Search Jobs

Search by job, company or skills

Consultant, Security Testing and Red Teaming

Consultant, Security Testing and Red Teaming

Ensign InfoSecurity
3-5 Years
  • Posted 17 days ago
  • Be among the first 10 applicants

Job Description

Consultant, Security Testing and Red Teaming

Description

The Consultant, Security Testing and Red Teaming is a core delivery role within the offensive security practice, responsible for independently executing penetration testing engagements and contributing to advanced offensive security activities.

This role has a strong emphasis on hands-on penetration testing across web applications, infrastructure, Active Directory, and cloud environments. Consultants are expected to operate with a high degree of autonomy on scoped engagements, apply sound technical judgement, and produce high-quality, defensible findings and reports for clients.

While penetration testing is the primary focus, Consultants are also expected to demonstrate the curiosity and technical breadth to grow into broader offensive security disciplines over time, including adversary simulation, red teaming, tooling development, and security research.

Roles and Responsibilities

  • Deliver end-to-end penetration testing engagements with minimal supervision, including:
  • Web application penetration testing
  • Internal and external network penetration testing
  • Active Directory security assessments
  • Cloud and hybrid environment testing
  • Mobile application penetration testing
  • IOT penetration testing
  • OT penetration testing
  • Perform manual vulnerability discovery, validation, and exploitation beyond automated scanning.
  • Identify attack paths, chain vulnerabilities, and assess real-world business impact.
  • Exercise sound judgement in exploitation depth, data handling, and risk management during testing.
  • Maintain clear, detailed testing notes, evidence, and attack logs to support reporting and quality review.
  • Produce high-quality technical findings with accurate severity assessment and actionable remediation guidance.
  • Develop structured penetration testing reports, and support client walkthroughs and debriefs.
  • Engage professionally with clients during kick-off sessions, testing clarification, and results discussions.
  • Participate in peer reviews of testing approaches and reports to uphold delivery quality standards.
  • Continuously develop technical depth across offensive security techniques, platforms, and tooling.
  • Contribute to security testing playbooks, internal knowledge sharing and peer learning.
  • Where appropriate, contribute to broader offensive security initiatives, such as:
  • Adversary simulation and red teaming exercises
  • Custom tooling, scripting, or automation
  • Internal research, labs, or capability development

Requirements

  • Offensive Security Certified Professional (OSCP) is required.
  • To hold at least one advanced or specialist certifications such as OSWE, OSEP, OSED
  • Approximately 3 to 5 years of hands-on penetration testing experience in consulting, internal security, or equivalent practical environments.
  • Strong understanding of penetration testing methodologies, rules of engagement, and ethical hacking principles.
  • Solid technical foundations in:
  • TCP/IP networking and common protocols
  • Windows and Linux operating systems
  • Web application architecture and common vulnerability classes
  • Demonstrated experience testing:
  • Web applications, including authentication, authorization, and business logic flaws
  • Network and infrastructure environments
  • Active Directory domains
  • Mobile applications
  • Proficiency with common penetration testing tools (e.g. Burp Suite, Nmap, Metasploit, BloodHound).
  • Experience with scripting or programming (e.g. Python, PowerShell, Bash) to support testing and automation.
  • Exposure to cloud security testing (AWS, Azure, GCP) and modern identity platforms.
  • Experience with post-exploitation, lateral movement, and attack path analysis.
  • Demonstrated interest in expanding beyond traditional penetration testing into broader offensive security and red teaming.
  • Ability to clearly communicate technical findings in written reports and verbal discussions.
  • Strong professionalism, integrity, and attention to detail.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Mobile Application Penetration Testing

Vulnerability Discovery

IOT Penetration Testing

Active Directory Security Assessments

Cloud Security Testing

BloodHound

OT Penetration Testing

About Company

Similar Jobs

3-5 yrs
Singapore
Skills:
Cloud security testing (AWS, GCP), Metasploit, Web Application Penetration Testing, PowerShell, Penetration Testing, Nmap, Bash, Burp Suite, Azure, Python, Active Directory security assessments, TCP/IP networking and common protocols, Cloud and hybrid environment testing, OT penetration testing, Mobile application penetration testing, Windows and Linux operating systems, Post-exploitation lateral movement and attack path analysis, BloodHound, Internal and external network penetration testing, Web application architecture and common vulnerability classes, IOT penetration testing
4-7 yrs
SGD 3,000 - 9,000 per month
Singapore, Ubi
Skills:
Iso 27001, Vulnerability Management, Penetration Testing, Cybersecurity Risk Management, Third-Party Risk Management, Security Governance, Incident Response and Recovery, Red teaming exercises
5-8 yrs
SGD 6,000 - 8,000 per month
Singapore
Skills:
FTP, Azure Functions, Power Automate, Edi, Rest Apis, Web Services, Logic Apps, Microsoft Dynamics 365 Business Central, C-AL, Al, Dynamics NAV
5-8 yrs
SGD 11,000 - 14,500 per month
Singapore
Skills:
Adversarial penetration testing, CREST CRT certification, Static Analysis, Manual code review
5-8 yrs
SGD 9,000 - 10,000 per month
Orchard Road, Singapore
Skills:
Apis, system integration, automation solutions, Python, orchestration frameworks, secure software delivery practices, LLMs, cloud-native applications, cloud platforms, vector databases, security governance, software development best practices, production support environments, AI agents