External Penetration Testing

28 minutes ago


Singapur, Singapore PowerToFly Full time

This is a senior level professional position responsible for serving as a liaison between Citi Stakeholders and External Penetration Testing vendors to address testing challenges, drive vulnerability discussions with Citi Stakeholders, drive operational health of the penetration testing vendors along with their adherence to Citi procedures, analyze vulnerability trends to better improve the root cause model of existing testing mechanisms and maintain the overall security hygiene for the organization. This role will also require the candidate to manage the end-to-end Vulnerability Disclosure Process for Citi that would involve onboarding applications with vendors, triaging and driving lessons learned as part of the public disclosure and Private Bug Bounty program. The overall objective of this role is to ensure the execution of Information Security directives and activities is in alignment with Citi's data security policy. Responsibilities: Be the central liaison between Citi stakeholders and the external penetration testing vendor, acting as a collaborator to ensure smooth execution of the end-to-end engagement. Manage the end-to-end process of Vulnerability Disclosure activities that involves onboarding applications, triaging, retesting and identifying lessons learned from the vulnerabilities reported through this channel. Knowledge of OWASP Top 10 and SANS top 25 Perform Yearly Quality Checks on the vendors to ensure adherence to technical and process quality. Act as an application security subject matter expert to assist both Citi stakeholders and third-party vendors during vulnerability risk discussions. Focus and drive quality as it relates to the information submitted by the businesses who are requesting Penetration testing services and ensuring that the provided information is accurate and complete. Focus on maintaining a high level of operational oversight with all vendors and ongoing penetration testing activities in order to ensure that engagements are progressing forward with the right level of attention. Have strong communication skills in order to effectively communicate expectations and resolve challenges. Have strong technical writing and presentation skills to articulate the penetration testing process end-to-end to any audience. Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation. Reduce risk by analyzing the root cause of issues, their impact, and required corrective actions to existing processes. Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citibank, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency. Qualifications: Minimum of 5 years of relevant experience in Information Security and/or relevant Technology role. Advanced proficiency with Microsoft Office tools and software Consistently demonstrates clear and concise written and verbal communication Proven influencing and relationship management skills Proven analytical skills Plus: Familiarity or hands-on experience in application security testing Basic understanding of Web/ Mobile / API security and relevant testing tools Relevant Certifications is a plus not a requirement: GPEN, GWAPT, GMOB, GWEB Education: Bachelor’s degree/University degree or equivalent experience Master’s degree preferred This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required. #LI-Hybrid Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi. View Citi’s EEO Policy Statement and the Know Your Rights poster. #J-18808-Ljbffr



  • Singapur, Singapore Citigroup Inc. Full time

    This is a senior level professional position responsible for serving as a liaison between Citi Stakeholders and External Penetration Testing vendors to address testing challenges, drive vulnerability discussions with Citi Stakeholders, drive operational health of the penetration testing vendors along with their adherence to Citi procedures, analyze...


  • Singapur, Singapore Centre for Strategic Infocomm Technologies Full time

    What you will be working on: Conduct Vulnerability Assessment and Penetration testing (VAPT) and red teaming against a variety of networks and systems. Develop advance penetration techniques that simulate Advanced Persistent Threats (APT) activities. Develop tools and processes to support VAPT and red teaming to improve its efficiency and effectiveness....


  • Singapur, Singapore Deloitte PLT Full time

    A global consulting firm is seeking a Manager for Cyber Defence & Resilience in Singapore. The role involves conducting security assessments, managing penetration testing activities, and leading initiatives to enhance cyber security. Candidates should possess a Bachelor's degree and have 7-10 years of IT experience, particularly in penetration testing....

  • VP, External Pen Testing

    28 minutes ago


    Singapur, Singapore Citigroup Inc. Full time

    A global financial services company in Singapore is seeking a senior-level professional to act as a liaison between stakeholders and external penetration testing vendors. The role focuses on managing the Vulnerability Disclosure Process, ensuring adherence to security policies, and driving discussions related to vulnerabilities and information security....


  • Singapur, Singapore Centre for Strategic Infocomm Technologies Full time

    Job Scope Leverage advance techniques to pentest well secured networks/devices (e.g., restricted/closed networks) Develop advance penetration techniques that overcome cyber defence mechanisms Identify key technology trends and lead technical initiatives to advance penetration capabilities Requirements Degree in Infocomm Security, Computer Science,...


  • Singapur, Singapore Wizlynx Group Full time

    A leading Cyber Security firm in Singapore is searching for a Cyber Security Manager & Consultant. This role involves overseeing a team of experts and executing penetration tests across various platforms, including networks and applications. Candidates should possess at least three years of experience in Cyber Security, with strong management skills and...


  • Singapur, Singapore Connect Energy Full time

    A leading cybersecurity firm in Singapore is seeking a professional to lead and mentor junior Penetration Testers. The role involves performing hands-on vulnerability assessments and penetration testing across various platforms, including web applications, networks, and more. Candidates should have extensive experience in web and network vulnerability...

  • Penetration Testing

    3 weeks ago


    Singapur, Singapore WIZLYNX PTE. LTD. Full time

    A renowned cyber security provider in Singapore is seeking a Cyber Security Consultant to conduct advanced penetration testing across multiple platforms. The consultant will collaborate with a dynamic team, maintain up-to-date knowledge of security trends, and assist clients in securing their systems. Ideal candidates have a bachelor’s degree, at least two...

  • VP, External Pen Testing

    28 minutes ago


    Singapur, Singapore PowerToFly Full time

    A leading financial institution in Singapore seeks a Senior Information Security Specialist to manage vendor relationships and oversee vulnerability disclosures. The ideal candidate will demonstrate at least 5 years of experience in Information Security, possess strong communication and analytical skills, and be proficient in Microsoft Office tools. This...


  • Singapur, Singapore ExpressVPN Full time

    Overview Join to apply for the Senior Penetration Tester role at ExpressVPN . If you’re passionate about security and privacy, and want to use your offensive security skills to help safeguard private, uncensored access to the internet for millions of customers, we’d love to speak with you. What You’ll Do Prepare and execute penetration testing projects...