Security Engineer – Vulnerability Management & VAPT

Ascendion

Cyberjaya

On-site

MYR 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ascendion is seeking a hands-on security engineer to support external attack surface management and crowdsourced security programmes. You will manually validate vulnerabilities affecting externally exposed applications and systems, and stay involved through risk assessment, remediation and retesting.

If you enjoy determining real-world exploitability rather than just reviewing scanner results, this role offers meaningful impact across security and engineering teams in a fast-moving environment.

Qualifications

  • Hands-on vulnerability assessment & testing across web apps and APIs.
  • Ability to reproduce vulnerabilities and verify exploitability.
  • Experience with vulnerability disclosure programmes preferred.
  • Collaborates with teams to drive remediation and retesting.

Responsibilities

  • Investigate vulnerabilities affecting externally exposed applications, infrastructure and services.
  • Manually reproduce reported vulnerabilities and determine real-world exploitability.
  • Perform vulnerability assessment and penetration testing using tools such as Burp Suite, Nmap, cURL or equivalent security tools.
  • Conduct reconnaissance, service fingerprinting and hands-on web/application security testing.
  • Prioritise vulnerabilities based on exploitability, exposure, severity and potential business impact.
  • Validate findings through crowdsourced security programmes.
  • Explain findings to application and security teams and agree remediation actions.
  • Track vulnerabilities through remediation and retesting.
  • Monitor vulnerability trends and remediation progress.

Skills

VAPT
Vulnerability validation
Burp Suite
Nmap
cURL
Web security testing

Tools

Burp Suite
Nmap
cURL

Job description

  • We're looking for a hands-on security engineer to support the external attack surface management and crowdsourced security programmes.
  • This role sits between offensive security and enterprise vulnerability management.
  • You’ll manually validate vulnerabilities affecting externally exposed applications and systems—including findings submitted by security researchers—and stay involved through risk assessment, remediation and retesting.
  • If you enjoy understanding whether a vulnerability is genuinely exploitable rather than simply reviewing scanner results, this could be a strong fit.
Responsibilities
  • Investigate vulnerabilities affecting externally exposed applications, infrastructure and services.
  • Manually reproduce reported vulnerabilities and determine their real-world exploitability.
  • Perform vulnerability assessment and penetration testing using tools such as Burp Suite, Nmap, cURL or equivalent security tools.
  • Conduct reconnaissance, service fingerprinting and hands-on web/application security testing.
  • Prioritise vulnerabilities based on exploitability, exposure, severity and potential business impact.
  • Validate findings submitted through crowdsourced security and vulnerability disclosure programmes.
  • Work with application, infrastructure and security teams to explain findings and agree practical remediation actions.
  • Track vulnerabilities through remediation and independently verify that fixes have resolved the issue.
  • Monitor vulnerability trends, outstanding findings and remediation progress.
Required Skills
  • Relevant experience from areas such as vulnerability management, vulnerability assessment & penetration testing (VAPT), application security/appSec, penetration testing, offensive security, product security, and attack surface management.
  • Security certifications such as OSCP, eJPT, CISSP, GSEC, Security+ or CEH are preferred.
  • Experience with vulnerability disclosure programmes and processes, including exposure to platforms such as Synack, HackerOne, or Bugcrowd, is preferred.
  • The key requirement is demonstrated experience personally investigating and validating security vulnerabilities.
  • Hands-on vulnerability assessment and security testing and using tools such as Burp Suite, Nmap, cURL or comparable tools.
  • Manually reproducing vulnerabilities and confirming whether reported issues are exploitable.
  • Working with application and infrastructure teams to move vulnerabilities from identification through remediation and retesting.
  • Experience testing web applications, APIs or externally exposed services will be particularly relevant.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer – Vulnerability Management - VAPT
Security Engineer – Vulnerability Management - VAPT

Ascendion • Cyberjaya

On-site
MYR 60,000 - 120,000
VAPT Security Engineer: Exploitability & Remediation
VAPT Security Engineer: Exploitability & Remediation

Ascendion • Cyberjaya

On-site
MYR 120,000 - 180,000
Security Engineer - Vulnerability Management & VAPT
Security Engineer - Vulnerability Management & VAPT

Ascendion • Cyberjaya

On-site
MYR 60,000 - 120,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 60,000 - 120,000
Senior Pentester
Senior Pentester

Ensign InfoSecurity • Selangor

On-site
MYR 159,000 - 279,000
Security Engineer - Vulnerability & Exposure Management
Security Engineer - Vulnerability & Exposure Management

Roche • Petaling Jaya

On-site
MYR 70,000 - 100,000
Cyber Defense Lead
Cyber Defense Lead

Hong Leong Bank Berhad • Selangor

On-site
MYR 120,000 - 160,000
Senior Penetration Tester
Senior Penetration Tester

Ensign InfoSecurity • Petaling Jaya

On-site
MYR 120,000 - 180,000
Security Engineer - Vulnerability & Exposure Management
Security Engineer - Vulnerability & Exposure Management

F. Hoffmann-La Roche AG • Petaling Jaya

On-site
MYR 70,000 - 100,000
Information Technology Security Specialist
Information Technology Security Specialist

Pride Global • Kuala Lumpur

On-site
MYR 120,000 - 160,000