The Consultant will perform vulnerability assessments and red teaming, enhance security capabilities, lead teams, and provide client support while staying updated on cyber threats.
Ensign is hiring !
Consultant, Cyber Adversarial Emulation
Duties and Responsibilities
- Conduct Vulnerability Assessments (VA), Penetration Testing (PT) and Red Teaming across various technologies but not limited to networks, web, mobile, thick client applications, cloud environments (AWS, Azure, GCP, alicloud), kubernetes and operational technology (OT)
- Enhance internal VAPT and red team capabilities by developing scripts, automating processes and researching the latest exploitation Tactics, Techniques and Procedures (TTPs) used by threat actors.
- Provide technical support to the pre-sales team and ensure clear communication of complex client requirements.
- Lead and mentor a team of consultants, ensuring effective communication of vulnerabilities and remediation recommendations to clients. Foster a culture of innovation, continuous improvement and knowledge sharing within the team.
- Organise and participate in Capture-The-Flag (CTF) events, both internally and externally.
- Collaborate with other cybersecurity teams within Ensign to provide actionable insights to clients.
Requirements
- Familiarity with cyber security principles (e.g. networking, web development, vulnerability classes) and industry best practices (e.g. OWASP Top 10, MITRE ATT&CK Framework and Cybersecurity Code of Practice (CCOP))
- Experienced in consulting, including both internal and client-facing engagements
- Ability to lead projects independently and communicate effectively with clients.
- Proficiency in programming/scripting languages such as .NET, Python, Bash and PowerShell.
- Possess relevant cybersecurity certifications (OSCP, OSCE3, CRT, CRTO) or accredited experience through CTF participation and Bug Bounties.
- Willing to travel internationally when required.
Preferred Qualifications/Skills
- At least 5 years of consulting experience
- Proficient with security testing tools such as Nessus, Burp Suite, Frida, dex2jar, etc.
- Offensive Cyber Security Certifications (e.g. OSCP, CRT preferred)
- Experience in mobile application security testing (Android/iOS).
- Familiarity with red teaming tools such as Cobalt Strike, GoPhish, Sliver etc.
- Expertise in source code review using automated scanners such as Checkmarx
- Experience in reverse engineering or malware development
- Competency in static and dynamic analysis
- Experience working in diverse security testing environments, including using jump hosts, VPNs, testing in GCC AWS/Azure, and both onsite and remote setups.
- A self-motivated learner with a passion for developing and leading teams to deliver professional services and enhance local capabilities.
Top Skills
.Net
AWS
Azure
Bash
Burp Suite
Checkmarx
Cobalt Strike
GCP
Gophish
Nessus
Powershell
Python
Ensign InfoSecurity Singapore Office
30A Kallang Place, #08-01, Singapore, Singapore , Singapore, 339213
Similar Jobs
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
As Complaints Lead, you'll analyze and resolve regulatory complaints, collaborate with legal teams, enhance customer experience workflows, and support compliance efforts.
Financial Services
The role involves monitoring security infrastructure, conducting investigations of incidents, developing response playbooks, and collaborating on security strategies.
Top Skills:
CryptographyLog AnalysisNetwork Traffic AnalysisSecurity Architecture DesignVulnerability Management
Financial Services
The role focuses on product development for cross-border payments, collaborating with technology and client teams to enhance product offerings and drive growth in the FX payments market.
Top Skills:
Ach SolutionsData AnalyticsDigital Payment Platforms
What you need to know about the Singapore Tech Scene
The digital revolution has driven a constant demand for tech professionals across industries like software development, data analytics and cybersecurity. In Singapore, one of the largest cities in Southeast Asia, the demand for tech talent is so high that the government continues to invest millions into programs designed to develop a talent pipeline directly from universities while also scaling efforts in pre-employment training and mid-career upskilling to expand and elevate its workforce.