Enable job alerts via email!
A leading industrial automation company in Kuala Lumpur is seeking a Security Analyst & Penetration Tester. The ideal candidate will have a strong background in penetration testing and vulnerability assessments, preferably with CREST certification. This role offers a competitive salary, flexible working hours, and opportunities for advanced training and certification renewals.
Security Analyst & Penetration Tester (CREST-Certified Preferred)
Conduct technical penetration tests across web applications, mobile apps, APIs, internal/external networks, and cloud environments (AWS, Azure, GCP).
Perform vulnerability assessments and red teaming exercises for clients in financial services, healthcare, and critical infrastructure.
Deliver detailed, actionable reports with risk ratings, technical findings, remediation guidance, and executive summaries.
Support the development of our automated security validation platform by feeding real-world attack patterns into detection logic.
Participate in incident response engagements and post-breach forensic analysis as needed.
Collaborate with developers and DevOps teams to embed secure practices (Shift-Left Security).
Maintain up-to-date knowledge of the latest attack vectors (e.g., OWASP Top 10, MITRE ATT&CK) and defensive countermeasures.
Assist in achieving and maintaining compliance with standards such as ISO 27001, SOC 2, PDPA, and MAS TRM.
Mentor junior analysts and contribute to internal security research and tooling.
Required Qualifications & Skills
Preferred Attributes
We take quality seriously. Shortlisted candidates will undergo:
Note: All candidates must pass a background check. Prior consultancy or MSSP experience is advantageous.