Skip to content
Applying is always free. We will NEVER ask for your Singpass password or bank log-in. ScamShield 1799 (opens in new tab)
Applying on WorkJio is always free. WorkJio and its verified employers will NEVER ask job seekers to pay, transfer money, or disclose bank log-in or Singpass passwords. Call the 24/7 ScamShield ↗ (opens in new tab) Helpline at 1799 if you are unsure whether something is a scam.
A Singapore job board for part-time, gig and full-time work, from verified employers and companies’ own careers pages. Every listing is scam-checked, and applications made on WorkJio get a status update.
Full-time Tech & engineering · Posted 24 Sept
Consultant, Red Teaming E Ensign InfoSecurity From company site
Salary
Not stated by the company
Start Not stated
Work mode On-site
Experience Some experience About the role This role sits with Ensign's offensive security team in Singapore, planning and running authorised Red Team and Purple Team engagements for clients. You'll simulate realistic adversaries, test controls across many environments, and work closely with defensive teams to strengthen detection and response. It suits an experienced offensive security practitioner who can also explain technical findings to senior stakeholders.
What you'll do Plan and carry out authorised Red Team engagements, adversarial simulations and objective-based security assessments Turn relevant threats and customer risks into realistic attack scenarios Perform reconnaissance, initial-access testing, social engineering, privilege escalation, lateral movement, persistence and data-access simulations where authorised Know someone for this? Share it
Consultant, Red Teaming job at Ensign InfoSecurity, Singapore | WorkJio
Assess security controls across networks, endpoints, applications, cloud platforms, identity systems and operational processes
Identify and demonstrate attack paths that could expose critical systems or business assets
Develop or adapt tools, scripts, payloads and supporting infrastructure to meet engagement objectives
Maintain operational security and reduce the risk of unintended disruption during engagements
Collaborate with Blue Teams, Security Operations Centres, incident response teams and other defensive stakeholders
Design and run controlled attack scenarios to validate preventive, detective and responsive security controls
Map simulated adversary behaviours to frameworks such as MITRE ATT&CK
Evaluate security alerts, telemetry, logging coverage, investigation workflows and response procedures
Help defensive teams develop and refine detection rules, use cases, playbooks and response processes
Facilitate knowledge-sharing sessions on attacker techniques to strengthen defensive capabilities
Conduct validation and retesting to confirm identified security gaps have been addressed
Document improvements and remaining areas of security exposure
Define engagement objectives, scope, assumptions, success criteria and rules of engagement with stakeholders
Ensure all activities stay within approved legal, ethical, safety and customer-defined boundaries
Follow applicable change-control, data-handling, access-control and escalation procedures
Keep accurate records of actions, evidence, findings and attack paths
Communicate critical findings, operational concerns and potential business risks promptly
Coordinate with project managers, internal teams and customer stakeholders throughout the engagement lifecycle
Produce clear technical reports, executive summaries, attack narratives and prioritised remediation recommendations
Explain technical findings in terms of operational and business impact
Present engagement outcomes to technical teams, senior management and executive stakeholders
Deliver engagement debriefs and remediation workshops where required
Support remediation planning, validation and retesting
Contribute to Requirements Offensive Security Certified Professional (OSCP) certification is required Advanced or specialist certifications such as OSEP, OSED, OSWE, CRTO, CRTE, CREST CRT/CCT, GPEN or GXPN are advantageous Demonstrated experience in Red Teaming, Purple Teaming, adversarial simulation, penetration testing or a related offensive security role Strong knowledge of adversary tactics, techniques and procedures, including MITRE ATT&CK Hands-on experience with network, Active Directory, Windows, Linux, web application, cloud and identity-based attack techniques Experience collaborating with defensive security teams to validate and improve security controls Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.
Open application Listed from Ensign InfoSecurity’s own careers page and not yet verified by WorkJio. You apply on the company’s site. See all their roles .
Is this your company? Roles that show a salary rank higher on WorkJio. Claim or remove this listing
Listing ID 4483 · Report this listing