Cyber Security Consultant

ABeam Consulting Malaysia

Petaling Jaya

On-site

MYR 90,000 - 150,000

Full time

3 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ABeam Consulting Malaysia is seeking a Security VAPT professional to perform comprehensive assessment of clients' infrastructure, endpoints, and cloud environments, ensuring alignment with RoE and industry standards.

You will document findings, present risk scenarios to technical and management teams, and collaborate with cross-functional groups to drive remediation and ongoing security improvements.

Qualifications

  • Bachelor's degree in Cybersecurity, CS, or related field.
  • Knowledge/experience in Vulnerability Assessment and Penetration Testing (VAPT).
  • Familiar with TCP/IP, networks, Windows/Linux, AD, web tech, vulnerabilities.
  • Experience with common VAPT tools (Nessus, Burp Suite, Metasploit, Nmap).
  • Ability to produce clear technical documentation and reports.
  • Strong communication and willingness to learn.

Responsibilities

  • Perform VAPT for internal and external environments across assets.
  • Conduct asset discovery, scanning, validation, exploitation, and configuration reviews.
  • Validate vulnerabilities to reduce false positives and assess risk.
  • Communicate results to stakeholders and provide remediation guidance.
  • Support presales activities and research emerging threats.
  • Collaborate with infra, network, cloud, app, and security teams.
  • Prepare professional reports, checklists, and evidence.
  • Travel to client sites as required.

Skills

VAPT
TCP/IP & Networking
Windows/Linux
Active Directory
Web technologies
Security vulnerabilities
Scripting: Python
Documentation skills
Communication skills
English & Malay

Education

Bachelor's degree in Cybersecurity/Info Sec/CS

Tools

Nessus
Burp Suite
Metasploit
Nmap
Wireshark
Kali Linux

Job description

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for internal and external infrastructure, servers, endpoints, network devices, web applications, and cloud environments.
  • Conduct asset discovery, service enumeration, vulnerability scanning, manual validation, exploitation testing, and security configuration assessments within the approved scope.
  • Validate identified vulnerabilities to minimize false positives and determine actual security impact and associated risk.
  • Perform penetration testing activities using appropriate tools and methodologies while adhering to client-approved Rules of Engagement (RoE).
  • Analyze vulnerabilities and map findings to relevant standards and references such as CVSS, CWE, OWASP, and MITRE ATT&CK, where applicable.
  • Prepare professional technical VAPT reports, executive summaries, vulnerability registers, assessment checklists, and supporting evidence.
  • Present assessment results to technical teams, management, and client stakeholders, clearly communicating identified risks and recommended remediation.
  • Provide post-assessment remediation support, including clarification of findings, remediation recommendations, evidence review, vulnerability re-scanning, and revalidation.
  • Work closely with infrastructure, network, cloud, application, and security teams to support effective vulnerability remediation.
  • Support cybersecurity presales activities including scope clarification, effort estimation, technical proposal preparation, and client discussions when required.
  • Continuously research emerging vulnerabilities, attack techniques, security tools, and industry cybersecurity trends.
  • Develop additional capabilities in OT/ICS security assessment, cloud security assessment, red teaming, and security configuration review based on business and project needs.
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, Information Technology, Networking, or a related field.
  • Knowledge or hands‑on experience in Vulnerability Assessment and Penetration Testing (VAPT).
  • Good understanding of TCP/IP, network protocols, Windows/Linux environments, Active Directory, web technologies, and common security vulnerabilities.
  • Experience or familiarity with security assessment tools such as Nmap, Nessus, Burp Suite, Metasploit, Nikto, Nuclei, Wireshark, Kali Linux, or equivalent tools.
  • Understanding of common vulnerability categories including OWASP Top 10, insecure configurations, outdated software, authentication weaknesses, network/service exposure, and access‑control issues.
  • Ability to perform manual vulnerability validation and distinguish exploitable security issues from scanner‑generated false positives.
  • Basic scripting or automation knowledge using Python, PowerShell, Bash, or equivalent is an advantage.
  • Ability to prepare clear technical documentation, assessment evidence, and professional cybersecurity reports.
  • Strong analytical and troubleshooting skills with willingness to continuously learn new security technologies and attack techniques.
  • Good verbal and written communication skills and ability to coordinate with technical and non‑technical stakeholders.
  • Business‑level proficiency in English and Malay is mandatory; proficiency in other languages is an advantage for stakeholder communication in multinational environments.
Preferred Qualifications
  • Certifications: CompTIA Security+, ISC2 Certified in Cybersecurity (CC), CEH, or equivalent entry‑level cybersecurity certifications are an advantage.
  • Hands‑on experience conducting infrastructure, network, web application, or cloud security assessments.
  • Knowledge of Active Directory security assessment and common attack techniques is an advantage.
  • Exposure to AWS, Azure, or other cloud security assessments is an advantage.
  • Exposure to OT/ICS environments and OT security concepts is an advantage; candidates with a strong willingness to develop OT security capabilities are also encouraged.
  • Knowledge of vulnerability remediation, system hardening, patch management, and security configuration improvement is advantageous.
  • Experience supporting re‑scanning/revalidation and remediation discussions with clients is preferred.
  • Willingness to travel or work at client sites when required for cybersecurity assessment activities.
  • Ability to work independently as well as collaboratively within cybersecurity and cross‑functional project teams.
  • Fresh graduates are encouraged to apply; candidates with 1–2 years of relevant cybersecurity or VAPT experience will be an added advantage.
  • Fresh graduates with Final Year Projects (FYP) related to OT/ICS cybersecurity, AI‑driven cybersecurity automation, AI agents for security operations, or other relevant cybersecurity areas are highly encouraged to apply.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Red Team
Security Engineer - Red Team

IBroad Solutions • Petaling Jaya

On-site
MYR 120,000 - 180,000
Senior Executive - Cybersecurity
Senior Executive - Cybersecurity

BDO Malaysia • Kuala Lumpur

On-site
MYR 60,000 - 110,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Axonect • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Penetration Tester
Senior Penetration Tester

FIRMUS • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Staff Cybersecurity & OT Security Engineer
Staff Cybersecurity & OT Security Engineer

Oxydata Software Sdn Bhd • Penang

On-site
MYR 180,000 - 240,000
Junior Security Solutions Consultant
Junior Security Solutions Consultant

UniQ Consulting & Services Sdn Bhd • Petaling Jaya

On-site
MYR 60,000 - 120,000
Security Engineer - Offensive Security (Red Team)
Security Engineer - Offensive Security (Red Team)

Axonect • Kuala Lumpur

On-site
MYR 100,000 - 180,000
Security Engineer - Offensive Security (Red Team)
Security Engineer - Offensive Security (Red Team)

XL Axiata • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior VAPT Practice Head at EC-Council International Limited
Senior VAPT Practice Head at EC-Council International Limited

EC-Council International Limited • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Penetration Tester (Security)
Penetration Tester (Security)

VeecoTech Web & Ecommerce Sdn Bhd • Bayan Lepas

On-site
MYR 80,000 - 120,000