Penetration Tester

3 days ago


Kuala Lumpur, Kuala Lumpur, Malaysia PAN ASIA SOFTWARE SOLUTIONS SDN BHD Full time

Job Title : Penetration Tester

Responsible managing a team of penetration testers, designing and executing complex security assessments, and ensuring the security posture of critical systems and applications across our organization. You will also serve as a subject matter expert in identifying vulnerabilities, providing remediation strategies, and developing threat modeling.

Key Responsibilities

Strategic & Operational Leadership

  • Set the direction and scope of internal and external penetration testing engagements.
  • Develop, refine, and maintain the organizations penetration testing methodology.
  • Align red team activities with business objectives, risk priorities, and threat intelligence.

Team Management

  • Lead, mentor, and coach a team of penetration testers, red teamers, and offensive security analysts.
  • Conduct regular 1-on-1s, career development planning, and performance evaluations.
  • Build a collaborative and high-performing team culture with continuous skills development.

Planning & Execution Oversight

  • Oversee project timelines, resource allocation, and task delegation.
  • Ensure timely delivery of assessments and reporting within defined SLAs.
  • Manage team workflows using Agile or structured project management frameworks.

Quality Assurance & Reporting

  • Review and approve penetration testing reports for clarity, accuracy, and risk relevance.
  • Ensure all tests are conducted ethically, legally, and in line with organizational policy.
  • Maintain consistency in reporting formats, severity ratings, and risk classifications.

Technical Guidance & Escalation

  • Provide hands-on support in complex testing scenarios (e.g., privilege escalation, advanced persistence).
  • Serve as the go-to expert in bypassing modern defenses (EDR, WAF, MFA, etc.).
  • Troubleshoot and advise during real-time engagements or red/purple team exercises.

Continuous Improvement

  • Stay current with threat trends, TTPs (MITRE ATT&CK), and industry frameworks (OWASP, PTES, NIST).
  • Recommend new tools, scripts, and techniques to keep the team ahead of emerging threats.
  • Introduce automation, playbooks, and reusable exploits to improve testing efficiency.

Training & Development

  • Develop internal training modules, labs, and tabletop exercises.
  • Support certifications and knowledge-sharing within the team (e.g., OSCP, OSCE, CRTO).
  • Organize internal red team simulations, capture-the-flag (CTF) challenges, or lab walkthroughs.

Stakeholder Communication

  • Present technical findings and risk assessments clearly to non-technical stakeholders.
  • Interface with IT, development, SOC, and compliance teams to coordinate remediation efforts.
  • Participate in executive briefings or incident response drills where red team input is required.

Compliance & Documentation

  • Ensure testing procedures align with regulatory frameworks (ISO 27001, PCI-DSS, NIST).
  • Maintain documentation for all tools, payloads, testing infrastructure, and evidence handling.
  • Establish safe testing protocols to avoid disruption or unintentional damage during engagements.

Job Types: Full-time, Contract

Benefits:

  • Dental insurance
  • Flexible schedule
  • Free parking
  • Health insurance
  • Maternity leave
  • Meal allowance
  • Opportunities for promotion
  • Parental leave
  • Professional development
  • Vision insurance

Application Question(s):

  • Do you require a work visa and authorized to work in Malaysia?
  • Stay current with threat trends, TTPs (MITRE ATT&CK), and industry frameworks (OWASP, PTES, NIST).
  • Experience managing a team of penetration testers, designing and executing complex security assessments, and ensuring the security posture of critical systems and applications across our organization
  • Review and approve penetration testing reports for clarity, accuracy, and risk relevance
  • Serve as the go-to expert in bypassing modern defenses (EDR, WAF, MFA, etc.).
  • Present technical findings and risk assessments clearly to non-technical stakeholders
  • Ensure testing procedures align with regulatory frameworks (ISO 27001, PCI-DSS, NIST).
  • Establish safe testing protocols to avoid disruption or unintentional damage during engagements

Location:

  • Kuala Lumpur (Preferred)

Work Location: In person


  • Penetration Tester

    2 weeks ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Hytech Consulting Management Sdn Bhd Full time 120,000 - 240,000 per year

    About The Role:The Penetration Tester will be responsible for assessing the security of our network, applications, and infrastructure by identifying vulnerabilities and weaknesses that could be exploited by malicious actors. You will work closely with cybersecurity and development teams to provide actionable insights and recommendations, helping us protect...

  • Penetration Tester

    3 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia FIRMUS Full time

    The Penetration Tester will be serving as the Penetration Testing Lead, is a technical leadership role responsible for steering and executing advanced offensive security engagements. This role requires a security practitioner capable of designing, managing, and delivering comprehensive security assessments including penetration testing, red teaming, and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Axiata Digital Labs Full time 120,000 - 240,000 per year

    Summary You will be responsible for managing a team of penetration testers, designing and executing complex security assessments, and ensuring the security posture of critical systems and applications across our organization. You will also serve as a subject matter expert in identifying vulnerabilities, providing remediation strategies, and developing threat...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Axiata Digital Labs Full time

    SummaryYou will be responsible for managing a team of penetration testers, designing and executing complex security assessments, and ensuring the security posture of critical systems and applications across our organization. You will also serve as a subject matter expert in identifying vulnerabilities, providing remediation strategies, and developing threat...

  • Penetration Tester

    2 weeks ago


    Kuala Lumpur, Kuala Lumpur, Malaysia R Systems Full time 120,000 - 240,000 per year

    Position Title: Penetration Testing & Vulnerability Assessment (PTVA)Department: Information SecurityLocation: Kuala LumpurRole OverviewThe PTVA PIC is responsible for coordinating and executing the bank's penetration testing andvulnerability assessment activities. This role ensures that assessments are conducted effectively,vulnerabilities are identified...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Ambition Full time $80,000 - $180,000 per year

    About the ClientOur client is a leading regional financial institution with a dedicated technology and innovation centre based in Kuala Lumpur. The organisation is currently undergoing a large-scale cloud transformation, with a strong focus on strengthening its security posture, modernising legacy platforms, and enhancing governance across digital...


  • Kuala Lumpur, Kuala Lumpur, Malaysia BAE Systems Full time 120,000 - 180,000 per year

    Location(s): Asia-Pacific & Middle East : Malaysia : Kuala LumpurBAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tentacle Infotech Full time 108,000 - 114,000 per year

    Job Title: Senior QA / Test Analyst – Internet & Core Banking SystemsCompetencies and SkillsQualificationsEducation: Minimum Bachelor's Degree or Diploma in Computer Science, Information Technology, or a related discipline.Professional Certification:CTFL (Certified Tester Foundation Level) certification is an added advantage.Exposure to CMMi/TMMi testing...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Wizlynx Malaysia Sdn Bhd Full time 900,000 - 1,200,000 per year

    Key RoleAs (Senior) Cyber Security Consultant & Penetration Tester, you will execute a variety of engagements, conducting advanced hands-on penetration testing beyond automated tool validation, which will focus on targets that may include network devices, servers, web and mobile apps, web APIs, wireless infrastructures, IoT devices, and other information...

  • Security Consultant

    3 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia LRQA Full time

    About LRQA At LRQA our focus has always been on excellence in cyber security. We have teams that offer world class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more. Our business is global and so are our clients. We work closely with central...