Penetration Tester-Govt Clerance

INFINITY CYBERSEC PTE. LTD.

Date: 2 days ago
City: Singapore, Singapore
Salary: SGD 4,000 - SGD 5,000 / mo
Contract type: Full time

JobOverview

Weseek a Penetration Testing with CAT1 clearance to lead VAPT for Singaporegovernment and critical infrastructure sectors. You will execute full-scopeattacks (networks, apps, cloud, OT), bypass advanced defenses, and deliveractionable remediation strategies. This role requires CREST/OSCP certification,deep exploit development skills, and experience with GovTech cybersecurityframeworks.

CoreResponsibilities

1. CAT1-clearedengagements:

2. Network:Breach segmented govt networks (e.g., air-gapped systems)

3. Applications:Exploit web/mobile apps (SCADA interfaces, GovTech portals)

4. Cloud:Attack AWS GovCloud/Azure Government environments

5. OT:ICS/SCADA system penetration (Siemens, Rockwell)

6. Developcustom malware/exploits (C++, Python) to evade EDR/XDR.

1. Leadmulti-vector campaigns:

2. Phishing(Evade Proofpoint/MS ATP)

3. Physicalsecurity bypass (RFID cloning, access control spoofing)

4. Wirelessattacks (802.1X, WPA3-Enterprise)

5. DocumentTTPs aligned with MITRE ATT&CK for ICS/Enterprise.

GovtCompliance & Reporting:

1. Aligntests with IM8, CSA Red Teaming Guidelines, and NIST SP 800-115.

2. Deliverexecutive briefings to CISOs with exploit demos.

3. Createremediation playbooks

Research& Development:

1. Reverseengineer firmware (Binwalk, Ghidra) for 0-day discovery.

2. Contributeto ASEAN CERT advisories (e.g., SingCERT).

TechnicalRequirements

Non-NegotiableCredentials

1. CAT1Security Clearance

2. ActiveCertifications: OSCP or CREST CRT/CCT (Inf/App)

3. 2+years in pentesting

ToolProficiency

1. Exploitation- Metasploit Pro, Cobalt Strike, Burp Suite Pro, PowerSploit

2. Post-Exploit- BloodHound, Mimikatz, Impacket, Covenant C2

3. Forensics- Volatility, Wireshark, CHIRP (ICS)

4. Wireless- HackRF One, Proxmark3, Wi-Fi Pineapple

5. Cloud- Pacu (AWS), MicroBurst (Azure), GCP IAM Exploit Toolkit

PreferredQualifications

1. Certifications:OSCE³, CREST CCT Gold, OSCP

2. GovtFramework Experience: IM8 Penetration Test Guidelines, CSA Cyber Essentials

3. PublicContributions: CVEs, exploit-db submissions, conference talks (Black Hat Asia,DEFCON)

For employers only

Is this your company's job post? Verify ownership to manage this listing and receive applications directly.

Claim this listing

Looking to apply for this job? Use the Apply button above.