Penetration Tester-Govt Clerance
infinity cybersec pte. ltd.- Posted 8 days ago
- Be among the first 10 applicants
Job Description
JobOverview
Weseek a Penetration Testing with CAT1 clearance to lead VAPT for Singaporegovernment and critical infrastructure sectors. You will execute full-scopeattacks (networks, apps, cloud, OT), bypass advanced defenses, and deliveractionable remediation strategies. This role requires CREST/OSCP certification,deep exploit development skills, and experience with GovTech cybersecurityframeworks.
CoreResponsibilities
AdvancedThreat Emulation:
1. CAT1-clearedengagements:
2. Network:Breach segmented govt networks (e.g., air-gapped systems)
3. Applications:Exploit web/mobile apps (SCADA interfaces, GovTech portals)
4. Cloud:Attack AWS GovCloud/Azure Government environments
5. OT:ICS/SCADA system penetration (Siemens, Rockwell)
6. Developcustom malware/exploits (C++, Python) to evade EDR/XDR.
RedTeam Operations:
1. Leadmulti-vector campaigns:
2. Phishing(Evade Proofpoint/MS ATP)
3. Physicalsecurity bypass (RFID cloning, access control spoofing)
4. Wirelessattacks (802.1X, WPA3-Enterprise)
5. DocumentTTPs aligned with MITRE ATT&CK for ICS/Enterprise.
GovtCompliance & Reporting:
1. Aligntests with IM8, CSA Red Teaming Guidelines, and NIST SP 800-115.
2. Deliverexecutive briefings to CISOs with exploit demos.
3. Createremediation playbooks
Research& Development:
1. Reverseengineer firmware (Binwalk, Ghidra) for 0-day discovery.
2. Contributeto ASEAN CERT advisories (e.g., SingCERT).
TechnicalRequirements
Non-NegotiableCredentials
1. CAT1Security Clearance
2. ActiveCertifications: OSCP or CREST CRT/CCT (Inf/App)
3. 2+years in pentesting
ToolProficiency
1. Exploitation- Metasploit Pro, Cobalt Strike, Burp Suite Pro, PowerSploit
2. Post-Exploit- BloodHound, Mimikatz, Impacket, Covenant C2
3. Forensics- Volatility, Wireshark, CHIRP (ICS)
4. Wireless- HackRF One, Proxmark3, Wi-Fi Pineapple
5. Cloud- Pacu (AWS), MicroBurst (Azure), GCP IAM Exploit Toolkit
PreferredQualifications
1. Certifications:OSCE³, CREST CCT Gold, OSCP
2. GovtFramework Experience: IM8 Penetration Test Guidelines, CSA Cyber Essentials
3. PublicContributions: CVEs, exploit-db submissions, conference talks (Black Hat Asia,DEFCON)
More Info
Key Skills
HackRF One
GCP IAM Exploit Toolkit
PowerSploit
AWS MicroBurst
Impacket
CREST OSCP certification
Metasploit Pro
Proxmark3
CHIRP ICS
Exploit development
Burp Suite Pro
Mimikatz
Covenant C2
BloodHound
Wi-Fi Pineapple
Cobalt Strike
