Offensive Security Engineer, Senior

5 days ago


Singapore Affinidi Full time

**Affinidi **is a technology company dedicated to changing data ownership for good. We empower businesses and individuals with control and ownership of their data, with a comprehensive approach to managing their holistic identity - accounting for all aspects of their digital footprint while ensuring privacy and security.

Affinidi's technology enables users to benefit from decentralised digital identity solutions. We believe that everyone has the right to own and control their data, and we are committed to creating a trusted digital credentials ecosystem that empowers businesses and individuals to securely exchange data and services across borders and industries.

**Equal Opportunity**

We believe in hiring different and diverse talent and providing a safe space where everyone can share their views without fear, where differences are celebrated, and where no one is left out. Inclusive cultures are the foundation for collaboration and innovation within our team.

We are seeking a highly skilled and experienced **Senior Offensive Security Engineer** to join our Security team.

In this vital role, you'll support Affinidi implementing a shift-left security approach, conducting web apps, mobile apps, API's, microservices and infrastructure penetration tests, defining secure development standards, engaging in security research, threat modelling, and offering expert code review to identify vulnerabilities. This position is based in Singapore, and reports to the Security Lead.

Our **work culture** at Affinidi is shaped by the following tenets:

- _We are unapologetically customer-focused_
- _We invest in cultures and teams to enable high performance_
- _We embrace experimentation and build fast_
- _We have the courage to be misunderstood_
- _We work together to unlock data_

**What's in it for you**:

- Implementing a shift-left approach to security and performing penetration tests on Web apps, Mobile apps, APIs, and Infrastructure.
- Establishing secure development standards and providing security advisory to development teams.
- Conducting security research and penetration testing across various products.
- Full-stack (Infra & Product security) grey and white box penetration testing.
- Creating and Implementing Threat Modelling.
- Utilizing code review skills to identify complex vulnerabilities within code.
- Offering security guidance to engineering and operational teams.
- Developing security tools for threat detection and prevention.
- Collaborating with other security teams to share insights and knowledge.

**You'll Be a Great Match If**:

- You have experience in infrastructure vulnerability assessments and remediation.
- You have expertise in web-based vulnerability assessments (Pentest) and remediation.
- You're skilled in secure coding practices and automating security checks in pipelines.
- Strong IaaS security skills are part of your expertise.
- You enjoy cross-team collaboration to achieve goals.
- You are actively involved in contributing to the community, be it through code, meetups, conferences, or mentorship.

**Bonus Points**:

- Share a GitHub repo with security tools/scripts you've developed or help maintain.
- Possess web development experience, participate in bug bounty programs, or engage in open-source vulnerability research.

**What can you expect from us**:

- Hybrid working model
- Flexible working hours
- Unlimited vacation policy
- Competitive compensation package
- Work within international environment
- Learning Budget
- Mobile Allowance
- Home Office Allowance
- Urban Sport Membership

LI-AB1



  • Singapore Traveloka Full time

    Overview It\'s fun to work in a company where people truly BELIEVE in what they\'re doing! Securing an organization and its information systems requires a holistic approach that includes continuous security verification, extending beyond standard testing and assessment methods. By assuming the role of a threat actor, the Offensive Security Team delivers...


  • Singapore Shopee Full time

    Offensive Security Engineer (Red Team) - Information Security Join to apply for the Offensive Security Engineer (Red Team) - Information Security role at Shopee . Job Responsibilities Design and perform APT adversary emulation to assess infrastructure, systems, and applications against confidentiality, integrity, authentication, availability, authorization,...


  • Central Singapore PayPal Full time

    **The Company** PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy. We operate a global, two-sided network at...


  • Singapore JPMorganChase Full time

    Lead Cybersecurity Architect, Offensive/Defensive Security Join to apply for the Lead Cybersecurity Architect, Offensive/Defensive Security role at JPMorganChase Lead Cybersecurity Architect, Offensive/Defensive Security 1 day ago Be among the first 25 applicants Join to apply for the Lead Cybersecurity Architect, Offensive/Defensive Security role at...


  • Singapore Assurity Trusted Solutions Pte Ltd Full time

    Senior / Lead Offensive Cybersecurity Engineer (VAPT)Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and...


  • Singapore Assurity Trusted Solutions Full time

    Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a...


  • Singapore watchTowr Full time

    Overview watchTowr is the Preemptive Exposure Management capability trusted by Fortune 500 companies and critical infrastructure providers. By combining proactive threat intelligence, real attacker telemetry, and automated red teaming, watchTowr continuously identifies and validates real exposure - so security teams can outrun real-world threats. When...


  • Singapore watchTowr Full time

    Overview watchTowr is the Preemptive Exposure Management capability trusted by Fortune 500 companies and critical infrastructure providers. By combining proactive threat intelligence, real attacker telemetry, and automated red teaming, watchTowr continuously identifies and validates real exposure - so security teams can outrun real-world threats. When...


  • Singapore SEKURO OPERATIONS PTE. LTD. Full time $120,000 - $200,000 per year

    Head of OffsecSekuro is a trusted provider of information security consulting services. We are currently recruiting a smart, experienced and motivated security professional to join manage our Technical Assurance OFFSEC team and engagements in Asia. The role involves working with mid-market to enterprise level clients. The successful candidate will have a lot...


  • Singapore Shopee Full time

    Department Engineering and Technology - LevelExperienced (Individual Contributor) - LocationSingapore The Engineering and Technology team is at the core of the Shopee platform development. The team is made up of a group of passionate engineers from all over the world, striving to build the best systems with the most suitable technologies. Our engineers do...