About iGears
iGears Technology Limited (科擎科技有限公司) has built software for Hong Kong organisations since 2004, including listed companies, public-sector bodies, NGOs, education organisations and churches. We develop and run 20 of our own SaaS products, and our MobPage division has published 200+ mobile apps. With offices in Hong Kong and Edmonton, Canada, we are now building an in-house cybersecurity team to deliver penetration testing, security risk assessments and privacy impact assessments for clients, and to secure our own platforms.
What you’ll do
- Plan and run penetration tests of web applications, APIs and mobile apps for clients in Hong Kong and Canada, following OWASP WSTG, ASVS and MASVS
- Test how applications connect to third-party services (OAuth, webhooks, payment and messaging APIs) and cloud environments
- Verify every finding by hand, rate risk with CVSS, and write clear reports with fix guidance for developers and management
- Retest fixes and issue verification letters
- Help scope engagements: rules of engagement, test accounts, testing windows and authorisation letters
- Contribute hands-on testing to security risk assessments and audits (SRAA)
- Test and harden iGears’ own SaaS platforms, and coach our developers on secure coding
What you’ll bring
- OSCP, or an equivalent hands-on certification (e.g. CREST CRT or CCT, GIAC GPEN or GWAPT, eWPTX, PNPT)
- At least 2 years of hands-on penetration testing, with web application and API testing as core skills
- Strong command of Burp Suite and common testing tools; scripting in Python, Bash or similar
- Clear written English for client reports
- The right to work in Hong Kong
Nice to have
- OSWE, OSEP, BSCP or CREST CCT APP
- Mobile (iOS/Android), Active Directory or cloud (AWS, Azure, GCP) testing
- Source code review
- CVEs, bug bounty findings or a CTF track record
- Spoken Cantonese, for working with Hong Kong clients
What we offer
- HK$30,000–50,000 a month, depending on experience and certifications
- Real client engagements, plus 20 in-house SaaS products to test and secure
- A founding role in our new security team, reporting to our CTO
- Birthday holiday, Free snacks and drinks
Explore our platforms before you apply
- AI: GenCMS (*************), AskCore (*************), HumanLevelUP (*************), PromoPilot (*************), Webetter (*************), PhotoCen (*************), Duckbot (*************, preview)
- Business operations: fileEC (*************), InsightBook (*************), HRFlowTech (*************), MemberSys (*************), AppointSys (*************), Paperless.Cards (*************)
- Messaging and marketing: SendPromotion.Email (*************), ************* (*************), MarketHK (*************)
- Education and community: LearnSys (*************), ITChurch (*************)
- Directories: E12 (*************, *************) and E12 Careers (*************)
Full list: *************
How to apply
Email your CV to ************* with the subject “Security Consultant (PT) – Your Name”. Please include:
- links to or IDs for your certifications (e.g. OffSec credential link, CREST or Credly badge, ISACA or ISC2 certificate number)
- your expected salary and notice period
Applications close on 31 October 2026. Only shortlisted candidates will be contacted.
iGears is an equal opportunity employer. This role is open to all qualified applicants.
Personal data you provide will be used by iGears Technology Limited only for recruitment. Providing it is voluntary, but we can’t consider your application without it. It may be shared with other iGears offices if you are considered for a role there. Data of unsuccessful applicants is destroyed within two years. To access or correct your data, or for our full Personal Information Collection Statement, email *************.
Pay: $30,000.00 - $50,000.00 per month
Work Location: In person