Security Consultant (Offensive Security)

ITSEC SERVICES ASIA PTE. LTD.Singaporemycareersfuturepublished 09/28/2026
Must-have:CloudMobileAIHealthTechSecurityJunior

ITSEC Asia is looking for a Cybersecurity Consultant (Offensive Security) to join our growing team. We are primarily looking for candidates with around 3 years of hands-on penetration-testing experience, although we also welcome applications from strong junior pentesters and early-career professionals who can demonstrate solid technical foundations, curiosity and a genuine passion for ethical hacking. This role provides exposure to a wide range of security assessments across enterprise, cloud, government and critical environments. We are particularly interested in people who are keen to embrace AI, automation and emerging technologies to improve the efficiency, depth and quality of penetration testing. About ITSEC Group ITSEC Group is a cybersecurity organisation operating across the Asia-Pacific region and beyond, with offices in Singapore, Indonesia, Australia, the UAE and Mauritius. We provide cybersecurity consulting and security services to clients across government, critical infrastructure, financial services, telecommunications, healthcare, technology and other industries. Joining ITSEC provides the opportunity to work across diverse technology environments, complex security challenges and a broad range of consulting engagements, while developing both your technical and client-facing capabilities. Key Responsibilities

  • Conduct penetration testing and vulnerability assessments across web applications, APIs, mobile

applications, networks, cloud environments and other technology platforms.

  • Support security assessments involving IT, Operational Technology (OT), Internet of Things (IoT)

and other specialised environments.

  • Identify, validate and demonstrate security vulnerabilities using appropriate testing methodologies

and techniques.

  • Assess the technical and business impact of identified vulnerabilities and attack paths.
  • Document testing activities, technical evidence, proof-of-concept results and assessment

conclusions in a clear and defensible manner.

  • Prepare professional penetration-testing reports covering findings, risk implications, supporting

evidence and practical remediation recommendations.

  • Present technical findings to clients and explain security risks and remediation approaches to both

technical and non-technical stakeholders.

  • Conduct remediation verification and retesting to confirm that identified vulnerabilities have been

effectively addressed.

  • Explore and responsibly apply AI-assisted security testing, automation, scripting and emerging

technologies to improve research, reconnaissance, analysis, testing and reporting workflows.

  • Continuously develop knowledge of emerging vulnerabilities, attack techniques, security tools,

technologies and industry methodologies.

  • Contribute to the development of the team's testing methodologies, knowledge base, tooling and

technical capabilities. What We Are Looking For

  • Diploma or degree in Cybersecurity, Information Security, Computer Science, Engineering or a

related discipline.

  • Ideally around 3 years of relevant hands-on penetration-testing or offensive-security experience.
  • Strong junior candidates with less experience are also encouraged to apply if they can demonstrate

good practical offensive-security skills and a strong willingness to learn.

  • CREST Registered Tester (CRT), Offensive Security Certified Professional (OSCP) or a comparable

recognised offensive-security certification is strongly preferred.

  • Good practical understanding of penetration-testing methodologies, tools and techniques.
  • Hands-on experience in areas such as web application, API, network, Active Directory, mobile or

cloud penetration testing will be advantageous.

  • Experience or knowledge in OT, ICS, IoT or critical-infrastructure security testing is highly

advantageous.

  • Strong analytical, troubleshooting and problem-solving capabilities.
  • Ability to produce clear, accurate and professional technical reports.
  • Good communication skills and the ability to explain technical security issues clearly to clients.
  • Interest in AI, automation, scripting and emerging offensive-security technologies, together with the

ability to learn and adapt quickly.

  • Willingness to take ownership, work collaboratively and continue developing professionally within a

cybersecurity consulting environment. Singapore Government / Classified Project Experience Singapore citizens are preferred, particularly candidates who are eligible to support sensitive or classified Singapore Government engagements. Previous experience working on Singapore Government, highly classified, critical-infrastructure or other high-security projects is highly advantageous. Candidates who are familiar with the security expectations, professional conduct, documentation discipline and operational constraints associated with sensitive government environments will be especially relevant to this role. What You Can Expect ITSEC provides on-the-job training, technical mentorship and exposure to experienced cybersecurity professionals to help consultants continue developing their capabilities. You will have opportunities to:

  • Work on diverse and technically challenging penetration-testing engagements.
  • Develop deeper expertise across traditional IT, cloud, OT and emerging technology environments.
  • Strengthen your consulting, client communication and professional report-writing skills.
  • Learn from experienced offensive-security practitioners.
  • Experiment responsibly with AI-assisted and automated security-testing approaches.
  • Progress technically into specialised offensive-security domains as your experience develops.

If you enjoy understanding how systems can be broken, explaining why it matters, and helping organisations become more secure, we would be happy to hear from you.