
VP, Red Team, Penetration Tester
- Singapore
- Permanent
- Full-time
- Plan and execute red team operations and campaigns across the spectrum of people, processes and technologies.
- Develop techniques from the Mitre ATT&CK framework and perform purple teaming exercises working closely with the SOC team to enhance detection and prevention capabilities.
- Support the development of red teaming methods, operations and simulations within and across the enterprise to include cyber security, personnel security, operations security, facilities security, and third party vendors/service providers.
- Provide cybersecurity technical testing services, including network, system or application penetration test and vulnerability assessment through in-depth technical analysis and exploitation of vulnerabilities.
- Provide regular threat/risk updates, presenting findings and learnings from cyber-attacks, red team operations, and cyber-attack simulations within a context of overall risk to the enterprise.
- Work closely with existing technology infrastructure, business application and security teams, both to receive input and to provide practical and actionable threat intelligence.
- Evaluate, build and support a set of open-source and commercial security tools.
- Plan and manage third party red teaming and penetration tests.
- Bachelor Degree in Computer Science, Computer Engineering, Software Engineering or related discipline.
- OSCP and/or CREST CRT certified.
- Advanced certifications such as OSCE, OSEP, CRTE, OSEE, GXPN, CREST CCT and CCSAS would be an advantage.
- At least 8 years of IT experience, in which over 5 years are in the domain of technical security testing, preferably in a banking environment.
- Excellent infrastructure and web penetration testing skills.
- Ability to circumvent incident detection processes when conducting red team operations.
- Ability to build custom tools and exploits using one or more of the following: Powershell, python, C++ or C#.
- Knowledge of the latest Cybersecurity tools and vulnerabilities.
- Experience in utilizing the Mitre ATT&CK framework would be an advantage.
- Reverse engineering and exploit development experience would be an advantage.
- Red teaming and purple teaming experience would be an advantage, but not a requirement.
- Excellent communication, writing and presentation skills.
- Ability to collaborate and share knowledge within a fast-moving environment.
- Ability to work effectively with a variety of stakeholders interests within the enterprise.