
Search by job, company or skills
About Reversec
At Reversec, we deliver research-led cyber security services that help organizations defend against real-world threats and build long-term resilience. Our consultants are a diverse team of highly skilled technical experts, researchers, and creative problem-solvers who are passionate about advancing the cyber security industry.
We believe great consultants are empowered consultants. Our people take ownership of their professional development, contribute to meaningful research, and have the freedom to shape the way we work. If you're driven by curiosity, enjoy solving complex technical challenges, and thrive in an environment that values innovation and continuous learning, we'd love to hear from you.
The Opportunity
We are looking for a Security Consultant to join our Singapore office.
In this role, you will deliver a broad range of offensive security engagements for clients across multiple industries. Your work will include penetration testing, security assessments, and technical consulting across modern enterprise environments from traditional infrastructure and web applications to cloud-native platforms, mobile applications, APIs, and emerging technologies.
Beyond client engagements, you'll have dedicated opportunities to conduct security research, develop internal capabilities, contribute to tooling, and explore new attack techniques. At Reversec, research is not an afterthought, it's a core part of how we stay ahead of evolving threats and continuously improve the services we deliver.
Key Responsibilities
As a Security Consultant, you will:
Deliver high-quality penetration testing and technical security assessments across web applications, APIs, mobile applications, cloud environments, infrastructure, wireless networks, and other technology platforms.
Identify, validate, and clearly articulate security vulnerabilities, attack paths, and associated business risks.
Produce high-quality technical reports with practical, risk-based remediation recommendations.
Present technical findings to both technical and non-technical stakeholders.
Support the planning, execution, and successful delivery of security consultancy engagements.
Assist with pre-sales activities, including technical scoping, solution design, effort estimation, and proposal development.
Conduct security research into emerging technologies, attack techniques, tools, vulnerabilities, and defensive strategies.
Develop and improve internal tools, methodologies, and testing frameworks.
Contribute to Reversec's knowledge-sharing culture by mentoring colleagues, presenting research, and continuously improving our delivery processes.
Stay current with evolving cyber security threats, technologies, industry standards, and regulatory requirements.
What We're Looking For
Successful consultants at Reversec typically demonstrate the following qualities:
Passion for Offensive Security
Cyber security isn't just your profession. It's something you genuinely enjoy. You're naturally curious, enjoy understanding how systems work, and are motivated to discover how they can be broken securely and responsibly. You continually challenge yourself to learn new technologies, techniques, and attack methodologies.
Technical Excellence
You possess strong technical foundations across multiple security domains and are comfortable tackling unfamiliar technologies. You understand offensive security principles beyond simply running automated tools and enjoy solving challenging technical problems through critical thinking and hands-on testing.
Ownership and Initiative
You are self-motivated and capable of working independently while knowing when to seek guidance or collaborate with teammates. You take ownership of your work, proactively identify opportunities for improvement, and continuously strive to deliver exceptional outcomes for clients.
Communication Skills
You can clearly explain complex technical concepts to audiences with varying levels of technical expertise. You produce concise, well-written reports, confidently present findings, and actively contribute to knowledge sharing within the team.
Skills and Experience
The ideal candidate will possess:
At least 1 year of hands-on experience delivering cyber security consultancy or penetration testing engagements.
Strong experience performing web application penetration testing, with a solid understanding of manual testing methodologies and common vulnerabilities beyond automated scanning.
Practical experience using tools such as Burp Suite, with the ability to manually identify and exploit vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), authentication and authorization flaws, and business logic issues.
Experience conducting infrastructure penetration testing across Windows, Linux, Active Directory, internal and external networks, demonstrating methodologies beyond vulnerability scanning.
Experience performing mobile application security assessments (iOS and/or Android), including dynamic analysis using tools such as Frida, objection, or equivalent instrumentation frameworks.
Familiarity with testing RESTful APIs, GraphQL APIs, and modern authentication mechanisms such as OAuth, OpenID Connect, and JWT.
Experience supporting the end-to-end delivery of consultancy engagements within a collaborative team environment.
Ability to support pre-sales activities by understanding client requirements, scoping assessments, and recommending suitable testing approaches.
Understanding of cloud security concepts across AWS, Microsoft Azure, or Google Cloud Platform.
Familiarity with secure software development practices, DevSecOps concepts, and CI/CD environments is advantageous.
Knowledge of regional cyber security regulations and frameworks, including the Monetary Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines, is highly desirable.
Excellent verbal communication, technical writing, and client-facing presentation skills.
Certifications
Required:
Active OffSec Certified Professional (OSCP) certification.
Active CREST Registered Penetration Tester (CRT) or equivalent CREST certification.
Highly desirable certifications include:
OffSec Web Expert (OSWE)
OffSec Experienced Penetration Tester (OSEP)
Certified Red Team Operator (CRTO)
AWS Certified Security - Specialty
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
Other relevant advanced offensive security certifications.
Why Join Reversec
At Reversec, you'll enjoy more than just interesting projects, such as:
Meaningful Technical Work
Work on challenging engagements involving modern technologies, cloud-native environments, enterprise infrastructure, applications, and emerging attack surfaces across diverse industries.
Dedicated Research Time
Research is part of your role and not something squeezed into your personal time. You'll have dedicated opportunities to explore new technologies, develop tools, publish research, and contribute to the wider security community.
Learn from Industry Experts
Collaborate with experienced consultants, researchers, and technical leaders who are passionate about offensive security and committed to sharing knowledge.
Career Growth
We invest in your professional development through structured mentoring, technical training, conference opportunities, certification support, and continuous learning.
Collaborative Culture
Join a supportive, highly technical team where innovation, curiosity, and knowledge sharing are genuinely encouraged.
Flexibility and Ownership
We trust our consultants to manage their work, take initiative, and influence how we engage clients, deliver services, and improve our capabilities.
Job ID: 151980453