Skip to content

Open nowPosted 16 days ago

Application Security Penetration Tester

MyCareersFuture94,028 open roles

Pay
SGD 8,000 – SGD 14,000 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowApplication Security Penetration TesterMyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 16 days ago

The posting

Role Overview

We are seeking an experienced Application Security Penetration Tester to perform security assessments across web applications, APIs, and supporting application environments. The role will focus on identifying and validating vulnerabilities through penetration testing, SAST, DAST, and vulnerability assessment activities.

The successful candidate will also work closely with development and DevOps teams to support vulnerability remediation and integrate security testing into DevSecOps and CI/CD processes.

Key Responsibilities

  • Perform penetration testing and security assessments across web applications and APIs.
  • Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Vulnerability Assessment and Penetration Testing (VAPT).
  • Identify, validate, assess, and document application security vulnerabilities.
  • Evaluate applications against OWASP Top 10 and other common application security risks.
  • Produce clear security assessment reports covering findings, severity, impact, and recommended remediation.
  • Perform remediation validation and vulnerability retesting.
  • Support Red Team and security testing activities where required.
  • Integrate automated security testing into DevSecOps and CI/CD pipelines.
  • Collaborate with development, DevOps, and security teams to resolve identified vulnerabilities.
  • Provide guidance on secure development and application security best practices.

Required Skills

  • 3–8 years of relevant experience in Application Security, Penetration Testing, VAPT, or DevSecOps Security.
  • Strong hands-on experience with SAST, DAST, and penetration testing.
  • Strong understanding of web application and API security.
  • Good knowledge of OWASP Top 10 and common application vulnerabilities.
  • Hands-on experience with security tools such as Burp Suite, OWASP ZAP, Checkmarx, Fortify, SonarQube, Nessus, or Qualys.
  • Familiarity with CI/CD and DevSecOps environments using tools such as Jenkins, GitLab, GitHub, or Azure DevOps.
  • Understanding of container security and environments such as Docker and Kubernetes.
  • Ability to analyze security findings, distinguish genuine vulnerabilities from false positives, and recommend appropriate remediation.
  • Strong analytical, troubleshooting, documentation, and communication skills.

Preferred Skills

  • Experience with Red Teaming or adversarial security testing.
  • Relevant security certifications such as OSCP, CEH, CREST, or equivalent.
  • Experience working within large enterprise or regulated environments.
  • Familiarity with secure coding practices and Software Development Life Cycle (SDLC) security.

Application Note

Interested applicants may send their CV directly to [email protected] for consideration.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.