Job Summary:
The successful candidate will be responsible for conducting comprehensive security assessments of systems, networks, and applications; identifying vulnerabilities; and providing actionable recommendations for remediation.
Responsibilities:
- Conduct penetration testing and vulnerability assessments on web applications, networks, and infrastructure.
- Identify and exploit security vulnerabilities using a variety of manual and automated techniques.
- Develop and maintain penetration testing methodologies and procedures.
- Document findings in clear, concise, and comprehensive reports, including detailed descriptions of vulnerabilities, potential impact, and recommended remediation steps.
- Present findings and recommendations to technical and non-technical audiences.
- Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques.
- Contribute to the development of security tools and scripts to automate testing processes.
- Perform red team exercises to simulate real-world attacks and assess the effectiveness of security controls.
- Adhere to ethical hacking principles and maintain confidentiality of sensitive information.
Required Skills and Experience:
- Minimum of 3 years of experience in penetration testing and vulnerability assessment.
- Possession of Offensive Security Certified Professional (OSCP) certification is mandatory.
- Excellent understanding of common web application vulnerabilities (OWASP Top 10) and exploitation techniques.
- Proficiency in scripting languages such as Python, Bash.
- Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, and Nessus.
- Solid understanding of networking protocols and security concepts.
- Excellent communication, interpersonal, and presentation skills.
- Ability to work independently and as part of a team.
- Excellent analytical and problem-solving skills.
Good to have:
- Other relevant security certifications (e.g., CEH, CISSP, GPEN).
- Contributions to the security community (e.g., bug bounty programs, open-source projects).
- Experience with threat modelling.
Claudia Kueh Kee Jinq EA License No.: 02C3423 Personnel Registration No.:R1880247
Please note that your response to this advertisement and communications with us pursuant to this advertisement will constitute informed consent to the collection, use and/or disclosure of personal data by ManpowerGroup Singapore for the purpose of carrying out its business, in compliance with the relevant provisions of the Personal Data Protection Act 2012. To learn more about ManpowerGroup's Global Privacy Policy, please visit https://www.manpower.com.sg/privacy-notice.
