Senior Cybersecurity Consultant (ASG), Cybersecurity Engineering Centre

Cyber Security Agency of Singapore (CSA)

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cyber Security Agency of Singapore (CSA) is seeking a senior offensive security practitioner to join the Attack Simulation Group (ASG). This hands-on role focuses on applying real-world attack techniques to test critical infrastructure in support of Singapore’s national cyber security mission.

You will lead end-to-end engagements, mentor junior consultants, and drive the evolution of ASG’s testing methodologies across web, mobile, cloud, OT, and telecom environments, while contributing to

Qualifications

  • Typically 5–8 years of relevant experience in penetration testing, red team operations, or related offensive security roles.
  • Industry certifications such as OSCP, CREST CRT, CCT, CRTO, or equivalent are desirable.

Responsibilities

  • Lead and conduct penetration testing, red teaming, and adversary simulation across web, mobile, infrastructure, cloud, OT, and telecommunications environments.
  • Execute realistic attack scenarios to assess the resilience of Critical Information Infrastructure (CII), including systems supporting essential services.
  • Support purple-teaming activities by translating offensive techniques into actionable detection and response improvements.
  • Lead engagements end-to-end, including planning, execution, reporting, and technical debriefs with stakeholders.
  • Mentor junior consultants and contribute to raising the team’s overall technical standard.
  • Drive continuous improvement of ASG’s testing methodologies, tooling, and research, including taking on problem spaces outside your primary domain when required.
  • Be prepared to contribute to strategic initiatives, supporting procurement activities, industry outreach, or coordination work to strengthen security outcomes.

Job description

You will be part of the Attack Simulation Group (ASG) within the Cyber Security Agency of Singapore (CSA), a specialist team responsible for delivering advanced security testing and adversary‑led assessments to strengthen the resilience of Critical Information Infrastructure (CII). This is a senior, hands‑on role for experienced offensive security practitioners who want to apply real‑world attack techniques to complex, high‑impact systems in support of Singapore’s national cyber security mission.

ASG is a technically driven team within CSA focused on realistic attack simulation, penetration testing, red teaming, and purple‑teaming outcomes. Our work goes beyond compliance‑driven assurance, emphasising hands‑on testing, attacker trade‑craft, and practical security improvements.

Operating within the realities of government, we value curiosity, adaptability, and out‑of‑the‑box thinking. Specialised training and development opportunities are provided to continuously deepen and expand our technical capabilities, and team members are expected to continuously learn, apply skills across domains, and contribute to the evolution of attack simulation practices across Singapore’s CII.

We also believe in sharing and growing our craft where appropriate. Some of our public work and tooling can be found at: https://github.com/hack-techv2/

Responsibilities:
  • Lead and conduct penetration testing, red teaming, and adversary simulation activities across web, mobile, infrastructure, cloud, OT, and telecommunications environments.
  • Execute realistic attack scenarios to assess the resilience of Critical Information Infrastructure (CII), including systems supporting essential services.
  • Support purple‑teaming activities by translating offensive techniques into actionable detection and response improvements.
  • Lead engagements end‑to‑end, including planning, execution, reporting, and technical debriefs with stakeholders.
  • Mentor junior consultants and contribute to raising the team’s overall technical standard.
  • Drive continuous improvement of ASG’s testing methodologies, tooling, and research, including taking on problem spaces outside your primary domain when required.
  • And because this is government, be prepared to occasionally switch gears by contributing to strategic initiatives, supporting and executing procurement activities, participating in industry outreach, or undertaking coordination work, all of which ultimately help us strengthen security outcomes and make Singapore a safer place to live and work.
Why Join ASG at CSA?
  • Work on nationally significant systems, including CII, OT, and telecommunications environments rarely accessible outside government.
  • Engage in deep, technically challenging work that prioritises realism, learning, and security outcomes over high-volume testing.
  • Apply your offensive security expertise to a public mission that directly contributes to Singapore’s cyber resilience.
  • Be part of a specialist team that is deliberately building towards strong technical depth, continuous learning, and moving beyond compliance‑driven assurance, and help shape what “good” looks like along the way.
  • An attacker’s mindset with strong technical understanding of operating systems, networks, and modern enterprise environments.
  • Proven ability to identify and execute real‑world attack scenarios, beyond automated or checklist‑based testing.
  • Experience in penetration testing and/or red team operations, with exposure to adversary tradecraft and attack chaining.
  • Demonstrated adaptability to transfer skills across technical domains (e.g. web to mobile, IT to OT, on‑prem to cloud).
  • Strong technical writing skills and the ability to clearly articulate security risks and impact.
  • Typically 5–8 years of relevant experience in penetration testing, red team operations, or related offensive security roles, with demonstrated depth in hands‑on technical work.
  • Relevant industry certifications such as OSCP, CREST (e.g. CRT, CCT), CRTO, or equivalent are desirable.
  • That said, we recognise that certifications alone do not define capability. Hands‑on experience, problem‑solving ability, and technical depth matter more to us than badges.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Offensive Security Consultant — Attack Simulation
Senior Offensive Security Consultant — Attack Simulation

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 120,000 - 180,000
Security Consultant (Offensive Security)
Security Consultant (Offensive Security)

ITSEC SERVICES ASIA PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
Lead Cybersecurity Consultant (Cybersecurity Certification Centre), CSEC
Lead Cybersecurity Consultant (Cybersecurity Certification Centre), CSEC

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 180,000 - 260,000
Security Consultant
Security Consultant

SOFTSCHECK SINGAPORE PTE. LTD. • Singapore

On-site
SGD 70,000 - 120,000
IT Security Consultant
IT Security Consultant

DADACONSULTANTS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Associate Cybersecurity Engineer (CSDP) July 2027 Intake
Associate Cybersecurity Engineer (CSDP) July 2027 Intake

Cyber Security Agency of Singapore (CSA) • Singapore

On-site
SGD 28,000 - 39,000
Penetration Tester, Advanced Cybersecurity Division
Penetration Tester, Advanced Cybersecurity Division

sggovterp • Singapore

On-site
SGD 120,000 - 180,000
Senior Cyber Security Consultant (Penetration Tester)
Senior Cyber Security Consultant (Penetration Tester)

CRIMSONLOGIC PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Senior Cybersecurity Operations Specialist
Senior Cybersecurity Operations Specialist

GovTech Singapore • Singapore

On-site
SGD 180,000 - 240,000
Security Consultant - Government
Security Consultant - Government

Consult • Singapore

On-site
SGD 120,000 - 160,000