Deskripsi Pekerjaan
Are you an elite security professional looking to make a tangible impact on the stability and resilience of Singapore’s financial ecosystem? The Monetary Authority of Singapore (MAS) is seeking a highly skilled Senior Cybersecurity Engineer (Offensive Security) to join our team on a contract basis. In this critical role, you will be at the forefront of our defense, proactively identifying vulnerabilities and stress-testing our digital infrastructure against sophisticated threats.
You will lead offensive security engagements, working alongside a world-class team of technologists to safeguard national financial assets. This is an opportunity to leverage your deep technical expertise to simulate real-world attack vectors, mitigate systemic risks, and drive improvements in our enterprise security posture. If you are passionate about ethical hacking, Red Teaming, and advanced threat modeling, we invite you to help us fortify the future of finance.
Tanggung Jawab
- Lead and execute comprehensive penetration testing and Red Team engagements across complex network environments.
- Develop and implement advanced custom scripts and tools to automate security assessments and identify novel attack vectors.
- Conduct deep-dive vulnerability research on enterprise applications, cloud infrastructure, and proprietary financial systems.
- Collaborate with internal stakeholders to translate findings into actionable remediation plans and security hardening strategies.
- Perform threat hunting and simulation exercises to test the efficacy of existing detection and response capabilities.
- Develop detailed technical reports and high-level summaries for executive leadership regarding identified risks.
- Stay ahead of the evolving cyber threat landscape through continuous research on emerging exploits and TTPs (Tactics, Techniques, and Procedures).
Kualifikasi
- Bachelor’s degree in Computer Science, Information Security, or a related technical discipline.
- 5+ years of professional experience in offensive security, penetration testing, or vulnerability assessment.
- Proven track record of successfully identifying and exploiting vulnerabilities in high-security environments.
- Expert-level proficiency in scripting and automation (Python, Go, or PowerShell) and security tooling (Burp Suite, Metasploit, Cobalt Strike).
- Deep understanding of web application security, cloud security (AWS/Azure/GCP), and network protocols.
- Industry-recognized certifications such as OSCP, OSEP, CISSP, or CREST are highly preferred.
- Excellent communication skills with the ability to articulate complex security risks to non-technical stakeholders.