Penetration Tester-Govt Clerance
AKERA TECHNOLOGIES PTE. LTD. · Singapore ·
- Category
- Security
- Experience
- 2+ years
AKERA TECHNOLOGIES PTE. LTD. · Singapore ·
INFINITY CYBERSEC PTE. LTD. · Singapore
JUST2IT PTE. LTD. · Singapore
SINGAPORE POWER LIMITED · Singapore
MANPOWER STAFFING SERVICES (SINGAPORE) PTE LTD · Singapore
Job Overview
We seek a Penetration Testing with CAT1 clearance to leadVAPT for Singapore government and critical infrastructure sectors. You willexecute full-scope attacks (networks, apps, cloud, OT), bypass advanceddefenses, and deliver actionable remediation strategies. This role requiresCREST/OSCP certification, deep exploit development skills, and experience withGovTech cybersecurity frameworks.
Core-Responsibilities
Advanced Threat Emulation:
1. CAT1-clearedengagements:
2. Network: Breach segmented govt networks(e.g., air-gapped systems)
3. Applications: Exploit web/mobile apps(SCADA interfaces, GovTech portals)
4. Cloud: Attack AWS GovCloud/AzureGovernment environments
5. OT:ICS/SCADA system penetration(Siemens, Rockwell)
6. Develop custom malware/exploits (C++,Python) to evade EDR/XDR.
Reteam Operations:
1. Lead multi-vector campaigns:
2. Phishing (Evade Proofpoint/MS ATP)
3. Physical security bypass (RFID cloning,access control spoofing)
4. Wireless attacks (802.1X,WPA3-Enterprise)
5. Document TTPs aligned with MITREATT&CK for ICS/Enterprise.
Govt Compliance & Reporting:
1. Align tests with IM8, CSA Red TeamingGuidelines, and NIST SP 800-115.
2. Deliver executive briefings to CISOswith exploit demos.
3. Create remediation playbooks
Research & Development:
1. Reverse engineer firmware (Binwalk,Ghidra) for 0-day discovery.
2. Contribute to ASEAN CERT advisories(e.g., Sing CERT).
Technical Requirements
Non-Negotiable Credentials
1. CAT1Security Clearance
2. Active Certifications: OSCP or CRESTCRT/CCT (Inf/App)
3. 2+years in pentesting
Tool Proficiency
1. Exploitation- Metasploit Pro, CobaltStrike, Burp Suite Pro, Powersport
2. Post-Exploit- Bloodhound, Mimi Katz,Impacket, Covenant C2
3. Forensics- Volatility, Wireshark, CHIRP(ICS)
4. Wireless- HackRF One, Proxmark3, Wi-FiPineapple
5. Cloud- Pacu (AWS), MicroBurst (Azure),GCP IAM Exploit Toolkit
Preferred Qualifications
1. Certifications:OSCE³, CREST CCT Gold,OSCP
2. Govt Framework Experience: IM8Penetration Test Guidelines, CSA Cyber Essentials
3. Public Contributions: CVEs, exploit-dbsubmissions, conference talks (Black Hat Asia, DEFCON)
S&P Global · Princeton, United States