Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
LAVU TECH SOLUTIONS SDN. BHD. is seeking a Senior Resident Engineer to provide on-site programme management for enterprise-wide VAPT engagements.
You will coordinate between TNB system owners, internal security teams and VAPT service providers, ensuring engagements are planned, executed, reported and closed consistently. You will lead the development of the annual VAPT plan, review test results, and drive remediation with system owners.
The Resident Engineer shall provide dedicated, on-site programme management for TNB's enterprise-wide Vulnerability Assessment and Penetration Testing (VAPT) programme. The role is management and governance focused, with sufficient technical depth to review and challenge test results. The Resident Engineer acts as the single point of coordination between TNB system owners, internal security teams and appointed VAPT service providers, and is accountable for ensuring all VAPT engagements are planned, executed, reported and closed in a consistent and auditable manner.
Develop and maintain the annual VAPT plan and testing calendar covering IT, cloud, application and network assets, prioritised on a risk basis.
Receive, scope and prioritise VAPT requests from business units and system owners, and prepare the rules of engagement, test authorisation and approvals for each engagement.
Verify pre-test readiness environment, test accounts, rollback plans and safe-testing controls, particularly for production and OT systems.
Coordinate and monitor day-to-day execution of multiple concurrent engagements across appointed service providers.
Perform quality assurance review of all VAPT reports, including technical accuracy, evidence sufficiency, risk rating consistency and false-positive validation.
Maintain a central findings register and drive remediation with system owners against TNB's remediation SLA by severity.
Coordinate retesting and formal closure of remediated findings, and administer the risk acceptance and exception process.
Produce monthly programme reports and quarterly management dashboards, including KPIs, trend analysis and recurring root causes.
Support internal audit, external audit and regulatory requirements by providing VAPT evidence and status.
Manage the day-to-day performance of appointed VAPT service providers and verify deliverables against contracted scope.
Bachelor's Degree in Computer Science, Information Technology, Engineering, Cyber Security or equivalent.
Minimum 8 years working experience in ICT, of which minimum 5 years in cyber security.
Minimum 3 years hands-on experience in VAPT delivery as a tester, team lead or technical reviewer.
Minimum 3 years experience managing security assessment projects and third-party service providers.
Proven ability to manage multiple concurrent security testing engagements in a large, complex organisation.
Working knowledge of VAPT methodologies and standards: OWASP Top 10 and Testing Guide, PTES, NIST SP 800-115, CVSS and MITRE ATT&CK.
Working knowledge of ISO/IEC 27001, NIST CSF, the Malaysia Cyber Security Act 2024 and PDPA 2010.
Proficient in written and spoken Bahasa Malaysia and English, with the ability to produce management-grade reports.
Malaysian citizen, able to pass TNB security screening and execute a Non-Disclosure Agreement.
Mandatory certification - at least one of: CISSP, CISM, CISA, OSCP, GPEN, GWAPT, GXPN, CREST CRT, CCT, or CEH (Practical preferred).