Web Application Vulnerability Researcher

6 months ago


Singapur, Singapore InnoEdge Labs Pte. Ltd. Full time

At InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver cutting-edge solutions and services.

InnoEdge believes in fostering a culture where team members are encouraged to overcome challenges, explore new ideas, and work together to succeed. We value individuals who are determined to push beyond the boundaries, and have a thirst for knowledge, continuous learning, and self-improvement.

Collaboration is key to our success. We prioritise open communication, constructive feedback, and a willingness to help others. We are committed to creating a supportive work environment that encourages excellence, innovation, and continuous improvement. We're looking for individuals who share our values and are excited to join us on our cyber mission.

Responsibilities
  • Recommend direction for research projects and conceptualize new tools/techniques that will enhance the vulnerability discovery process.
  • Mentor and guide new researchers in the area of web application vulnerability research.
  • Perform deep research into web applications with complex codebases to understand the attack surface for an attacker to abuse.
  • Ideate hypothesis as to how an attacker could possibly abuse features in the application and validate if hypothesis holds true.
  • Develop proof of concept to demonstrate the severity of the discovered vulnerability and propose mitigations.
  • Develop cutting edge tools to improve and scale up the vulnerability discovery process for web applications.
  • Keep abreast of the latest research into web security and vulnerabilities detection techniques.
  • Level up the local security community through mentorship of aspiring security researcher, publishing blog post and speaking at conferences.

Requirements

  • Demonstrated ability to
    • Perform attack surface analysis and prioritization of research on a web application.
    • Independently apply static/dynamic analysis techniques to find low lying bugs in a web application.
    • Discover and exploit vulnerability in web applications.
  • Deep understanding of web programming languages (PHP, Java, Python, .Net…), web frameworks, typical web vulnerabilities and how they are commonly exploited.
  • Track record of having found vulnerabilities in the last 4 years.


For a more senior role, we're looking for candidates with:

  • Fluency in assembly language (x86/64)
  • Experience in debugging, reverse engineering binary and exploiting memory corruption and logic vulnerabilities.
  • Track records in these areas:
    • Consistency in discovering security-related vulnerabilities and demonstrating their impact.
    • Performing research on a complex web application by a major vendor (e.g. WordPress), applying attack surface analysis and prioritization, and performing various static and dynamic analysis techniques to find bugs in the different components.
    • Discovering and exploiting security vulnerabilities in in a complex application by a major vendor (e.g. Exchange, WordPress).

Benefits

  • Training & Development
  • Performance Bonus
  • Medical Benefits
  • Hybrid Work Arrangement


If you meet these qualifications and are passionate about cyber security, we encourage you to apply for this exciting opportunity. We offer competitive compensation, a comprehensive benefits package, and a collaborative and dynamic work environment.



  • Singapur, Singapore Ensign InfoSecurity Full time

    Ensign is hiring !Responsibilities:Perform research to discover vulnerabilities in operating systems, software applications and hardware devices through code audit, black box testing and reverse engineeringDevelop and enhance processes and tools for the discovery and triage of vulnerabilitiesResearch into new vulnerability discovery techniques and...


  • Singapur, Singapore InnoEdge Labs Pte. Ltd. Full time

    At InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver cutting-edge solutions and...


  • Singapur, Singapore TikTok Full time

    Team Introduction The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer...


  • Singapur, Singapore InnoEdge Labs Pte. Ltd. Full time

    At InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver cutting-edge solutions and...

  • Web Application

    7 months ago


    Singapur, Singapore Talenthrive Full time

    Job title : Web Application DeveloperOverview:We are looking for a highly motivated and experienced web application developer to join our amazing team. Choose us for an amazing opportunity to develop your career with us.Responsibilities:Analyze business requirements and develop custom software and scripts using .Net Framework, ASP Framework, Microsoft Visual...

  • Security Research Lead

    5 months ago


    Singapur, Singapore TikTok Full time

    Team Introduction The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer...


  • Singapur, Singapore Nanyang Technological University Full time

    NTU is a world-class research-intensive university located in Singapore, consistently ranked among the top universities in Asia and the world. We are home to over 33,000 students and 10,000 staff, offering a vibrant and dynamic work environment for individuals seeking to advance their careers.We are seeking an experienced and motivated Specialist, IT...


