AVP - Senior Penetration Tester (Hybrid)

2 months ago


Singapore Citi Full time
About the job

If you are passionate and curious about security, and want to use your offensive security skills to help keep our firm's application and infrastructure safe, we want to speak with you.

Who You Are

You are talented in solving problems and identifying security weaknesses, and you have experience collaborating with engineers who remediate the vulnerabilities you identified. You adapt well to changes, and speak up to ask questions to clarify when things don't look right.

As someone with an offensive security mindset, you work closely with others to listen to ideas and share suggestions to collectively devise the best approach to remediate vulnerabilities,

continuously learn and enhance skillsets, techniques and methods.

You should have a bachelor's degree with minimally 5 years of relevant experience. Have a good understanding of industry frameworks and methodologies such as OWASP, OSSTMM, PTES, MITRE ATT&CK, threat modeling, etc. Be certified, or intend to be certified, in accredited security certifications such as OSCP, OSWE, GXPN, GCPN, CISSP, etc.

What You'll Do

As an individual contributor on our penetration testing team, you are responsible for:
  • Preparing and executing penetration testing assignments on our infrastructure assets and applications
  • Working closely with the engineering teams to provide expert guidance and advice on remediation of identified vulnerabilities
  • Verifying newly discovered vulnerabilities in the environment
  • Reporting security vulnerabilities to businesses, clearly articulating security issues to technical and non-technical stakeholders
  • Guide and support other team members using your strong technical knowledge
  • Identify inefficiencies in the team's workflow, suggest solutions and drive outcomes
This role focuses strongly on your ability to perform manual penetration testing on infrastructure related systems and devices. To be a good fit for this role, you should be able to identify security weaknesses and vulnerabilities in various platforms, and efficiently deliver security assessment assignments.

What You'll Bring

Identify vulnerabilities and zero-day exploits though various means of analysis using:
  • Vulnerability assessment tools such as Nessus, Qualys, Kali Linux, AppScan, Burp Suite, etc.
  • Familiar with scripting languages such as Python
  • Good knowledge of:
    • TCP/IP, IDS/IPS, firewalls, AAA systems, SSH, PKI
    • OS Security - Unix, Linux, Windows, Android/IOS
    • Common protocols - LDAP, SMTP, DNS, routing etc.
    • Web application infrastructure - application servers, web servers, databases, cloud services, containers technologies etc.
Provide guidance to other team members and share knowledge and findings with them

How You'll Succeed

Be consistent and conscientious in identifying security vulnerabilities and working with the respective engineering teams and stakeholders to provide sound guidance and remediations. Be a team player, and a keen learner.

#LI-Hybrid
------------------------------------------------------

Job Family Group:
Technology
------------------------------------------------------

Job Family:
Information Security
------------------------------------------------------

Time Type:
Full time
------------------------------------------------------

Citi is an equal opportunity and affirmative action employer.

Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Citigroup Inc. and its subsidiaries ("Citi) invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi .

View the " EEO is the Law " poster. View the EEO is the Law Supplement .

View the EEO Policy Statement .

View the Pay Transparency Posting


  • Singapore Citi Full time

    Whether you're at the start of your career or looking to discover your next adventure, your story begins here. At Citi, you'll have the opportunity to expand your skills and make a difference at one of the world's most global banks. We're fully committed to supporting your growth and development from the start with extensive on-the-job training and exposure...


  • Singapore Citi Full time

    About the RoleWe are seeking a highly skilled and experienced Penetration Tester (Hybrid) to join our team. As a key member of our cybersecurity team, you will be responsible for identifying and exploiting vulnerabilities in our infrastructure and applications.Key Responsibilities• Prepare and execute penetration testing assignments on our infrastructure...

  • Penetration Tester

    1 month ago


    Singapore Citi Full time

    About the RoleWe are seeking a skilled Penetration Tester to join our team at Citi. As a Penetration Tester, you will be responsible for identifying security weaknesses and vulnerabilities in our infrastructure and applications.Key Responsibilities Prepare and execute penetration testing assignments on our infrastructure assets and applications Work closely...

  • Penetration Tester

    3 weeks ago


    Singapore Citi Full time

    About the RoleWe are seeking an experienced Penetration Tester to join our team at Citi. As a Penetration Tester, you will be responsible for identifying and exploiting security vulnerabilities in our infrastructure and applications.Your primary focus will be on manual penetration testing, using a variety of tools and techniques to identify security...

  • Penetration Tester

    4 weeks ago


    Singapore Citi Full time

    About the job If you are passionate and curious about security and want to use your offensive security skills to help keep our firm's application and infrastructure safe, we want to speak with you. Who You Are You are talented in solving problems and identifying security weaknesses, and you have experience collaborating with engineers who remediate...

  • Senior Consultant

    1 month ago


    Singapore Deloitte SEA Full time

    Are you ready to unleash your potential? At Deloitte, our purpose is to make an impact that matters for our clients, our people, and the communities we serve.   We believe we have a responsibility to be a force for good, and WorldImpact is our portfolio of initiatives focused on making a tangible impact on society’s biggest challenges and...


