Principal Vulnerability Researcher
3 days ago
**Hello, let us introduce ourselves**
We are watchTowr, a VC-backed cyber-security start-up headquartered in Singapore. Cyber security veterans and technical experts, we are obsessed with continuously finding ways to break into enterprises, while building technology for some of the world’s most targeted organisations.
With experience informed by years of simulating attacks by ransomware gangs and APT groups against some of the world's largest organisations, our mission is to be every organisation’s persistent adversary - with cutting-edge technology.
As a team, we’re leveraging data to build the future of Attack Surface Management and Continuous Automated Red Teaming technology. We’ve seen the limitations of the status-quo - consultancy. Our mission is to enable organisations to rapidly react to new threats and ultimately answer that one elusive question - “how could my organisation be compromised today?”.
We are a young, high-energy and high-performing team that is devoted to building world-class technology in pursuit of realising our mission. We are in a high and aggressive growth phase of our journey and are excited to continue adding colleagues to join our phorce of nature.
Our vision for offensive security is continuous.
**But what’s the role?**
We are looking for a veteran Vulnerability Researcher to join the watchTowr Labs team, in our bid to help secure attack surfaces at scale.
watchTowr Labs is our epicentre of offensive security expertise, and has been designed to operate like an APT group.
This is a pure research role, with an equal focus split on analysing N-day vulnerabilities to build reliable detections/exploits, and 0-day research - looking at critical technology that we see across vast attack surfaces (whether it be cloud solutions, appliances, etc).
If something is exposed to the Internet - whether it’s SaaS, cloud, shadow IT, or the random marketing website everyone forgot about presents a weakness to their organisation - it’s our job to discover, highlight, and hack it.
This is the opportunity to work with a highly capable, veteran team - while having significant flexibility to have an impact on the security posture of the organisations we work with.
**Sounds great - what will I do?**
- You will spend your days hacking - or, professionally put, “looking for vulnerabilities in critical software”. Pure research.
- You will be focused on analysing and hunting for vulnerabilities that **matter** - truly exploitable weaknesses that would have a material impact on our clients. We don’t care about weak SSL ciphers and unexploitable “the stars must align” weaknesses - we care about mass Remote Code Execution.
- You’ll work with other offensive security experts to share ideas and brainstorm new tactics and techniques that we can use to demonstrate high-impact weaknesses in organisations.
- You’ll perform cutting-edge offensive security research to build and test your tactics and techniques. Our research has one goal - to strengthen external attack surfaces.
- Use our technology to deploy tactics and techniques at scale against all of our clients - our message is very clear, never do anything twice. Let our technology provide the harness and continuous framework you need.
- We’d encourage you and expect you to be submitting your work to conferences around the world - we will support you to make it happen
**Sounds perfect to me, what specifics are you looking for?**
**Ideal Experience**
- 5 or more years of professional, or passion-driven extracurricular, experience focused on vulnerability research and exploit development
- Comfortable with a broad spectrum of weaknesses - ranging from abusive logic-based vulnerabilities, to esoteric low-level, memory corruption vulnerabilities.
- A demonstrable history of analysing or disclosing impactful, complex vulnerabilities - via advisories, blog posts and conference presentations - in enterprise-grade software.
- Driven by your own passion and initiative - you understand the mission, and don’t need someone to guide you.
- You can comfortably turn your highly-technical analysis and exploitation process into internal documentation, and occasionally tailored to an external audience.
**Our Experience**
When you join us, you can expect (ok, we kinda expect this from you too):
- A highly motivated, experienced, offensive cyber team that obsesses over our shared mission.
- To be part of a team of outcome-focused problem-solvers.
- An environment of autonomy and creativity to support you to deliver the best work of your life.
- A culture of continuous improvement in the form of learning and growth.
**What’s in it for me?**
- **Competitive compensation -** we believe that hard work, skills and ambition should be fairly compensated.
- **Meaningful role in a company** - You will be a key and early contributor to a fast-growing cyber security business that helps protect some of the world's largest enterprises.
-
Vulnerability Researcher
1 week ago
Singapore InnoEdge Labs Pte. Ltd. Full time $120,000 - $180,000 per yearAt InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver cutting-edge solutions and...
-
MacOS Vulnerability Researcher
3 days ago
Singapore Redherd Full time $120,000 - $180,000 per yearLocation: Remote (Open globally)Engagement: [Permanent / Long-term Contract]Start: ASAPCompensation: Competitive, based on experienceRecruiting on behalf of a confidential clientOverviewWe're recruiting on behalf of a confidential client for an experienced macOS Vulnerability Researcher. This role focuses on low-level system internals and kernel exploitation...
-
Cyber Vulnerability Researcher
3 days ago
Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time**Responsibilities**: - Develop and enhance processes and tools for the discovery and triage of vulnerabilities - Research into new vulnerability discovery techniques and processes **Requirements**: - Bachelor's degree in a computer science or engineering field or equivalent a minimum of 3 years of relevant experience - Up-to-date knowledge on modern...
-
Cyber Vulnerability Researcher
2 weeks ago
Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time**Duties and Responsibilities** - Develop and enhance processes and tools for the discovery and triage of vulnerabilities. - Research into new vulnerability discovery techniques and processes. **Requirements**: - Bachelor's degree in a computer science or engineering field or equivalent a minimum of 3 years of relevant experience. - Up-to-date knowledge on...
-
Singapore SEARCH STAFFING SERVICES PTE. LTD. Full timeWe are currently working with a German MNC client; looking for a Vulnerability Researcher with cybersecurity work experience to join them. **Vulnerability Researcher **Responsibilities**: - Identify and analyze security weaknesses and flaws in software, hardware, or systems - Analyzing code, protocols, and configurations for security issues - Penetration...
-
Cyber Security Vulnerability Researcher
3 days ago
Singapore Centre for Strategic Infocomm Technologies Full time $80,000 - $120,000 per yearWe are looking for passionate individuals to be part of our vulnerability research team dedicated to keeping our Windows platform and software safe. In this role, you will be part of a team of vulnerability researchers responsible for working closely with stakeholders to perform security audit on Windows operating systems and relevant software. The audit...
-
Cyber Security Vulnerability Researcher
2 weeks ago
Singapore Centre for Strategic Infocomm Technologies (CSIT) Full timeCyber Security Vulnerability Researcher (Windows)Join to apply for the Cyber Security Vulnerability Researcher (Windows)role at Centre for Strategic Infocomm Technologies (CSIT)We are looking for passionate individuals to be part of our vulnerability research team dedicated to keeping our Windows platform and software safe. In this role, you will be part of...
-
Web Application Vulnerability Researcher
5 days ago
Singapore InnoEdge Labs Pte. Ltd. Full timeAt InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver cutting-edge solutions and...
-
Cyber Security Vulnerability Researcher
4 days ago
Singapore Centre for Strategic Infocomm Technologies Full timeWe are looking for passionate individuals to be part of our vulnerability research team dedicated to keeping our Windows platform and software safe. In this role, you will be part of a team of vulnerability researchers responsible for working closely with stakeholders to perform security audit on Windows operating systems and relevant software. The audit...
-
Cyber Security Vulnerability Researcher
3 days ago
Singapore Centre for Strategic Infocomm Technologies Full time $80,000 - $120,000 per yearJob ScopeInvestigate vulnerabilities/threats and assess the impact on mobile devices and appsConduct research to gain in-depth understanding of Android and iOS architecture (kernel and subsystems) and how these subsystems could be exploited by malwarePerform information security assessments through vulnerability research, code audit, black box testing,...