Cybersecurity Consultant (CREST CRT & OSCP) | Singapore
Job Description
Company Description Firmus, founded in 2008 by experienced cybersecurity professionals, is an industry leader in advanced cybersecurity services and solutions. The company is ISO/IEC 27001:2022 certified and CREST accredited for penetration testing, demonstrating strong commitment to security and compliance. Its integrated team specializes in Assessment, Assurance, Operational Technology, and Cybersecurity Solutions, partnering with organizations to manage cyber risks and support business growth. With nearly two decades of proven experience, Firmus helps clients address expanding attack surfaces and evolving cyber threats. Applicants can expect to work in a highly specialized environment that focuses on safeguarding businesses through comprehensive cybersecurity services.
Role Description This is a full-time, on-site Cybersecurity Consultant role based in Singapore, focused on penetration testing and security consulting for a wide range of clients. The consultant will plan and execute application and network penetration tests, perform vulnerability assessments, and analyze security configurations in line with CREST CRT and OSCP standards. Day-to-day responsibilities include preparing test scopes, documenting findings, developing remediation recommendations, and presenting clear, actionable reports to technical and non-technical stakeholders. The role also involves collaborating with internal teams on security assessments, contributing to methodologies and toolsets, and staying current with emerging threats, exploits, and defensive techniques. The consultant will support pre-sales and client engagements as needed, helping align cybersecurity services with business objectives.
Qualifications
Role Description This is a full-time, on-site Cybersecurity Consultant role based in Singapore, focused on penetration testing and security consulting for a wide range of clients. The consultant will plan and execute application and network penetration tests, perform vulnerability assessments, and analyze security configurations in line with CREST CRT and OSCP standards. Day-to-day responsibilities include preparing test scopes, documenting findings, developing remediation recommendations, and presenting clear, actionable reports to technical and non-technical stakeholders. The role also involves collaborating with internal teams on security assessments, contributing to methodologies and toolsets, and staying current with emerging threats, exploits, and defensive techniques. The consultant will support pre-sales and client engagements as needed, helping align cybersecurity services with business objectives.
Qualifications
- Strong foundation in Cybersecurity and Information Security, including security principles, threat landscapes, and risk management.
- Hands-on experience in Application Security, such as web and mobile penetration testing, secure code review, and common vulnerability exploitation.
- Practical skills in Network Security, covering network penetration testing, secure configuration review, and network protocols.
- Proficiency in Vulnerability Assessment, including use of industry-standard tools, manual verification, and prioritization of findings.
- Valid CREST Registered Tester (CRT) and Offensive Security Certified Professional (OSCP) certifications.
- Experience with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Wireshark) and scripting or automation (e.g., Python, Bash, PowerShell).
- Strong analytical, documentation, and report-writing skills, with the ability to communicate clearly to both technical and business audiences.
- Ability to work collaboratively in a team environment, manage multiple engagements, and maintain high professional and ethical standards.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience; prior consulting or client-facing experience is an advantage.
More Info
Key Skills
CREST Registered Tester CRT
Offensive Security Certified Professional OSCP
