jobs in FIRMUS

全职 Senior Penetration Tester 工作, 薪水, FIRMUS Federal Territory 公司招聘中 - Ricebowl

Senior Penetration Tester

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

The Penetration Tester will be serving as the Penetration Testing Lead, is a technical leadership role responsible for steering and executing advanced offensive security engagements. This role requires a security practitioner capable of designing, managing, and delivering comprehensive security assessments including penetration testing, red teaming, and application security reviews to identify critical vulnerabilities and assess organizational risk across diverse client environments.


Key Responsibilities


Technical Leadership & Execution

  • Design and Scope Engagements: Plan, scope, and lead security assessment activities targeting network infrastructure, web applications, mobile platforms, and cloud environments.
  • Advanced Testing: Conduct offensive security exercises, including Red Team exercises, to simulate real-world threats and test defensive capabilities.
  • Post-Engagement Analysis: Oversee the thorough documentation of findings, providing clear, actionable, and prioritized recommendations to mitigate identified risks.


Consulting & Reporting

  • Client Collaboration: Work directly with clients to understand their security objectives, define testing parameters, and clearly communicate the technical findings and associated business risk.
  • Quality Assurance (QA): Serve as a technical QA reviewer for reports and deliverables produced by junior consultants, ensuring accuracy, clarity, and adherence to industry best practices.
  • Strategic Advisement: Provide strategic counsel to clients on enhancing their overall security posture, incident response capabilities, and adherence to relevant compliance standards.


Team Mentorship & Growth

  • Mentorship: Mentor and train junior consultants, fostering the development of technical skills in penetration testing methodologies, application security, and report writing.


Qualifications & Experience


Essential Technical Expertise

  • Proven Expertise: 5+ years of demonstrable experience in hands-on penetration testing, web and mobile application security, and managing Red Team exercise.
  • Offensive Security Skills: Expert knowledge of common exploitation techniques, attack methodologies (e.g., MITRE ATT&CK), and vulnerability analysis tools.
  • Foundational Knowledge: Broad and deep understanding of core Cybersecurity principles, defensive architectures, and regulatory frameworks.


Educational & Professional Requirements

  • Certifications: Possession of industry-leading certifications such as OSCP, CREST CRT or equivalent is highly advantageous.
  • Analytical Skills: Exceptional analytical ability and meticulous attention to detail required for complex vulnerability research and reporting.


Soft Skills & Work Environment

  • Communication: Excellent verbal and written communication skills, with the ability to articulate complex technical concepts to both technical and executive audiences.
  • Team Collaboration: Demonstrated ability to lead projects, work effectively on-site, and collaborate seamlessly with cross-functional internal and client teams.
  • Location: Commitment to working full-time on-site in WP. Kuala Lumpur.


重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多