{"id":1394050,"url":"https://alion.io/job/itsec-security-consultant-offensive-security","title":"Security Consultant (Offensive Security)","company":{"id":2520594,"name":"ITSEC","domain":"itsec.asia","url":"https://alion.io/company/itsec-asia","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Singapore"],"countries":["SG"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":6500,"max":8500,"currency":"SGD","period":"month","gross":true,"usd_annual":79788},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false}],"status":"live","first_seen_at":"2026-09-28T00:00:00Z","employer_posted_date":null,"last_verified_at":"2026-09-28T00:00:00Z","board_verified":false,"closed_at":null,"days_open":3,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":3},"description":"ITSEC Asia is looking for a Cybersecurity Consultant (Offensive Security) to join our growing team.\nWe are primarily looking for candidates with around 3 years of hands-on penetration-testing\nexperience, although we also welcome applications from strong junior pentesters and early-career\nprofessionals who can demonstrate solid technical foundations, curiosity and a genuine passion for\nethical hacking.\nThis role provides exposure to a wide range of security assessments across enterprise, cloud,\ngovernment and critical environments. We are particularly interested in people who are keen to\nembrace AI, automation and emerging technologies to improve the efficiency, depth and quality of\npenetration testing.\nAbout ITSEC Group\nITSEC Group is a cybersecurity organisation operating across the Asia-Pacific region and beyond,\nwith offices in Singapore, Indonesia, Australia, the UAE and Mauritius.\nWe provide cybersecurity consulting and security services to clients across government, critical\ninfrastructure, financial services, telecommunications, healthcare, technology and other industries.\nJoining ITSEC provides the opportunity to work across diverse technology environments, complex\nsecurity challenges and a broad range of consulting engagements, while developing both your\ntechnical and client-facing capabilities.\nKey Responsibilities\n• Conduct penetration testing and vulnerability assessments across web applications, APIs, mobile\napplications, networks, cloud environments and other technology platforms.\n• Support security assessments involving IT, Operational Technology (OT), Internet of Things (IoT)\nand other specialised environments.\n• Identify, validate and demonstrate security vulnerabilities using appropriate testing methodologies\nand techniques.\n• Assess the technical and business impact of identified vulnerabilities and attack paths.\n• Document testing activities, technical evidence, proof-of-concept results and assessment\nconclusions in a clear and defensible manner.\n• Prepare professional penetration-testing reports covering findings, risk implications, supporting\nevidence and practical remediation recommendations.\n• Present technical findings to clients and explain security risks and remediation approaches to both\ntechnical and non-technical stakeholders.\n• Conduct remediation verification and retesting to confirm that identified vulnerabilities have been\neffectively addressed.\n• Explore and responsibly apply AI-assisted security testing, automation, scripting and emerging\ntechnologies to improve research, reconnaissance, analysis, testing and reporting workflows.\n\n• Continuously develop knowledge of emerging vulnerabilities, attack techniques, security tools,\ntechnologies and industry methodologies.\n• Contribute to the development of the team's testing methodologies, knowledge base, tooling and\ntechnical capabilities.\nWhat We Are Looking For\n• Diploma or degree in Cybersecurity, Information Security, Computer Science, Engineering or a\nrelated discipline.\n• Ideally around 3 years of relevant hands-on penetration-testing or offensive-security experience.\n• Strong junior candidates with less experience are also encouraged to apply if they can demonstrate\ngood practical offensive-security skills and a strong willingness to learn.\n• CREST Registered Tester (CRT), Offensive Security Certified Professional (OSCP) or a comparable\nrecognised offensive-security certification is strongly preferred.\n• Good practical understanding of penetration-testing methodologies, tools and techniques.\n• Hands-on experience in areas such as web application, API, network, Active Directory, mobile or\ncloud penetration testing will be advantageous.\n• Experience or knowledge in OT, ICS, IoT or critical-infrastructure security testing is highly\nadvantageous.\n• Strong analytical, troubleshooting and problem-solving capabilities.\n• Ability to produce clear, accurate and professional technical reports.\n• Good communication skills and the ability to explain technical security issues clearly to clients.\n• Interest in AI, automation, scripting and emerging offensive-security technologies, together with the\nability to learn and adapt quickly.\n• Willingness to take ownership, work collaboratively and continue developing professionally within a\ncybersecurity consulting environment.\nSingapore Government / Classified Project Experience\nSingapore citizens are preferred, particularly candidates who are eligible to support sensitive or\nclassified Singapore Government engagements.\nPrevious experience working on Singapore Government, highly classified, critical-infrastructure or\nother high-security projects is highly advantageous.\nCandidates who are familiar with the security expectations, professional conduct, documentation\ndiscipline and operational constraints associated with sensitive government environments will be\nespecially relevant to this role.\nWhat You Can Expect\nITSEC provides on-the-job training, technical mentorship and exposure to experienced cybersecurity\nprofessionals to help consultants continue developing their capabilities.\nYou will have opportunities to:\n• Work on diverse and technically challenging penetration-testing engagements.\n\n• Develop deeper expertise across traditional IT, cloud, OT and emerging technology environments.\n• Strengthen your consulting, client communication and professional report-writing skills.\n• Learn from experienced offensive-security practitioners.\n• Experiment responsibly with AI-assisted and automated security-testing approaches.\n• Progress technically into specialised offensive-security domains as your experience develops.\nIf you enjoy understanding how systems can be broken, explaining why it matters, and helping\norganisations become more secure, we would be happy to hear from you.\nSkills\nMethodology, Risk Assessment, Cyber Security, Web Application Security Assessment, Validate Test Methods, IT Security Assessments, Penetration Testing, Operating Systems, Cybersecurity, Consulting, Security Consulting, Systems Design, Vulnerability Assessment, Network Security, Security Analysis, It Systems","description_format":"text","description_chars":6113,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Cybersecurity","Information Security","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-09-28T12:03:07Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":41,"reasons":["seen:2","velocity","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":{"stated_usd_annual":79788,"is_top_pay":false},"html_url":"https://alion.io/job/itsec-security-consultant-offensive-security","json_url":"https://alion.io/job/itsec-security-consultant-offensive-security.json","meta":{"generated_at":"2026-10-01T03:30:12Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2981,"day_limit":5000,"remaining_today":2019,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}