  • Singapur, Singapore TikTok Full time

    Team Introduction The Global Security Organization provides industry-leading cybersecurity and business protection services to TikTok globally. Our organization employs four principles that guide our strategic and tactical operations. Firstly, we champion Transparency & Trust by leading the charge in organizational transparency, prioritizing customer...


  • Singapur, Singapore StarHub Full time

    Job Description The role is responsible to design, develop and implement secured application architecture. As an Application Security Manager, you will be responsible for ensuring the security of our applications throughout their lifecycle. You will work closely with development teams, architects, and other stakeholders to implement robust security...


  • Singapur, Singapore 11112 Citibank, N.A. Singapore Full time

    Whether you’re an application developer looking to make the switch into the challenging, yet rewarding, world of information security, or you’re a rock star white-hat hacker, Citi is the place for you. Our team of world class, talented individuals, who are passionate about security, put their skills to the test every day on a global scale. At Citi...


  • Singapur, Singapore InnoEdge Labs Pte. Ltd. Full time

    At InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver cutting-edge solutions and...


  • Singapur, Singapore Fortinet Full time

    Location: Malaysia (Kuala Lumpur), Hong Kong, Korea (Seoul), Philippines (Manila), SingaporeRole Overview:As a member of the International Sales Department, you will work closely with the Sales Team to position our Portfolio of Solutions, educate and drive field Systems Engineers in their projects and report product evolution requests to Product Management....

  • Systems Analyst

    7 months ago


    Singapur, Singapore TransitLink Full time

    Responsibilities:Design, maintain and enhance existing and new software systems to support business requirementsLiaising with end-users, stakeholders to define user requirement and design specificationsExploring and enhancing application in new and emerging technologiesConducting system testing to ensure applications conform to user requirementsReviewing...

  • Research Assistant

    8 months ago


    Singapur, Singapore Singapore Institute of Technology Full time

    Key Responsibilities Participate in and manage the research project with Principal Investigator (PI), Co-PI and the research team members to ensure all project deliverables are met. Undertake these responsibilities in the project: Management of Student Assistants and workplacesCoordinate with industrial partnersManage project schedule, equipment,...


  • Singapur, Singapore Xcellink Pte Ltd Full time

    The Service Delivery Manager is responsible for overseeing the end-to-end management of security vulnerability remediation processes. This role requires a deep understanding of security best practices, risk management, and IT service delivery. The successful candidate will collaborate with cross-functional teams to identify, prioritise, and mitigate security...

  • Analyst III

    7 months ago


    Singapur, Singapore Marina Bay Sands Full time

    Summary of the role The Application Security Engineer is an expert level application testing and threat response specialist within Marina Bay Sands’ Cyber Security Branch. The Application Security Engineer assesses the application security posture of Marina Bay Sands’ applications, designs & tunes application security tools and investigates...

  • Web Developer

    7 months ago


    Singapur, Singapore Helius Full time

    Job Description: - Coordinate with the web development team to maintain and improve the site in collaboration with product managers and designers. - Develop and manage well-functioning databases and applications. - Write well-designed, testable, efficient, clean code on the front-end and back-end. - Participate in the design and creation of new...

  • DevSecOps Engineer

    2 months ago


    Singapur, Singapore Sopra Steria I2S Full time

    Company:Sopra Steria is a listed European tech leader specializes in Consulting, Digital Service, and Software. We have 60,000 employees worldwide located in different regions (Europe, North America and Asia), whereby Singapore is the HQ for APAC. EvaGroup Asia Pacific is part of Sopra Steria I2S APAC, in charge of Infrastructure, Cloud and Cybersecurity...


  • Singapur, Singapore Ensign InfoSecurity Full time

    Ensign is hiring !Duties and Responsibilities:Research and Development – Stay current with the latest cybersecurity threats, vulnerabilities, and tools. Contribute to the development and automation of security assessment processes, red team exercises, and the creation of new methodologies or tools.Vulnerability Assessment – Learn and collaborate with the...

  • App Developer

    6 months ago


    Singapur, Singapore Marina Bay Sands Full time

    At Marina Bay Sands, the primary responsibility of the Senior Developer will be to execute all Development related activities for local MBS IT Projects whilst aligning to standards & best practices followed within the organization. JOB SCOPE Execute application development deliverables and activities Participate in various phases of the Software...