Penetration Tester

FIRMUS

Kuala Lumpur

On-site

MYR 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

FIRMUS in Kuala Lumpur is seeking an experienced Penetration Tester to design, execute, and manage comprehensive security assessments across networks, web and mobile applications, and cloud environments.

You will lead offensive security exercises (including Red Team engagements), document findings with clear, prioritized recommendations to mitigate risks, and mentor junior consultants while advising clients on improving security posture and incident response capabilities.

Qualifications

  • 3–5+ years hands-on penetration testing experience across networks, apps and cloud.
  • Relevant certifications such as OSCP, CREST CRT, or equivalent preferred.
  • Strong knowledge of MITRE ATT&CK and vulnerability assessment tools.
  • Excellent reporting, communication, and client-facing skills.

Responsibilities

  • Plan, scope, and lead security assessment activities targeting network infrastructure, web apps, mobile platforms, and cloud.
  • Conduct offensive security exercises, including Red Team engagements.
  • Document findings with clear, prioritized recommendations to mitigate identified risks.
  • Work directly with clients to understand security objectives and communicate technical findings and business risk.
  • Serve as QA reviewer for reports from junior consultants, ensuring accuracy and best practices.
  • Provide strategic counsel to clients on security posture and incident response.
  • Provide advisory and project support to junior consultants.
  • Ensure all deliverables are high-quality and on schedule.

Skills

Penetration testing
Red team
Application security
Vulnerability assessment
Project management
Leadership

Education

Degree in Information Technology

Job description

The Penetration Tester position is an experienced and certified security practitioner capable of designing, executing, and managing comprehensive security assessments. This includes penetration testing, red teaming, and application security reviews to uncover critical vulnerabilities and assess organizational risk across diverse client environments.

Key Responsibilities:
  • Plan, scope, and lead security assessment activities targeting network infrastructure, web applications, mobile platforms, and cloud environments.
  • Conduct offensive security exercises, including Red Team exercises, to simulate real-world threats and test defensive capabilities.
  • Oversee the thorough documentation of findings, providing clear, actionable, and prioritized recommendations to mitigate identified risks.
  • Work directly with clients to understand their security objectives, define testing parameters, and clearly communicate the technical findings and associated business risk.
  • Serve as a technical QA reviewer for reports and deliverables produced by junior consultants, ensuring accuracy, clarity, and adherence to industry best practices.
  • Provide strategic counsel to clients on enhancing their overall security posture, incident response capabilities, and adherence to relevant compliance standards.
  • Provide advisory, technical guidance, and project support to junior consultants.
  • Ensure all project deliverables are completed with high quality and within the agreed timelines.
Qualifications & Experience
  • Degree in Information Technology, Cybersecurity, or a related computer science field is preferred.
  • 3-5+ years of hands-on experience in penetration testing, web and mobile application security, and managing red team exercises.
  • Strong proficiency in both manual and automated security testing methodologies and tools (experience in publishing security exploits is an added advantage).
  • Possession of industry-recognized certifications such as OSCP, CREST CRT, or equivalent is highly preferred.
  • Expert understanding of exploitation techniques, attack methodologies (e.g., MITRE ATT&CK), and vulnerability assessment tools.
  • Broad knowledge of core cybersecurity principles, defensive architectures, and relevant regulatory frameworks.
  • Strong analytical skills with meticulous attention to detail for vulnerability research, analysis, and reporting.
  • Demonstrated project management and leadership capabilities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester (Security)
Penetration Tester (Security)

VeecoTech Web & Ecommerce Sdn Bhd • Bayan Lepas

On-site
MYR 80,000 - 120,000
Penetration Tester (Team Lead) | RM15K
Penetration Tester (Team Lead) | RM15K

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Associate- Digital Trust and Cybersecurity
Associate- Digital Trust and Cybersecurity

PwC Malaysia • Kuala Lumpur

On-site
MYR 54,000 - 90,000
PwC Professional development
Certifications support
Career progression
Cybersecurity Tester
Cybersecurity Tester

IMPRESSIVE COMMUNICATION SDN BHD • Petaling Jaya

On-site
MYR 120,000 - 180,000
Associate - Cybersecurity
Associate - Cybersecurity

PwC • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Security Engineer - Red Team
Security Engineer - Red Team

IBroad Solutions • Selangor

On-site
MYR 120,000 - 180,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 60,000 - 120,000
Security Engineer - Red Team
Security Engineer - Red Team

IBroad Solutions • Petaling Jaya

On-site
MYR 120,000 - 180,000
Offensive Security Analyst (Penetration Testers)
Offensive Security Analyst (Penetration Testers)

Sekuro Asia - An Insight Company • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Specialist I, Cyber Defense Operation Centre (TCF)
Specialist I, Cyber Defense Operation Centre (TCF)

Concentrix • Kuala Lumpur

On-site
MYR 60,000 - 90,000