Security Engineer – Vulnerability Management - VAPT

Ascendion

Cyberjaya

On-site

MYR 60,000 - 120,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jora Malaysia is seeking a hands-on Security Engineer to support the external attack surface management and crowdsourced security programmes, bridging offensive security and enterprise vulnerability management.

You will manually validate vulnerabilities affecting externally exposed applications and systems, reproduce findings, assess exploitability, and coordinate remediation with engineering teams, retesting to confirm fixes.

Qualifications

  • Hands-on experience in vulnerability management, assessment & testing (VAPT).
  • Proven ability to manually validate security vulnerabilities and assess real-world exploitability.
  • Experience with web apps, APIs or external services testing.

Responsibilities

  • Investigate vulnerabilities affecting externally exposed applications, infrastructure and services.
  • Manually reproduce reported vulnerabilities and determine their real-world exploitability.
  • Perform vulnerability assessment and penetration testing using tools such as Burp Suite, Nmap, cURL or equivalent security tools.
  • Conduct reconnaissance, service fingerprinting and hands-on web/application security testing.
  • Prioritise vulnerabilities based on exploitability, exposure, severity and potential business impact.
  • Validate findings submitted through crowdsourced security and vulnerability disclosure programmes.
  • Work with application, infrastructure and security teams to explain findings and agree practical remediation actions.
  • Track vulnerabilities through remediation and independently verify that fixes have resolved the issue.
  • Monitor vulnerability trends, outstanding findings and remediation progress.

Skills

Vulnerability management
VAPT
Security testing
Burp Suite
Nmap
cURL
Exploitation assessment
Cross-team collaboration

Tools

Burp Suite
Nmap
cURL

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

Security Engineer – Vulnerability Management - VAPT
  • We’re looking for a hands‑on security engineer to support the external attack surface management and crowdsourced security programmes.
  • This role sits between offensive security and enterprise vulnerability management.
  • You’ll manually validate vulnerabilities affecting externally exposed applications and systems—including findings submitted by security researchers—and stay involved through risk assessment, remediation and retesting.
  • If you enjoy understanding whether a vulnerability is genuinely exploitable rather than simply reviewing scanner results, this could be a strong fit.
Responsibilities
  • Investigate vulnerabilities affecting externally exposed applications, infrastructure and services.
  • Manually reproduce reported vulnerabilities and determine their real‑world exploitability.
  • Perform vulnerability assessment and penetration testing using tools such as Burp Suite, Nmap, cURL or equivalent security tools.
  • Conduct reconnaissance, service fingerprinting and hands‑on web/application security testing.
  • Prioritise vulnerabilities based on exploitability, exposure, severity and potential business impact.
  • Validate findings submitted through crowdsourced security and vulnerability disclosure programmes.
  • Work with application, infrastructure and security teams to explain findings and agree practical remediation actions.
  • Track vulnerabilities through remediation and independently verify that fixes have resolved the issue.
  • Monitor vulnerability trends, outstanding findings and remediation progress.
Required Skills
  • Relevant experience from areas such as vulnerability management, vulnerability assessment & penetration testing (VAPT), application security/appSec, penetration testing, offensive security, product security, and attack surface management.
  • Security certifications such as OSCP, eJPT, CISSP, GSEC, Security+ or CEH are preferred.
  • The key requirement is demonstrated experience personally investigating and validating security vulnerabilities.
  • Hands‑on vulnerability assessment and security testing and using tools such as Burp Suite, Nmap, cURL or comparable tools.
  • Manually reproducing vulnerabilities and confirming whether reported issues are exploitable.
  • Working with application and infrastructure teams to move vulnerabilities from identification through remediation and retesting.
  • Experience testing web applications, APIs or externally exposed services will be particularly relevant.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability Management & VAPT
Security Engineer - Vulnerability Management & VAPT

Ascendion • Cyberjaya

On-site
MYR 60,000 - 120,000
Application Security Engineer
Application Security Engineer

Puresoftware • Kuala Lumpur

On-site
MYR 90,000 - 180,000
Security Engineer – Vulnerability Management & VAPT
Security Engineer – Vulnerability Management & VAPT

Ascendion • Cyberjaya

On-site
MYR 120,000 - 180,000
Penetration Tester (Security)
Penetration Tester (Security)

VeecoTech • Bayan Lepas

On-site
MYR 60,000 - 100,000
Travel for on-site assessments
On-site security assessments
Cyber Security Project Analyst
Cyber Security Project Analyst

Golden Agri-Resources • Selangor

On-site
MYR 60,000 - 90,000
Network Security Engineer
Network Security Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Information Security Engineer
Information Security Engineer

Carsome • Selangor

On-site
MYR 180,000 - 260,000
Dental insurance
Health insurance
Maternity leave
+3
Cybersecurity Engineer
Cybersecurity Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Principal Security Consultant (Penetration Tester)
Principal Security Consultant (Penetration Tester)

Sysarmy • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Engineer
Security Engineer

Job Search Asia • Petaling Jaya

On-site
MYR 90,000 - 150,000
EPF
SOCSO
EIS