Penetration Tester & Security Researcher
BNF Corporation Co., Ltd. · Singapore River, Central Region ·
- Work mode
- Hybrid
- Employment
- Full time
- Category
- Security
- Experience
- 3+ years
- Visa sponsorship
- No
BNF Corporation Co., Ltd. · Singapore River, Central Region ·
Interactive Brokers · Mumbai, MH, IN
SCIENTE INTERNATIONAL PTE. LTD. · Singapore
IGamingHunt · Remote
lbg · Manchester
Mid-to-senior penetration tester and security researcher in Singapore performing grey/white-box pentesting and security research across web apps, infrastructure/Active Directory, cloud/Kubernetes, AI systems, mobile, and source code, with client reporting and internal tooling. OSCP or CREST CRT certification and Singapore work authorization are mandatory.
About the role
We are looking for a Mid-to-Senior Penetration Tester & Security Researcher to join our team in Singapore. At BNF SG, we work on complex security challenges where going beyond standard testing methodologies is essential. Our engagements are typically grey-box or white-box, often with access to source code, and we expect our researchers to dig deep and uncover vulnerabilities others may miss. Our work spans web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code. For us, penetration testing is not just about running tools — it's about understanding how systems work, challenging assumptions, and conducting real security research. You'll report to the Team Lead and work alongside a small team of security researchers in an international, collaborative, and highly technical environment. You'll work independently on complex problems and together with the team on live client engagements.
Key responsibilities
Conduct penetration testing and security research across web applications, infrastructure and networks, cloud and Kubernetes environments, AI systems, mobile applications, and source code.
Take ownership of security reporting, including technical accuracy, root-cause analysis, and real-world business impact.
Present vulnerabilities, findings, and recommendations clearly to clients and their technical teams.
Build internal security tools, methodologies, automation, and agentic workflows that enable the team to work faster and go deeper.
Contribute to red team and adversary emulation engagements.
Independently investigate unfamiliar technologies, attack surfaces, and complex technical problems.
About you
3+ years of hands-on experience in penetration testing and/or security research (mandatory).
Deep expertise in at least two of the following areas: web application penetration testing, infrastructure and network penetration testing including Active Directory with fluency in Windows and Linux internals and privilege escalation, or manual source code review and vulnerability research.
OSCP or CREST CRT certification (mandatory).
Strong research mindset, technical curiosity, and the ability to independently investigate unfamiliar technologies and attack surfaces.
Hands-on experience using AI tools to support security testing, research, automation, or tool development, with a strong interest in exploring new AI-driven security workflows.
Ability to work independently on deep technical problems and collaboratively on live client engagements.
Excellent written and verbal English communication skills.
Currently based in Singapore with valid work authorization (mandatory).
Availability to work in a hybrid model in Singapore, including regular work at client sites.
FPT Asia Pacific Pte Ltd · Singapore