Consultant, Red Teaming

Posted 7 Days Ago
Be an Early Applicant
Singapore, SGP
In-Office
Entry level
Information Technology • Security • Cybersecurity
The Role
Plan and conduct authorized red and purple team engagements, adversarial simulations, and penetration tests. Assess networks, endpoints, applications, cloud, identity systems, and security controls; develop attack tools and scenarios; collaborate with defensive teams to validate detection and response capabilities. Produce technical and executive reports, communicate business risks, support remediation and retesting, and contribute to security methodologies and research while maintaining strict legal, ethical, and operational boundaries.
Summary Generated by Built In

Ensign is hiring !

Red Team Engagements

- Plan and conduct authorised Red Team engagements, adversarial simulations, and objective-based security assessments.

- Translate relevant threats and customer risks into realistic attack scenarios.

- Perform reconnaissance, initial-access testing, social engineering, privilege escalation, lateral movement, persistence, and data-access simulations where authorised.

- Assess security controls across networks, endpoints, applications, cloud platforms, identity systems, and operational processes.

- Identify and demonstrate attack paths that could expose critical systems or business assets.

- Develop or adapt tools, scripts, payloads, and supporting infrastructure to achieve engagement objectives.

- Maintain operational security and minimise the risk of unintended disruption throughout each engagement.

Purple Team Engagements

- Collaborate with Blue Teams, Security Operations Centres, incident response teams, and other defensive stakeholders.

- Design and execute controlled attack scenarios to validate preventive, detective, and responsive security controls.

- Map simulated adversary behaviours to recognised frameworks such as MITRE ATT&CK.

- Evaluate security alerts, telemetry, logging coverage, investigation workflows, and response procedures.

- Help defensive teams develop and refine detection rules, use cases, playbooks, and response processes.

- Facilitate knowledge-sharing sessions to explain attacker techniques and strengthen defensive capabilities.

- Conduct validation and retesting to confirm that identified security gaps have been addressed.

- Document improvements and remaining areas of security exposure.

Engagement Planning and Governance

- Define engagement objectives, scope, assumptions, success criteria, and rules of engagement with relevant stakeholders.

- Ensure all activities are conducted within approved legal, ethical, safety, and customer-defined boundaries.

- Follow applicable change-control, data-handling, access-control, and escalation procedures.

- Maintain accurate records of actions, evidence, findings, and attack paths.

- Communicate critical findings, operational concerns, and potential business risks promptly.

- Coordinate with project managers, internal teams, and customer stakeholders throughout the engagement lifecycle.

Reporting and Stakeholder Communication

- Produce clear technical reports, executive summaries, attack narratives, and prioritised remediation recommendations.

- Explain technical findings in terms of their operational and business impact.

- Present engagement outcomes to technical teams, senior management, and executive stakeholders.

- Deliver engagement debriefs and remediation workshops where required.

- Support remediation planning, validation, and retesting.

Capability Development

- Contribute to the improvement of Red Team and Purple Team methodologies, tools, procedures, and knowledge bases.

- Research emerging threats, vulnerabilities, attack techniques, defensive approaches, and security technologies.

- Share technical knowledge, lessons learned, and good practices with team members.

- Support the development of reusable attack scenarios and detection-validation content.

Customer Engagement and Adaptability

- Deliver assignments of varying scope, complexity, and duration based on customer and business needs.

- Work at customer premises when required.

- Adapt to different industries, technologies, operating environments, and levels of security maturity.

- Remain flexible in supporting planned and ad-hoc project requirements.

- Communicate effectively with internal teams and customer stakeholders throughout each assignment.

- Offensive Security Certified Professional (OSCP) is required.

- Advanced or specialist certifications, such as OSEP, OSED, OSWE, CRTO, CRTE, CREST CRT/CCT, GPEN, GXPN, would be advantageous.

- Demonstrated experience in Red Teaming, Purple Teaming, adversarial simulation, penetration testing, or a related offensive security role.

