Skip to content

Open nowPosted 34 days ago

Senior Cybersecurity Consultant (ASG), Cybersecurity Engineering Centre

Workable (global search)108,016 open roles

Where
Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Cybersecurity Consultant (ASG), Cybersecurity Engineering CentreWorkable (global search) · Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 34 days ago

Workable (global search) median: 7 days open

The posting

You will be part of the Attack Simulation Group (ASG) within the Cyber Security Agency of Singapore (CSA), a specialist team responsible for delivering advanced security testing and adversary-led assessments to strengthen the resilience of Critical Information Infrastructure (CII). This is a senior, hands-on role for experienced offensive security practitioners who want to apply real-world attack techniques to complex, high-impact systems in support of Singapore’s national cyber security mission.

ASG is a technically driven team within CSA focused on realistic attack simulation, penetration testing, red teaming, and purple-teaming outcomes. Our work goes beyond compliance-driven assurance, emphasising hands-on testing, attacker tradecraft, and practical security improvements.

Operating within the realities of government, we value curiosity, adaptability, and out-of-the-box thinking. Specialised training and development opportunities are provided to continuously deepen and expand our technical capabilities, and team members are expected to continuously learn, apply skills across domains, and contribute to the evolution of attack simulation practices across Singapore’s CII.

We also believe in sharing and growing our craft where appropriate. Some of our public work and tooling can be found at: 👉 https://github.com/hack-techv2/

Responsibilities: - Lead and conduct penetration testing, red teaming, and adversary simulation activities across web, mobile, infrastructure, cloud, OT, and telecommunications environments.

- Execute realistic attack scenarios to assess the resilience of Critical Information Infrastructure (CII), including systems supporting essential services.

- Support purple-teaming activities by translating offensive techniques into actionable detection and response improvements.

- Lead engagements end-to-end, including planning, execution, reporting, and technical debriefs with stakeholders.

- Mentor junior consultants and contribute to raising the team’s overall technical standard.

- Drive continuous improvement of ASG’s testing methodologies, tooling, and research, including taking on problem spaces outside your primary domain when required.

- And because this is government, be prepared to occasionally switch gears by contributing to strategic initiatives, supporting and executing procurement activities, participating in industry outreach, or undertaking coordination work, all of which ultimately help us strengthen security outcomes and make Singapore a safer place to live and work.

Why Join ASG at CSA?

- Work on nationally significant systems, including CII, OT, and telecommunications environments rarely accessible outside government.

- Engage in deep, technically challenging work that prioritises realism, learning, and security outcomes over high-volume testing.

- Apply your offensive security expertise to a public mission that directly contributes to Singapore’s cyber resilience.

- Be part of a specialist team that is deliberately building towards strong technical depth, continuous learning, and moving beyond compliance-driven assurance, and help shape what “good” looks like along the way.

Requirements

- An attacker’s mindset with strong technical understanding of operating systems, networks, and modern enterprise environments.

- Proven ability to identify and execute real-world attack scenarios, beyond automated or checklist-based testing.

- Experience in penetration testing and/or red team operations, with exposure to adversary tradecraft and attack chaining.

- Demonstrated adaptability to transfer skills across technical domains (e.g. web to mobile, IT to OT, on-prem to cloud).

- Strong technical writing skills and the ability to clearly articulate security risks and impact.

- Typically 5–8 years of relevant experience in penetration testing, red team operations, or related offensive security roles, with demonstrated depth in hands-on technical work.

- Relevant industry certifications such as OSCP, CREST (e.g. CRT, CCT), CRTO, or equivalent are desirable.

- That said, we recognise that certifications alone do not define capability. Hands-on experience, problem-solving ability, and technical depth matter more to us than badges.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.