Skip to content

Open nowPosted 4 days ago

Lead Cybersecurity Specialist (Offensive Security)

MyCareersFuture94,028 open roles

Pay
SGD 12,000 – SGD 15,000 a Monthly
Where
Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLead Cybersecurity Specialist (Offensive Security)MyCareersFuture · Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 4 days ago

The posting

​Our Client is an established company in Singapore, who is seeking to recruit a Lead Cybersecurity Specialist (Offensive Security).

Lead Cybersecurity Specialist (Offensive Security)

As the Cybersecurity Specialist (Offensive Security) within the CISO Office, you will be the domain expert responsible for elevating the security testing and "Secure-by-Design" capabilities across the entire Family. You will bridge the gap between high-level governance and technical implementation, ensuring that all agencies under the ’s purview adopt consistent, high-quality security practices. Your role is pivotal in shifting from a reactive security posture to a proactive, resilient one.

Key Responsibilities

1. Security Testing Governance & Standardisation

· Establish Standards: Define and maintain the -wide framework for security testing (Vulnerability Assessment and Penetration Testing - VAPT).

· SOP Development: Create and roll out Standard Operating Procedures (SOPs) to guide project teams on engaging external security vendors and managing internal testing cycles.

· Quality Assurance: Develop "Quality Rubrics" to help agencies evaluate the performance of pen-testers. You will conduct periodic sampling of testing reports and project involvements to ensure quality and rigour across the Company.

2. Advanced Technical Operations

· Red Teaming & Critical Testing: Lead and execute complex Red Teaming exercises and deep-dive penetration tests on the ’s high-impact systems.

· Adversary Simulation: Utilise knowledge of the latest Adversary Tactics, Techniques, and Procedures (TTPs) to simulate real-world attacks, helping agencies identify blind spots in their prevention, detection and response capabilities.

· Environmental Scanning: Proactively monitor the global threat landscape to identify emerging threats and evolving actor TTPs. Assess how these changes impact the 's current security posture and update testing standards accordingly.

3. Secure-by-Design & Source Code Excellence

· Secure Coding Standards: Establish -wide secure coding guidelines (e.g., based on OWASP, SANS) to ensure developers build security into the application layer from day one.

· Source Code Analysis: Lead the strategy for Static Application Security Testing (SAST) and Software Composition Analysis (SCA). You will evaluate tools that automate the detection of vulnerabilities in source code and third-party libraries.

· CI/CD Integration: Evaluate, recommend, and provide guidance on integrating security tools into the agencies' DevOps pipelines (DevSecOps).

· Code Quality Oversight: Review and recommend systems that help to boost code quality, ensuring that security is treated as a core component of "clean code."

· Technology Foresight: Stay abreast of technology changes (e.g., Cloud-native security, AI-driven development) and recommend systems/technologies that enhance code quality and resilience.

4. Stakeholder Engagement & Advocacy

· Consultative Leadership: Act as a trusted advisor to CIOs, ACISOs, and Project Owners to educate them and inculcate a culture of secure-by-design.

· Community of Practice: Establish a platform for knowledge sharing among security practitioners within the Family to harmonise security testing efforts.

Requirements

Experience

· Years of Experience: 8 to 10 years of deep technical experience in Cybersecurity, with a strong focus on offensive security and application security.

· Domain Expertise: Proven track record in conducting penetration tests for Web Applications, IT Systems (on-premises and cloud environments), and complex Network architectures.

· Code Review Mastery: Experience in performing manual and automated source code reviews to identify logic flaws, injection vulnerabilities, and cryptographic weaknesses.

Technical Skills

· Secure Development: Deep understanding of secure software development lifecycles (SSDLC) and the ability to read/analyze common programming languages (e.g., Java, Python, .NET, JavaScript).

· Source Code Analysis Tools: Proficiency with enterprise-grade SAST, DAST, SCA and VAPT tools (e.g., Checkmarx, Fortify, SonarQube, Snyk, Burp Suite).

· Offensive Security: Proficiency in manual and automated testing tools; deep understanding of the MITRE ATT&CK framework and common TTPs.

· Cloud & DevOps: Experience with Government Commercial Cloud (GCC) environments and practical knowledge of Jenkins, GitLab CI, or GitHub Actions.

· Certifications: Professional certifications such as OSCP, OSWE (Offensive Security Web Expert), CASE (Certified Application Security Engineer), or GWEB are highly desirable.

Soft Skills

· Influence & Diplomacy: Ability to communicate complex technical risks to non-technical stakeholders (CIOs/Project Owners) and influence change without direct reporting lines.

· Analytical Mindset: Ability to spot patterns in "bad" testing jobs or recurring code vulnerabilities and provide constructive feedback to improve Company-level performance.

· Intellectual Curiosity: A strong commitment to continuous learning and keeping pace with the rapidly evolving cyber threat landscape.

JJ Consulting Services

EA Licence No.: 12C6207

Applicants are invited to send in a MS Word resume to [email protected] stating position applying for/present/expected salaries and earliest available date.

We thank all applicants in advance and regret that only short listed candidates will be notified.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.