- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 11 seconds ago
- Work mode
- In office
- Education
- Bachelor's degree in Cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role and Organization
Join Singapore's longest-standing bank, OCBC, dedicated since 1932 to supporting individuals and businesses in achieving their goals by deeply understanding their unique needs. Currently undertaking a transformation to become a future-ready learning institution, the bank aims to lead Asia's financial services industry sustainably while fostering innovation and community value.
As part of the Cybersecurity team, you will play a vital role in protecting our customers' data and assets, helping to secure our systems against cyber threats through cutting-edge methods.
Role Responsibilities
- Design and carry out red team exercises simulating real-world adversaries targeting enterprise and banking-critical systems.
- Create attack scenarios and tactics aligned with the MITRE ATT&CK framework, informed by the latest financial sector threat intelligence.
- Prepare and maintain detailed Rules of Engagement, scope documents, and exercise plans with proper oversight and data protection protocols.
- Perform reconnaissance, initial access, lateral movement, and post-exploitation techniques within controlled environments, documenting all findings and methodologies.
- Work closely with Threat Hunting and Detection Engineering teams to verify detection effectiveness and participate in purple team activities.
- Produce comprehensive reports tailored for both technical teams and management, including risk assessments, root cause analysis, and remediation advice.
- Support red team activities across multiple jurisdictions, coordinating logistics and engaging relevant stakeholders.
- Continuously refine red team strategies, tools, and operational playbooks.
- Keep up-to-date with emerging adversary tactics, tooling, and threat actor behavior relevant to banking and financial services.
Candidate Profile
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related discipline.
- At least 5 years of direct experience in red teaming, penetration testing, or offensive security, preferably within financial services or similarly regulated sectors.
- Proficient understanding of the MITRE ATT&CK framework and adversary emulation techniques.
- Hands-on experience using common red team tools like command and control (C2) frameworks, exploitation tools, OSINT utilities, and scripting languages such as Python or PowerShell.
- Strong knowledge of enterprise architecture, Active Directory, cloud platforms (AWS, Azure, GCP), and network security fundamentals.
- Experienced in designing and executing engagements under formal Rules of Engagement and managing stakeholder expectations.
- Excellent written and oral communication skills, able to convey technical insights to non-technical audiences effectively.
- Familiarity with regulatory and compliance standards including MAS TRM, BNM RMiT, HKMA, and CSA CCoP is advantageous.
- Certification in OSCP, OSCE, CRTP, CRTE, CRTO, GXPN, or equivalents highly desirable.
- Previous exposure to banking, payments, or critical financial infrastructure sectors.
- Experience participating in purple team exercises and collaborating with detection engineering teams.
Benefits and Culture
OCBC offers competitive salaries with a broad range of flexible benefits tailored to diverse lifestyles. We provide community engagement opportunities alongside industry-leading learning and professional development resources. Your wellbeing, career growth, and personal aspirations are prioritized as much as customer needs. Join a dynamic, supportive environment where you can contribute to shaping the future of banking services.
Minimum education
Bachelor's Degree