Senior Penetration Testing Engineer

digital treasures center pte. ltd.

Singapore

On-site

SGD 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

digital treasures center pte. ltd.

in Singapore is seeking an experienced penetration tester to conduct comprehensive assessments of web systems, applications and internal networks, identify security vulnerabilities, and provide actionable remediation guidance to clients. You will own the full penetration testing lifecycle—from information gathering to vulnerability verification, including Java code audits, mobile security testing, and reporting.

Qualifications

  • Bachelor's degree or above in Computer Science, Computer Engineering, or a related field.
  • 5+ years of experience in penetration testing / information security, with experience on both the client side and security vendor (consulting) side preferred.
  • Strong ability to work independently, capable of taking on a project lead role and independently liaising with clients and project teams.

Responsibilities

  • Conduct comprehensive penetration testing of web systems, applications, and internal networks, identifying and verifying security vulnerabilities.
  • Independently execute the full penetration testing lifecycle: information gathering, vulnerability scanning, vulnerability verification, privilege escalation, lateral movement within internal networks, etc.
  • Perform in-depth analysis of OWASP Top 10 vulnerabilities and provide remediation recommendations.
  • Conduct code audits covering Java frameworks (Spring, Spring Boot, Spring MVC, MyBatis) and identify common web vulnerabilities at source level.
  • Perform mobile application security testing, including decompilation, hardening detection, static/dynamic analysis, and API penetration testing.
  • Independently prepare penetration testing reports and communicate technical findings with project teams and clients.
  • Participate in red team/blue team exercises and cyber defense drills, handling monitoring, analysis, attribution, and remediation.
  • Maintain familiarity with security frameworks such as MAS TRM, DORA, PCI DSS, ISO 27001, and SOC 2.
  • Assist in delivering enterprise information security training to enhance internal security awareness.

Skills

Penetration testing
Security tooling
Python scripting
Java code audits
Mobile security testing
Report writing
Client liaison

Education

Bachelor's degree in CS/CE or related

Tools

AWVS
Nmap
SQLMap
Burp Suite
AppScan
Fortify
Eclipse
Frida
JADX
apktool

Job description

Job Responsibilities

  1. Conduct comprehensive penetration testing of the company's and clients' web systems, applications, and internal network environments, identifying and verifying security vulnerabilities;
  2. Independently execute the full penetration testing lifecycle: information gathering, vulnerability scanning, vulnerability verification, privilege escalation, lateral movement within internal networks, etc.;
  3. Perform in-depth analysis of common vulnerabilities including SQL injection, XSS, CSRF, command execution, insecure deserialization, and OWASP Top 10 vulnerabilities, and provide remediation recommendations;
  4. Conduct code audits covering Java frameworks (Spring, Spring Boot, Spring MVC, MyBatis, etc.) and source-level identification of common web vulnerabilities;
  5. Perform mobile application (APP) security testing, including decompilation, hardening/reinforcement detection, static/dynamic analysis, and API penetration testing;
  6. Independently prepare penetration testing reports and communicate technical findings with project teams and clients;
  7. Participate in red team/blue team exercises and cyber defense drills, taking on responsibilities such as monitoring and analysis, attack attribution, and vulnerability remediation;
  8. Maintain familiarity with security frameworks such as MAS TRM, DORA, PCI DSS, ISO 27001, and SOC 2;
  9. Assist in delivering enterprise information security training to enhance internal security awareness.

Requirements

Basic Requirements

  • Bachelor's degree or above in Computer Science, Computer Engineering, or a related field;
  • 5+ years of experience in penetration testing / information security, with experience on both the client side and security vendor (consulting) side preferred;
  • Strong ability to work independently, capable of taking on a project lead role and independently liaising with clients and project teams.

Technical Skills

  • Proficient in end-to-end penetration testing methodology, with hands-on experience in internal network penetration testing (tunneling via ICMP/LCX/SSH, pass-the-hash, pass-the-ticket, lateral movement via WMI/PsExec, etc.);
  • Proficient with security scanning and penetration testing tools such as AWVS, Nmap, SQLMap, Burp Suite, and AppScan;
  • Capable of conducting Java code audits, familiar with tools such as Fortify and Eclipse, and vulnerability identification methods for common frameworks;
  • Proficient in Python development, with the ability to independently write security tools (directory scanners, subdomain scanners, C-segment scanners, protocol brute-forcing tools, PoC/exploit development, etc.);
  • Familiar with mobile application security testing, including APP decompilation (JADX, apktool), hardening/reinforcement identification, and dynamic testing with Frida;
  • Familiar with common middleware attack techniques and host security inspection procedures.

Nice to Have

  • Holds security certifications such as OSCP, OSWE, CREST, or has proof of original CVE disclosures;
  • Project experience with high-security clients in financial services, government, or large state-owned enterprises;
  • Experience participating in large-scale red team, purple team, or threat-led penetration testing engagements;
  • Experience in security technical sharing/training, or an active personal technical blog/open-source project portfolio.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

dtcpay • Singapore

On-site
SGD 120,000 - 180,000
Penetration Tester
Penetration Tester

Kris Infotech : Technology & Talent - Synced • Singapore

On-site
SGD 70,000 - 110,000
Penetration Tester (Security Consutant)
Penetration Tester (Security Consutant)

Atos • Singapore

On-site
SGD 70,000 - 120,000
Penetration Test and Vulnerability Assessment Expert
Penetration Test and Vulnerability Assessment Expert

The Digital and Intelligence Service (DIS) • Singapore

On-site
SGD 90,000 - 150,000
Application Security Penetration Tester
Application Security Penetration Tester

Aryan-Solutions-Pte.-Ltd. • Singapore

On-site
SGD 60,000 - 100,000
Senior Cybersecurity Engineer (Python/Penetration Testing)
Senior Cybersecurity Engineer (Python/Penetration Testing)

manpower staffing services (singapore) pte ltd • Singapore

On-site
SGD 120,000 - 180,000
Contract position
Extension potential
Singapore-based role
26989093 Information Security Technology Senior Analyst, Penetration Testing
26989093 Information Security Technology Senior Analyst, Penetration Testing

CITIBANK N.A. • Singapore

On-site
SGD 70,000 - 120,000
Consultant, Security Testing and Red Teaming
Consultant, Security Testing and Red Teaming

re-zoo-me • Singapore

Hybrid
SGD 90,000 - 130,000
Penetration Tester
Penetration Tester

SCIENTE • Singapore

On-site
SGD 67,000 - 134,000
Associate Engineer, Security Testing and Red Teaming
Associate Engineer, Security Testing and Red Teaming

Ensign InfoSecurity (Singapore) Pte. Ltd. • Singapore

On-site
SGD 70,000 - 110,000