Job Profile: Simulated Attack Specialist
Simulated Attack Specialist
You will play a unique role challenging the status quo to strengthen the resilience of our digital infrastructures. You will provide assurance for whole-of-Government, Critical Information Infrastructure (CII) and beyond through simulating the threat of advanced attackers.
What you can expect to be doing:
-
Design, implement and manage digital security solutions and infrastructure to mitigate sophisticated cyber threats
-
Conduct attack simulation (vulnerability assessment, penetration testing, red/purple teaming) on Enterprise, Industrial Control and Telco systems
-
Work closely with respective stakeholders to facilitate the engagements, provide technical consultancy, report findings, and recommend remediations
-
Develop niche skillsets and customise tools to support attack simulation
-
Research modern and advanced techniques, tactics, and procedures and conduct technical sharing
Join us if you have:
-
Experience in Enterprise IT/Cloud, Industrial Control Systems or Telco technologies. This includes their underlying operations, architectures, networks, products, and security standards
-
CRT/OSCP or equivalent penetration testing-specific certifications
-
Passion for cybersecurity, technically hands-on, willingness to learn, and curious about the inner workings of technologies and exploiting their vulnerabilities
-
Experience using tools (Nmap, BurpSuite, Metasploit, Cobalt Strike, etc.) and programming languages (Python, VBscript, Javascript, Powershell, etc.)
-
Public disclosure of vulnerabilities or relevant awards/participations from Capture-The-Flags (CTF) competitions
-
Excellent analytical, conceptualisation, and problem-solving skills
-
Strong communication and interpersonal skills to collaborate with key stakeholders
Consultant (Attack Simulation Group), Cyber Security Engineering Centre, CSA
Joined in 2018
"Knowing that my contribution in CSA helps society move forward in this new digital age motivates me to put my best foot forward.”
[Find out more about Xavier Yeo]
Senior Cybersecurity Specialist, GovTech
2019-2022
“I love the burst of excitement when I manage to spot some vulnerable code and develop it into a working exploit!”
[Find out more about Loke Hui Yi]