  • Singapore St Engineering Info-security Pte. Ltd. Full time

    We are seeking an experienced Cloud PenetrationTesterto join our team. The successful candidatewill have expertise in cloud security, penetration testing, andvulnerability assessment. The role involves identifying andexploiting vulnerabilities in cloud-based systems, applications,and infrastructure to help our organization strengthen its...


  • Singapore CHANGTING NETWORK TECHNOLOGY PTE LTD Full time

    About the role Join our team at CHANGTING NETWORK TECHNOLOGY PTE LTD as a Senior Penetration Engineer. In this full-time role based in the East Region, you will be responsible for conducting comprehensive security assessments to identify and mitigate vulnerabilities across our systems and applications. Your expertise will play a crucial role in ensuring the...


  • Singapore CROWE HORWATH FIRST TRUST RISK ADVISORY PTE. LTD. Full time

    Roles & ResponsibilitiesJob Roles and Responsibilities:The Cybersecurity Penetration Tester will be responsible for conducting regular audits on our client’s IT systems, ensuring compliance with all relevant regulations and standards. The ideal candidate will have a strong understanding of IT systems, network security, and audit procedures. Job...


  • Singapore Assurity Trusted Solutions Full time

    Job SummaryWe are seeking a highly skilled Cybersecurity Expert to join our team as a Vulnerability Assessment and Penetration Tester. In this role, you will be responsible for conducting end-to-end vulnerability assessments and penetration testing on a wide range of systems, networks, and applications.Key ResponsibilitiesConduct thorough source code reviews...


  • Singapore Empower Partners Search Full time

    AVP/VP KYC Compliance Empower Partners Search, SingaporeJob Details: Posted 2 days ago | Hybrid Job | Permanent | S$100k - S$120k Our client, a leading private bank, is seeking a qualified professional for an AVP/VP position in their KYC team. This role will be senior and offers the opportunity to contribute to a growing organisation looking to enhance...


  • Singapore Citi Full time

    We are seeking a highly skilled Cybersecurity Specialist to join our team as an Application Penetration Tester in Singapore.About CitiCiti is one of the world's most global banks, with a presence in over 160 countries. As a trusted advisor to our retail, mortgage, small business and wealth management clients, we offer an array of products, services and...


  • Singapore Citi Full time

    Citi is a global bank with a strong commitment to supporting the growth and development of its employees. As a Senior Information Security Specialist - Application Penetration Testing (Hybrid), you will have the opportunity to work with a talented team of cybersecurity experts to identify and mitigate potential security risks in our applications. The ideal...

  • Avp, senior auditor

    6 days ago


    Singapore Citi Full time

    AVP, Senior Auditor (Technology) - Hybrid 5 CHANGI BUSINESS PARK CRESCENT CHANGI BUSINESS PARK SINGAPORE CitiCiti is a leading global bank for institutions with cross-border needs, a global provider in wealth management and a U. S. personal bank.Whether you’re at the start of your career or looking to discover your next adventure, your story begins here....


  • Singapore Citi Full time

    Unlock Your Potential with CitiAt Citi, we're committed to helping you grow and develop your skills in a dynamic and supportive environment. As an AVP Application Penetration Tester, you'll have the opportunity to work with our team of expert ethical hackers to identify and address vulnerabilities in our applications.Key Responsibilities:Conduct thorough...

  • Avp, senior auditor

    2 weeks ago


    Singapore Citi Full time

    AVP, Senior Auditor (Technology) - Hybrid 5 CHANGI BUSINESS PARK CRESCENT CHANGI BUSINESS PARK SINGAPORE Citi Citi is a leading global bank for institutions with cross-border needs, a global provider in wealth management and a U. S. personal bank. Whether you’re at the start of your career or looking to discover your next adventure, your story begins...


  • Singapore ANRADUS PTE. LTD. Full time

    At ANRADUS PTE. LTD., we are seeking a skilled Cybersecurity Penetration Expert to join our team. Our ideal candidate will have extensive experience in penetration testing and a strong understanding of security trends and technologies.Key Responsibilities:Conduct thorough penetration tests on web and mobile applications, networks, and cloud...

  • Avp, senior auditor

    2 weeks ago


    Singapore Citigroup Full time

    AVP, Senior Auditor (Technology) - Hybrid Whether you're at the start of your career or looking to discover your next adventure, your story begins here. At Citi , you'll have the opportunity to expand your skills and make a difference at one of the world's most global banks. We're fully committed to supporting your growth and development...


  • Singapore Ambition Full time

    Operational Due Diligence AVP Ambition SingaporeApply nowOur client, an established global investment firm, is hiring for an AVP/Senior Associate who will be part of their team conducting Operational Due Diligence for global investment funds. Responsibilities include project management, on-site visits, service provider reviews, documentation, and reporting....


  • Singapore CHANGTING NETWORK TECHNOLOGY PTE. LTD. Full time

    Roles & ResponsibilitiesJob Responsibilities:1. Responsible for conducting security assessments of corporate networks. Responsible for assessing network security through penetration testing under legal authorization, discovering and reporting security vulnerabilities. 2. Research on cutting-edge attack technologies and research and development of security...