About the job
Join Assurity Trusted Solutions (ATS), a proud subsidiary of the Government Technology Agency (GovTech), as we continue our mission to strengthen cybersecurity across the digital landscape. With over ten years of dedicated service, ATS partners with government entities and commercial organizations to deliver a wide array of products and services, including infrastructure, operational services, and assurance solutions. Our focus remains on fostering trust and collaboration to mitigate cyber risks effectively.
Key Responsibilities:
- Lead the penetration testing and red teaming initiatives for systems governed by the CISO, encompassing both corporate environments and internal product teams.
- Plan and implement testing strategies for:
- Web, cloud, network, and API applications,
- Cloud workloads, including government cloud platforms and containerized environments,
- Data platforms such as data lakes and large-scale analytics systems,
- Enterprise platforms including identity, collaboration, and developer tools, along with other approved SaaS solutions.
- Identify and validate end-to-end attack paths across various domains, documenting realistic threat scenarios and assessing their potential impact.
- Oversee penetration testing engagements with external vendors, including defining rules of engagement, preparing environments, and reviewing reports for quality and depth.
- Generate concise, prioritized reports and briefings for engineering teams and management, aiding in remediation planning and retesting efforts.
- Design and manage standardized penetration testing environments, including workstations, network zones, and realistic testing datasets.
- Collaborate with infrastructure and central engineering teams to integrate penetration testing tools and automation, ensuring comprehensive logging and telemetry.
- Co-author penetration testing policies and standards within GovTech and lead implementations for product teams.
- Translate policy directives into practical guidance, templates, and checklists to facilitate consistent and compliant penetration testing practices.

