Penetration Tester / Red Team Engineer
Location: Singapore, Singapore, Singapore
Department: Managed Services
Workplace: on_site
Description
Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade. ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, governance and assurance services as well as managed processes. In a dynamic digital & cyber landscape where trust & collaboration is key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
Key responsibilities:
- Lead penetration testing and red teaming for systems under the CISO’s remit, covering both corporate systems and internal product teams.
- Plan and execute tests for:
- Web, cloud, network and API applications,
- Cloud workloads (e.g. government cloud platforms, containerised workloads, CI/CD paths),
- Data platforms (e.g. data lakes / lakehouses and large-scale analytics platforms),
- Enterprise / internal platforms (e.g. identity, collaboration, and developer tooling, as well as other approved SaaS).
- Identify and validate end-to-end attack paths across identity, endpoints, networks, data platforms and SaaS integrations; document realistic threat scenarios and impact.
- Manage PT engagements with external vendors / programmes (including GBBP or similar):
- Define rules of engagement and scope,
- Prepare environments and access,
- Review reports for depth and quality and consolidate findings for product owners.
- Produce clear, prioritised reports and briefings for engineering teams and management, and support remediation planning, retesting and closure.
- Design and own standard PT environment patterns, including:
- PT workstations and hardened images,
- Appropriate network zones and access controls,
- Realistic but non-sensitive test tenants and seeded datasets.
- Work with infra and central engineering teams to integrate PT tooling and automation where appropriate and ensure sufficient logging / telemetry for red and purple teaming.
- Co-author PT / red team policies and standards within Govtech, and act as implementation lead for product teams.
- Translate policy into practical guidance, templates and checklists so product and platform teams can plan and execute PT in a consistent, compliant way.
Requirements
- Experience: At least 2 years of hands-on penetration testing (web and API), with exposure to cloud-native / containerised applications, data platforms and/or enterprise SaaS; experience working with SOC or on purple teaming is a plus.
- Technical skills: Strong grasp of common attack techniques (e.g. OWASP, cloud/API), solid PT tooling skills, and working knowledge of web, network and cloud security; able to read and reason about code and infrastructure.
- Qualifications: OSCP is required (or clearly equivalent demonstrated skill level); other offensive or cloud security certifications are a plus.
- Personal attributes: Clear communicator, comfortable operating as an individual contributor while influencing cross-functional teams, with high integrity and a pragmatic, outcome-focused mindset.
Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click "Apply Now".
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS’s privacy statement which can be found at: https://www.assurity.sg/ or such other successor site.
Benefits
- A wholly-owned subsidiary of GovTech.
- We promote a learning culture and encourage you to grow and learn.
- Contract Staff enjoys the same benefits as Permanent Employees.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