- Strong knowledge of adversary tactics, techniques, and procedures, including the MITRE ATT&CK framework.

- Hands-on experience with network, Active Directory, Windows, Linux, web application, cloud, and identity-based attack techniques.

- Experience collaborating with defensive security teams to validate and improve security controls.

- Understanding of defensive technologies and processes, including SIEM, endpoint detection and response, network monitoring, security logging, threat hunting, and incident response.

- Proficiency with relevant commercial or open-source offensive security tools and frameworks.

- Ability to develop or modify tools and scripts using languages such as Python, PowerShell, Bash, C#, or another relevant programming language.

- Ability to analyse complex attack paths and translate technical findings into clear business risks and actionable recommendations.

- Strong report-writing, presentation, communication, and stakeholder-management skills.

- Sound professional judgement and a strong commitment to ethics, confidentiality, operational security, and authorised testing boundaries.

- Ability to work independently and collaboratively within multidisciplinary teams.

- Willingness and ability to undertake customer-facing assignments of varying duration, including working at customer premises when required.

- Flexibility to support ad-hoc assignments and changing project requirements.

- Eligibility to obtain any security clearance or customer-specific access approval required for assigned engagements.

- A degree or diploma in cybersecurity, computer science, information technology, or a related discipline is preferred; equivalent practical experience will also be considered.

Skills Required

  • Offensive Security Certified Professional (OSCP) certification
  • Demonstrated experience in red teaming, purple teaming, adversarial simulation, penetration testing, or a related offensive security role
  • Strong knowledge of adversary tactics, techniques, procedures, and the MITRE ATT&CK framework
  • Hands-on experience with network, Active Directory, Windows, Linux, web application, cloud, and identity-based attack techniques
  • Experience collaborating with defensive security teams to validate and improve security controls
  • Understanding of SIEM, endpoint detection and response, network monitoring, security logging, threat hunting, and incident response
  • Proficiency with commercial or open-source offensive security tools and frameworks
  • Ability to develop or modify tools and scripts using Python, PowerShell, Bash, C#, or another relevant programming language
  • Ability to analyze complex attack paths and translate technical findings into business risks and actionable recommendations
  • Strong report-writing, presentation, communication, and stakeholder-management skills
  • Professional judgment and commitment to ethics, confidentiality, operational security, and authorized testing boundaries
  • Ability to work independently and collaboratively within multidisciplinary teams
  • Willingness and ability to undertake customer-facing assignments, including work at customer premises when required
  • Flexibility to support ad-hoc assignments and changing project requirements
  • Eligibility to obtain security clearance or customer-specific access approval required for assigned engagements
  • Advanced or specialist certifications such as OSEP, OSED, OSWE, CRTO, CRTE, CREST CRT/CCT, GPEN, or GXPN
  • Degree or diploma in cybersecurity, computer science, information technology, or a related discipline; equivalent practical experience considered
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Singapore
800 Employees
Year Founded: 2018

What We Do

Ensign InfoSecurity is the largest pure-play end-to-end cybersecurity service provider in Asia. Headquartered in Singapore, Ensign offers bespoke solutions and services to address their clients’ cybersecurity needs. Their core competencies are in the provision of cybersecurity advisory and assurance services, architecture design and systems integration services, and managed security services for advanced threat detection, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity. Ensign has two decades of proven track record as a trusted and relevant service provider, serving clients from the public and private sectors in the Asia Pacific region

Similar Jobs

Cloudflare Logo Cloudflare

Senior Customer Engineer,Indonesia

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Singapore, SGP
4400 Employees

Cloudflare Logo Cloudflare

Deal Desk Manager, APAC

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Singapore, SGP
4400 Employees

Mastercard Logo Mastercard

Manager, Partner Success - Security Solutions

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Singapore, SGP
38800 Employees

Mastercard Logo Mastercard

Platform Engineer

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Singapore, SGP
38800 Employees

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account