jobs in Net2Source Inc.

全职 Penetration Tester 工作, 薪水, Net2Source Inc. Federal Territory 公司招聘中 - Ricebowl

Penetration Tester

Net2Source Inc.

Undisclosed

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

Role- Penetration Testing (Must have any one certification- CREST, OSCP+, OSEP, or GPEN)

Role Type- Contract

Work Mode- Onsite

Location- Malaysia


Job Description:

Conduct penetration testing for web, mobile, and API applications.


• Perform secure code reviews, software composition analysis, and container image assurance to identify vulnerabilities early in the SDLC.


• Perform vulnerability assessments for applications, middleware, and supporting systems.


• Utilise industry-standard tools such as Burp Suite, OWASP ZAP, Fortify, Checkmarx, Black Duck, Nessus, Aqua and Qualys.


• Triage, validate, and prioritise security findings from security assessments.


• Work with development, DevOps, and infrastructure teams to ensure timely remediation.


• Track and report remediation progress, ensuring closure within timelines required by regulatory instruments and Technology Security Standards.


• Provide guidance to developers and project teams on secure coding practices.


• Embed application security controls and tools (SAST, DAST, SCA, IAST) into CI/CD pipelines.


• Maintain security documentation and provide evidence for audits and regulatory reviews.


• Ensure compliance with internal policies, regulatory obligations, and industry best practices.


• Support audits, risk assessments, and regulatory inspections involving application security.


We are looking for people with


• Bachelor’s degree in Information Security, Computer Science, or related field.


• Professional certifications such as CREST, OSCP+, OSEP, or GPEN.


• 7+ years of IT security experience, with at least 4 years of direct experience in project-based and annual penetration testing for web, mobile, and API applications.


• Experienced in secure code reviews, software composition analysis, container image assurance, and vulnerability assessments.


• Strong technical knowledge of web, mobile, and API security, including OWASP Top 10 and common attack vectors.


• Hands-on expertise with security testing tools mentioned above.


• Working knowledge of MAS TRM, MAS Cyber Hygiene, and BNM RMiT requirements.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多