AVP/VP, Red Team Specialist, Cyber Security Assurance & Defence, Technology Group

Location: 

Singapore, SG

Job Function:  Technology Group
Job Type:  Permanent
Req ID:  17320

GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.

 

Infrastructure Cybersecurity & Resilience (ICR)

Our mission is to fortify GIC's infrastructure and cybersecurity capabilities by embedding security and resilience into everything we do, providing stable, secure and dependable services and solutions.The individual will be part of the Cybersecurity Assurance & Defence (CSAD) team and will play a key role in strengthening the firm’s security posture through proactive vulnerability management, adversarial attack simulation planning, and continuous improvement of security. The individual will serve as a control owner, driving threat prioritization, root cause analysis, and cross-team collaboration to remediate and prevent recurrence of vulnerabilities.  

 

What impact can you make in this role?

This is an exciting opportunity for someone to demonstrate impact, value, through advance security technology and adapting security practices.  Your engagement with stakeholders at all levels of the organisation will foster a robust and resilient cyber security environment, thereby safeguarding GIC's digital assets and operations.  This role requires strategic thinking, strong analytical capabilities, and the ability to influence stakeholders across technical and business domains. 

 

We are seeking a technical, hands-on Red Teamer to continuously identify, simulate and validate security gaps across our people, processes, and technology. Unlike compliance-driven vulnerability scanning, this role emulates real-world adversaries — chaining exploits, evading defenses, and demonstrating tangible business impact — to prove where exposure lies. The scope spans enterprise infrastructure as well as emerging technologies, including IoT devices, AI/ML systems, and their supporting or dependent technologies. The successful candidate should be to write exploit code and translate technical findings into business impact.

 

What will you do as AVP/VP Red Team Specialist, Cyber Security Assurance & Defence?

  • Design and execute full-scope adversary emulation and red team engagements against people, process, and technology, mapping objectives to recognized frameworks (e.g., MITRE ATT&CK).
  • Develop, adapt, and maintain custom exploit code, tooling, and payloads where off-the-shelf tooling is insufficient or too easily detected.
  • Stand up and operate resilient, secure command-and-control (C2) infrastructure — including redirectors, domain fronting/categorization, and operational security (OPSEC) hardening — to safely emulate advanced threat actors.
  • Build a threat model and engagement plan prior to execution: define the target, likely adversary profiles, attack paths, success criteria, and safety constraints before any action is taken.
  • Conduct social engineering, physical, and process-focused assessments to validate the human and procedural layers of defense, not just the technical stack.
  • Assess emerging technologies — particularly AI/ML systems, LLM applications, and their pipelines — for adversarial, prompt-injection, data-poisoning, model-extraction, and supply-chain exposures.
  • Validate detection and response: work with (or against) the blue team to measure whether attacks are detected, escalated, and contained (purple teaming).
  • Produce clear, prioritized, business-relevant findings and present them to both technical teams and executive stakeholders.
  • Track remediation and re-test to confirm that validated gaps are genuinely closed.

 

What qualifications or skills should you possess in this role?

 

Exploit Development

  • Proficiency in one or more systems/scripting languages (e.g., C/C++, Rust, Go, Python, PowerShell, C#) sufficient to write and debug exploit code and custom tooling.
  • Understanding of memory-corruption classes (buffer/heap overflows, use-after-free), web and API exploitation, and common defensive mitigations (ASLR, DEP/NX, CFG, EDR).
  • Ability to weaponize public vulnerabilities and, where appropriate, discover novel ones through fuzzing and code review.

 

C2 & Offensive Infrastructure

  • Hands-on experience deploying and operating C2 frameworks (e.g., Cobalt Strike, Mythic, Sliver, Havoc) securely and with sound OPSEC.
  • Ability to design resilient infrastructure: redirectors, TLS/HTTPS profiles, domain categorization, and segregation between engagements.
  • Discipline around encryption of implants and traffic, credential handling, and teardown/destruction of infrastructure after engagements.

 

Threat modelling and Planning

  • Ability to construct a threat model before execution — defining adversary profiles, assets, attack surface, likely kill chains, and abuse cases.
  • Familiarity with structured methodologies (MITRE ATT&CK, STRIDE, PASTA, cyber kill chain) and threat-intelligence-led scoping.
  • Translating threat models into a rules-of-engagement (RoE) document with clear scope, constraints, and abort criteria.

 

Emerging Technology and AI

  • Knowledge of AI/ML attack surface: prompt injection, jailbreaks, training-data poisoning, model theft/extraction, and insecure ML pipelines
  • Awareness of relevant guidance such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
  • Comfort assessing cloud-native, container/Kubernetes, and CI/CD supply-chain environments that underpin modern AI deployments.

 

Report and Communicating

  • Write clear, reproducible reports that document attack paths, evidence, business impact, and prioritized, actionable remediation.
  • Present findings to technical teams (developers, IT, blue team) and to non-technical audience, adjusting depth and framing.
  • Defend methodology and conclusions under scrutiny and constructively partner with defenders rather than adopting a purely adversarial posture.
  • Contribute to metrics that show risk reduction over time, not just a count of vulnerabilities.

 

Work at the Point of Impact
We need to be forward-looking to attract the right people to help us become the Leading Global Long-term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day-to-day decisions. We strive to inspire. To make an impact.

 

Flexibility at GIC
At GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection.  At the same time, we believe that flexibility allows us to do our best work and be our best selves.  Thus, our teams come into the office four days per week to harness the benefits of in-person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise

 

GIC is an equal opportunity employer 
As an employer, we passionately believe every individual brings with them unique diversity of thought and perspectives to meaningfully enrich perspectives of GIC teams to drive competitive performance. An inclusive environment yields exceptional contribution.

 

Learn more about our Technology Group here: 
https://gic.careers/group/technology-group/

 

 

 

 

 

Our PRIME Values

Our PRIME Values

GIC is a values driven organization. GIC’s PRIME Values act as our compass, enabling us to fulfil our fundamental purpose and objectives. It is the foundational bedrock which governs our behaviors, our decision making, and our focus. It informs both our long-term strategy as a firm, and the way we relate to our Client, business partners and employees. PRIME stands for Prudence, Respect, Integrity, Merit and Excellence.