
Enable job alerts via email!
Generate a tailored resume in minutes
Land an interview and earn more. Learn more
A leading technology organisation in Singapore is hiring a Senior Cybersecurity Operations Specialist to enhance security testing and capabilities across teams. This role involves defining security testing standards, leading penetration tests, and fostering a secure-by-design culture. Ideal candidates will have 8–10 years of experience in cybersecurity, particularly in offensive security, and strong skills in penetration testing, secure coding, and communication with stakeholders.
Join a leading technology organisation driving large-scale digital transformation. We are hiring a Senior Cybersecurity Operations Specialist (Security Services) to strengthen organisation-wide security testing governance, secure-by-design practices, and offensive security capabilities across multiple teams and systems.
As a domain expert within the CISO Office, you will work closely with senior stakeholders and engineering teams to uplift VAPT standards, application security, and secure development across the organisation.
Key responsibilities include:
Define and maintain security testing standards (VAPT) and Ministry/organisation-wide frameworks
Develop SOPs to guide teams on vendor engagement and security testing cycles
Build quality rubrics and conduct sampling reviews to improve testing rigour and outcomes
Lead complex red teaming / deep-dive penetration testing for high-impact systems
Simulate real-world adversaries using latest TTPs (MITRE ATT&CK) and threat intelligence
Establish secure coding standards (OWASP / SANS) and uplift secure SDLC practices
Drive SAST / SCA strategy, including tool evaluation and automation
Advise teams on integrating security into CI/CD pipelines (DevSecOps)
Partner with stakeholders to promote a strong secure-by-design culture
8–10 years of hands-on cybersecurity experience (offensive security / AppSec focus)
Strong track record in penetration testing across web apps, on-prem / cloud systems, and networks
Experience with manual & automated code review (logic flaws, injections, crypto issues)
Strong knowledge of SSDLC and ability to work with common programming languages (Java, Python, .NET, JavaScript)
Familiar with tools like Burp Suite, Checkmarx, Fortify, SonarQube, Snyk (or equivalents)
Experience with DevOps/CI tools (e.g., Jenkins, GitLab CI, GitHub Actions)
Certifications preferred: OSCP / OSWE / CASE / GWEB (or similar)
Strong communication skills to influence stakeholders and drive standards across teams