Penetration Tester-Govt Clerance
Privaloma:PythonAWSAzureGoogle CloudCloudMobileSecurityLead
Job Overview
We seek a Penetration Testing with CAT1 clearance to leadVAPT for Singapore government and critical infrastructure sectors. You willexecute full-scope attacks (networks, apps, cloud, OT), bypass advanceddefenses, and deliver actionable remediation strategies. This role requiresCREST/OSCP certification, deep exploit development skills, and experience withGovTech cybersecurity frameworks.
Core-Responsibilities
Advanced Threat Emulation:
- CAT1-clearedengagements:
- Network: Breach segmented govt networks(e.g., air-gapped systems)
- Applications: Exploit web/mobile apps(SCADA interfaces, GovTech portals)
- Cloud: Attack AWS GovCloud/AzureGovernment environments
- OT:ICS/SCADA system penetration(Siemens, Rockwell)
- Develop custom malware/exploits (C++,Python) to evade EDR/XDR.
Reteam Operations:
- Lead multi-vector campaigns:
- Phishing (Evade Proofpoint/MS ATP)
- Physical security bypass (RFID cloning,access control spoofing)
- Wireless attacks (802.1X,WPA3-Enterprise)
- Document TTPs aligned with MITREATT&CK for ICS/Enterprise.
Govt Compliance & Reporting:
- Align tests with IM8, CSA Red TeamingGuidelines, and NIST SP 800-115.
- Deliver executive briefings to CISOswith exploit demos.
- Create remediation playbooks
Research & Development:
- Reverse engineer firmware (Binwalk,Ghidra) for 0-day discovery.
- Contribute to ASEAN CERT advisories(e.g., Sing CERT).
Technical Requirements
Non-Negotiable Credentials
- CAT1Security Clearance
- Active Certifications: OSCP or CRESTCRT/CCT (Inf/App)
- 2+years in pentesting
Tool Proficiency
- Exploitation- Metasploit Pro, CobaltStrike, Burp Suite Pro, Powersport
- Post-Exploit- Bloodhound, Mimi Katz,Impacket, Covenant C2
- Forensics- Volatility, Wireshark, CHIRP(ICS)
- Wireless- HackRF One, Proxmark3, Wi-FiPineapple
- Cloud- Pacu (AWS), MicroBurst (Azure),GCP IAM Exploit Toolkit
Preferred Qualifications
- Certifications:OSCE³, CREST CCT Gold,OSCP
- Govt Framework Experience: IM8Penetration Test Guidelines, CSA Cyber Essentials
- Public Contributions: CVEs, exploit-dbsubmissions, conference talks (Black Hat Asia, DEFCON)