Ensign is hiring !
Key Responsibilities
1. Penetration Testing & Security Assessments
Conduct penetration testing on:
Web applications (OWASP Top 10)
Mobile applications (iOS / Android)
Internal and external networks
APIs and web services
Cloud environments (AWS, Azure, GCP)
Perform vulnerability assessments using automated and manual techniques.
Simulate real-world attack scenarios including privilege escalation and lateral movement.
2. Exploitation & Validation
Identify and exploit security weaknesses in systems and applications.
Develop proof-of-concept (PoC) exploits to validate findings.
Assess impact and risk severity of vulnerabilities discovered.
3. Reporting & Documentation
Prepare detailed penetration testing reports including:
Executive summary
Technical findings
Risk ratings
Remediation recommendations
Present findings to technical teams and management.
Provide remediation validation (retest) services.
4. Tools & Techniques
Utilize industry tools such as:
Burp Suite
Metasploit
Nmap
Nessus / OpenVAS
Wireshark
SQLmap
Kali Linux toolsets
Develop custom scripts (Python, Bash, PowerShell) where necessary.
Stay updated on latest attack techniques, CVEs, and threat trends.
5. Compliance & Standards
Conduct testing aligned with:
OWASP Testing Guide
PTES (Penetration Testing Execution Standard)
NIST frameworks
ISO 27001 controls
Support compliance-driven assessments (e.g., PCI-DSS).
Requirements
Bachelor’s Degree in Cybersecurity, Computer Science, IT, or related field.
Experience
2–5 years of experience in penetration testing or offensive security.
Hands-on experience conducting web and network penetration tests.
Experience preparing formal penetration testing reports.
(Senior level: 5+ years with leadership or project ownership experience.)
Top Skills
What We Do
Ensign InfoSecurity is the largest pure-play end-to-end cybersecurity service provider in Asia. Headquartered in Singapore, Ensign offers bespoke solutions and services to address their clients’ cybersecurity needs. Their core competencies are in the provision of cybersecurity advisory and assurance services, architecture design and systems integration services, and managed security services for advanced threat detection, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity. Ensign has two decades of proven track record as a trusted and relevant service provider, serving clients from the public and private sectors in the Asia Pacific region







