Skip to content

Open nowPosted 3 days ago

Senior Penetration Testing Engineer

MyCareersFuture91,045 open roles

Pay
SGD 8,000 – SGD 11,000 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Penetration Testing EngineerMyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. MyCareersFuture postings stay open a median of 1 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 3 days ago

MyCareersFuture median: 1 days open

The posting

Job Responsibilities

  1. Conduct comprehensive penetration testing of the company's and clients' web systems, applications, and internal network environments, identifying and verifying security vulnerabilities;
  2. Independently execute the full penetration testing lifecycle: information gathering, vulnerability scanning, vulnerability verification, privilege escalation, lateral movement within internal networks, etc.;
  3. Perform in-depth analysis of common vulnerabilities including SQL injection, XSS, CSRF, command execution, insecure deserialization, and OWASP Top 10 vulnerabilities, and provide remediation recommendations;
  4. Conduct code audits covering Java frameworks (Spring, Spring Boot, Spring MVC, MyBatis, etc.) and source-level identification of common web vulnerabilities;
  5. Perform mobile application (APP) security testing, including decompilation, hardening/reinforcement detection, static/dynamic analysis, and API penetration testing;
  6. Independently prepare penetration testing reports and communicate technical findings with project teams and clients;
  7. Participate in red team/blue team exercises and cyber defense drills, taking on responsibilities such as monitoring and analysis, attack attribution, and vulnerability remediation;
  8. Maintain familiarity with security frameworks such as MAS TRM, DORA, PCI DSS, ISO 27001, and SOC 2;
  9. Assist in delivering enterprise information security training to enhance internal security awareness.

Requirements

Basic Requirements

  • Bachelor's degree or above in Computer Science, Computer Engineering, or a related field;
  • 5+ years of experience in penetration testing / information security, with experience on both the client side and security vendor (consulting) side preferred;
  • Strong ability to work independently, capable of taking on a project lead role and independently liaising with clients and project teams.

Technical Skills

  • Proficient in end-to-end penetration testing methodology, with hands-on experience in internal network penetration testing (tunneling via ICMP/LCX/SSH, pass-the-hash, pass-the-ticket, lateral movement via WMI/PsExec, etc.);
  • Proficient with security scanning and penetration testing tools such as AWVS, Nmap, SQLMap, Burp Suite, and AppScan;
  • Capable of conducting Java code audits, familiar with tools such as Fortify and Eclipse, and vulnerability identification methods for common frameworks;
  • Proficient in Python development, with the ability to independently write security tools (directory scanners, subdomain scanners, C-segment scanners, protocol brute-forcing tools, PoC/exploit development, etc.);
  • Familiar with mobile application security testing, including APP decompilation (JADX, apktool), hardening/reinforcement identification, and dynamic testing with Frida;
  • Familiar with common middleware attack techniques and host security inspection procedures.

Nice to Have

  • Holds security certifications such as OSCP, OSWE, CREST, or has proof of original CVE disclosures;
  • Project experience with high-security clients in financial services, government, or large state-owned enterprises;
  • Experience participating in large-scale red team, purple team, or threat-led penetration testing engagements;
  • Experience in security technical sharing/training, or an active personal technical blog/open-source project portfolio.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.