Cybersecurity Testing Engineer
Summary
Conducts security testing, manages a bug bounty program, and validates vulnerabilities for a cybersecurity authority using tools like Kali Linux and Burp Suite.
About this role
As part LISA capability of early detection, the security testing engineer shall assist with regular security testing on the Authority digital assets as well as validating security vulnerabilities reported via various sources to the Authority. They simulate cyber-attacks, conduct security assessments, and identify vulnerabilities that could be exploited. They are also responsible for the maintenance of the Authority's Bug Bounty Programme, Attack Surface Management and any other existing security testing tools and services. The role involves providing recommendations for fixing identified issues to ensure security measures work as intended.
Core Responsibilities
- Manage Client's Private Bug Bounty Programme by overseeing the triaging processes and coordination with various project teams;
- Assists with security testing efforts;
- Responsible for the management and tracking of the VAPT scanning and remediation status;
- Responsible for the configuration, tuning, patching, upgrades or maintenance of security testing tools, platforms and services;
Core Requirements
- A minimum of TWO (2) years' experience in cybersecurity testing, penetration testing, vulnerability assessment, or related cybersecurity disciplines;
- Hands-on experience with security testing tools such as Kali Linux, Metasploit, Burp Suite, OWASP ZAP, Nessus, or equivalent security testing platforms;
- Demonstrated experience in conducting security assessments for web applications, network infrastructure, mobile applications, or cloud environments;
- Strong analytical skills, excellent communication abilities, and advanced problem-solving capabilities in cybersecuritytesting environments; and
- Certification such as CISSP, CEH, OSCP, GSEC, or equivalent cybersecurity credential is preferred.