Make an Impact by
- Seeking a highly skilled and motivated Cyber Security Testing Lead who is skilled in application and infrastructure penetration testing, vulnerability assessment and source code review to guide and review the work of external and cross function team security testers. Need to be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders.
- Review and tailor the scope of external penetration testing, along with Domain security champions.
- Review the results of external penetration tests and partner with Domains to contextualise findings and prioritise remediation
- Conduct application and infrastructure penetration testing, vulnerability assessment and source code review in line with Singtel’s standards, through leveraging own team, cross-functional teams or external testers.
- Perform targeted application security assessments and penetration tests for various applications such as mobile, and web services as needed.
- Collaborate with cross-functional teams to provide guidance on Singtel’s standards, security best practices and recommend remediation strategies.
- Work with third party penetration testers to coordinate annual penetration tests for the organisation.
- Collaborate with cross-functional team’s penetration testers and provide guidance on scoping, rules of engagement, testing methodology and reporting.
- Develop and maintain detailed documentation of security assessments, including findings, methodologies, and recommendations.
- Utilize both manual testing and automated application vulnerability scanning/testing tools for assessments.
- Retest security vulnerabilities and update reports with retesting results.
- Stay updated with the latest security trends, vulnerabilities, and attack techniques to enhance the effectiveness of security testing methodologies.
Skills for Success
- Bachelor’s degree in computer science, Information Security, or a related field.
- Solid experience in application security testing, vulnerability assessment, source code review and penetration testing.
- Proficiency in performing application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
- Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
- Attained OSCP or CREST
- Familiarity with various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, etc.
- Strong understanding of APIs, HTTP protocol, and Cloud technologies
- Familiarity with secure coding practices and common programming languages
- Strong written and verbal communication skills, including the ability to effectively communicate complex technical concepts to both technical and non-technical stakeholder.