Senior Offensive Security Consultant Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting

Kuala Lumpur

On-site

MYR 240,000 - 360,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

20 days holiday
Hybrid working
Private medical insurance
Life Insurance 4X salary
Parental Support
Maternity leave 26 weeks
Paternity leave 6 weeks
EAP programme

Job summary

S-RM Intelligence and Risk Consulting seeks a Senior Offensive Security Consultant in Kuala Lumpur to lead pentesting engagements across web, API, cloud and infrastructure. You will drive client outcomes, shape delivery approaches, and mentor junior team members while contributing to business development.

The role combines delivery with leadership and a focus on resilience, threat-aware assessments, and practical risk mitigation for clients in Malaysia and beyond.

Qualifications

  • 8+ years’ experience in pentesting and offensive security consulting across multiple areas.
  • Experience with web/API, internal networks, external infra and cloud.
  • Exposure to red team engagements and modern detection/evasion concepts.

Responsibilities

  • Engage with clients to understand cyber security challenges and translate into solutions.
  • Lead proposal writing, deliveries, and pricing discussions; support business expansion.
  • Deliver findings in reports, presentations, and briefings; mentor junior staff.

Skills

Web/API testing
Internal network
Active Directory
External infrastructure
Cloud (AWS/Azure/GCP)
AI security testing
Red Team

Job description

Senior Offensive Security Consultant

We have a new and exciting role for a Senior Offensive Security Consultant in the Cyber Security Team in Kuala Lumpur.

Cyber Security

Kuala Lumpur

Offensive Security consultants run the delivery of our offensive security services. They help to interpret client challenges, innovate solutions, and deliver findings.

As an OS consultant, you will work across the full spectrum of our pentesting services, whether point in time or continuous, as well as participate in larger engagements such as red teams. You will help our clients to build cyber resilience, enhance their understanding of the threat landscape and become better prepared to face dynamic and evolving security risks.

As a senior consultant, you will be responsible for supporting commercial efforts, as well as line management and maintenance of standards, tools and knowledge. We are looking for someone with a strong business acumen and technical background who can help us shape, sell and deliver impactful resilience workstreams to our clients. The commercial and leadership aspect of this role will take approximately 40% of your time, the rest being focused on delivery.

Main duties and responsibilities

Client Engagement and Account Management

  • Engage with clients to understand their cyber security challenges
  • Translate client challenges into solutions that fit S-RM’s Offensive Security service offering and value proposition
  • Lead on proposal writing and presentations, with an understanding of delivery timelines, project resourcing requirements and pricing
  • Contribute to the expansion of client accounts and winning of new business
  • Gain an understanding of S-RM’s target sectors and industries

Offensive Security

Penetration testing:

  • External infrastructure
  • Web application
  • API pentesting
  • Phishing and spear phishing
  • Internal pentesting
  • Mobile application pentesting (Android and iOS)
  • Attack surface scanning and monitoring
  • Cloud assessments and configuration reviews
  • Hardware Build Reviews
  • Support senior team members in the delivery of red team assessments (end to end, breaching the perimeter, assumed breach, bespoke)
  • Red teaming
  • Support senior team members in the delivery of red team assessments (end to end, breaching the perimeter, assumed breach, bespoke)

Delivery:

  • Deliver findings in a range of formats, including written reports, presentations, and verbal briefings

Training:

  • Support the development and delivery of cyber security training packages on a range of topics
  • Deliver client training on phishing/awareness/general cyber topics.
  • Threat Intelligence
  • Keep abreast of threat intelligence developments, threat actor activity and security industry developments in mitigations and tooling

Mentoring and technical leadership

  • Provide oversite, shadowing and knowledge sharing opportunities for pentesting to other team members
  • Participate in monthly knowledge sharing sessions
  • Gain an understanding of our cyber services outside of offensive security (incident response, cyber advisory, digital forensics) and support with offensive security skills where required
  • Identify and address internal capability gaps with the support of senior team members

Requirements

We are looking for an individual who has 8 or more years’ experience in pentesting and offensive security consulting across multiple areas including:

  • Web/API testing
  • Internal network and Active Directory
  • External infrastructure and VA
  • Cloud (AWS/Azure/GCP)
  • AI security testing (nice to have)
  • Red Team assessments and familiarity with modern detection/evasion techniques (nice to have)

Experience:

  • Experience working within security consulting, with good client-facing skills including report writing, briefings and general comms.
  • Experience mentoring or line managing more junior members of a team.

All candidates must have permission to work in Malaysia by the start of their employment.

Our benefits

We offer thoughtful, balanced rewards and supportto help our people do their best work and live their lives outside it, this includes but is not exhaustive of:

  • 20 days holiday per year in addition to bank holidays (+1 day for every year of service up to a maximum of 25 days in total);
  • Hybrid working and flexible working hours;
  • EPF (Employees Provident Fund with a contribution rate of 12% employer & 11% employee;
  • Life Insurance 4X annual salary.
  • Parental Support:
  • Fertility treatment leave – 5 days of leave per cycle of treatment per year;
  • Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay;
  • Paternity leave – 6 weeks of full pay.
  • Various Health and Medical Benefits including:
  • Private dental and medical insurance (taxable benefit) for you and your family;
  • EAP programme for you and your immediate family;
  • Free access to the world-famous mindfulness app

We nurture a culture of equality, diversity and inclusion and we are dedicated to developing a workforce that displays a variety of talents, experiences and perspectives.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity (SOC) Analyst Cyber security Kuala Lumpur
Cybersecurity (SOC) Analyst Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 60,000 - 80,000
20 days paid holiday
Flexible working hours
Pension scheme
+3
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Senior Associate, Incident Response Cyber security Kuala Lumpur
Senior Associate, Incident Response Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
20 days holiday
Flexible working
EPF pension
+4
Senior Penetration Tester
Senior Penetration Tester

FIRMUS • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Junior Security Solutions Consultant
Junior Security Solutions Consultant

UniQ Consulting & Services Sdn Bhd • Petaling Jaya

On-site
MYR 60,000 - 120,000
Associate (Forensics Lead), Incident Response
Associate (Forensics Lead), Incident Response

S-RM • Malaysia

Hybrid
MYR 180,000 - 240,000
20 days paid holiday
Flexible working
EPF (Employees Provident Fund)
+3
Associate (Forensics Lead), Incident Response
Associate (Forensics Lead), Incident Response

S-RM • Kuala Lumpur

Hybrid
MYR 90,000 - 150,000
20 days paid holiday
Flexible working options
Pension scheme
+3
SOC Engineer, Kuala Lumpur Cyber security Kuala Lumpur
SOC Engineer, Kuala Lumpur Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 60,000 - 90,000
20 days paid holiday plus additional leave
Flexible working hours
Pension scheme
+2
Senior Associate, Incident Response
Senior Associate, Incident Response

S-RM • Malaysia

Hybrid
MYR 180,000 - 280,000
20 days paid holiday
Flexible working
EPF pension
+3
Senior Offensive Security Lead: Red Team & Client Growth
Senior Offensive Security Lead: Red Team & Client Growth

S-RM Intelligence and Risk Consulting • Kuala Lumpur

On-site
MYR 240,000 - 360,000
20 days holiday
Hybrid working
Private medical insurance
+5