
Ability to write clear technical documentation and deliver findings to clients or internal stakeholders
Knowledge of detection engineering,hypothesis driventhreat hunting, and SOC workflows
Familiarity with adversary emulation plans and intelligence-driven testing
Experience with CI/CD security, container security, and cloud-native environments.
Understanding of malware analysis, reverse engineering, or exploit development is a plus
Minimally possess OSCP / CREST CRT certifications
Candidates with relevant certifications such asOSCP, OSEP, CRTO, CRTE, OSED,CREST CRT/CCT, CARTP/CARTE, Azure/AWSsecurity certificationsarepreferred