about the company
Our client is an established cybersecurity consulting firm with a strong presence in Malaysia, providing cybersecurity advisory, penetration testing, vulnerability management and managed security services to enterprise and government clients. They are known for delivering high-quality security consulting services and investing in the continuous development of their cybersecurity professionals.
...
about the job
We are looking for an experienced Penetration Tester to join a growing cybersecurity consulting team. You will be responsible for delivering penetration testing and vulnerability assessment projects across web applications, mobile applications, APIs, internal and external networks, and cloud environments.
The ideal candidate enjoys ethical hacking, problem solving and helping organisations strengthen their security posture. You will work alongside experienced security consultants while gaining exposure to a wide range of technologies and industries.
Key Responsibilities
- Perform Web Application, Mobile Application, API, Internal and External Network Penetration Testing.
- Conduct Vulnerability Assessments and Security Configuration Reviews.
- Identify, validate and document security vulnerabilities following industry best practices.
- Produce clear technical reports with practical remediation recommendations.
- Present technical findings and risk assessments to customers.
- Support remediation verification and security consultation throughout project delivery.
- Research emerging attack techniques and continuously improve testing methodologies.
- Collaborate with internal teams to ensure successful project delivery.
Preferred Skills & Experience
- Minimum 3 years of hands-on Penetration Testing experience.
- Strong understanding of OWASP Top 10, MITRE ATT&CK and common attack vectors.
- Hands-on experience with tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark, Kali Linux or similar.
- Experience performing Web, Mobile, API and Network Penetration Testing.
- Familiarity with Vulnerability Assessment methodologies and security standards.
- Professional certifications such as OSCP, CEH, GPEN, CREST or equivalent are advantageous.
- Strong report writing and client communication skills.
about the manager/team
You will be joining a highly experienced cybersecurity consulting team consisting of penetration testers and security consultants who deliver projects across financial services, government, telecommunications, healthcare and enterprise clients. The team promotes continuous learning, knowledge sharing and professional certification, providing excellent exposure to diverse security engagements and career development opportunities.