Cybersecurity Consultant (Offensive Security)
Singapore · Full Time
Be the first to apply
- Experience
- 3 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Education
- Diploma or Degree in Cybersecurity, Information Security, Computer Science, Engineering or related
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join PT ITSEC Asia Tbk as a Cybersecurity Consultant specializing in Offensive Security, based in Singapore. This position suits individuals with approximately 3 years of practical penetration-testing experience, though ambitious junior pentesters with strong foundational skills, curiosity, and a passion for ethical hacking are also encouraged to apply. The role offers involvement in a broad spectrum of security evaluations across enterprise, cloud, government, and critical infrastructure sectors. Candidates eager to leverage AI, automation, and emerging technologies to enhance penetration testing effectiveness will find this role particularly rewarding.
About PT ITSEC Asia Tbk
PT ITSEC Asia Tbk serves as a cybersecurity leader across the Asia-Pacific and beyond, operating offices in Singapore, Indonesia, Australia, the UAE, and Mauritius. The company delivers consulting and security solutions to a diverse clientele including government, critical infrastructure, finance, telecom, healthcare, and technology industries. Employment at ITSEC offers exposure to varied technology stacks, intricate security challenges, and a spectrum of consulting assignments that help refine both technical and client engagement skills.
Key Responsibilities
- Perform penetration testing and vulnerability evaluations on web applications, APIs, mobile apps, networks, cloud platforms, and other technologies.
- Assist with security reviews involving IT, Operational Technology (OT), Internet of Things (IoT), and other specialized fields.
- Detect, confirm, and demonstrate security weaknesses using established testing strategies and tactics.
- Analyze both the technical and business consequences of found vulnerabilities and potential attack paths.
- Document all testing processes, evidence, proofs-of-concept, and conclusions thoroughly and defensibly.
- Create comprehensive penetration testing reports detailing discoveries, risks, evidence, and remediation advice.
- Communicate technical findings and the significance of security risks clearly to clients across technical and non-technical audiences.
- Conduct remediation verification testing to ensure vulnerabilities are properly mitigated.
- Investigate and responsibly implement AI-assisted testing, automation, scripting, and new technologies to improve penetration testing and reporting.
- Continuously update knowledge on new threats, attack methods, tools, technologies, and industry standards.
- Contribute to enhancing team methodologies, knowledge resources, tooling, and technical skills.
Candidate Profile
- Possess a diploma or degree in Cybersecurity, Information Security, Computer Science, Engineering, or related field.
- Approximately 3 years of hands-on experience in penetration testing or offensive security preferred; strong junior candidates are also welcome if they demonstrate solid offensive security skills and eagerness to learn.
- Certifications such as CREST Registered Tester (CRT) or Offensive Security Certified Professional (OSCP) or equivalent are highly desirable.
- Strong practical knowledge of penetration testing methodologies, tools, and techniques.
- Experience in domains like web application, API, network, Active Directory, mobile, or cloud penetration testing is advantageous.
- Expertise or familiarity with OT, ICS, IoT, or critical infrastructure security testing is a plus.
- Excellent analytical, troubleshooting, and problem-solving skills.
- Ability to generate clear, precise, and professional technical reports.
- Competent in communicating technical security issues to clients with varying technical expertise.
- Interest and aptitude in AI, automation, scripting, and emerging offensive security technologies, with willingness to learn rapidly.
- Self-motivated, collaborative, and committed to continual professional growth in cybersecurity consulting.
Preferred Experience for Government and Classified Projects
Preference is given to Singapore citizens, especially those eligible to engage in sensitive or classified government projects. Prior experience in working with Singapore Government, classified, critical infrastructure, or other high-security assignments is highly beneficial. Familiarity with security standards, professional conduct, documentation practices, and operational limitations for secure government environments is highly relevant.
What PT ITSEC Asia Tbk Offers
- Practical training and mentorship from seasoned cybersecurity professionals to support ongoing skill development.
- Opportunities to engage in diverse and complex penetration testing projects.
- Growth in expertise across IT, cloud, OT, and emerging technology landscapes.
- Enhancement of consulting, client interaction, and report writing competencies.
- Chance to learn from veterans in offensive security and cautiously experiment with AI-assisted and automated testing techniques.
- Room to advance into specialized offensive security domains aligned with growing experience.
Minimum education
Diploma / ITI / Vocational