Search Jobs

Search by job, company or skills

Cyber Security Consultant
  • Posted 7 hours ago
  • Be among the first 10 applicants

Job Description

Key Responsibilities

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for internal and external infrastructure, servers, endpoints, network devices, web applications, and cloud environments.
  • Conduct asset discovery, service enumeration, vulnerability scanning, manual validation, exploitation testing, and security configuration assessments within the approved scope.
  • Validate identified vulnerabilities to minimize false positives and determine actual security impact and associated risk.
  • Perform penetration testing activities using appropriate tools and methodologies while adhering to client-approved Rules of Engagement (RoE).
  • Analyze vulnerabilities and map findings to relevant standards and references such as CVSS, CWE, OWASP, and MITRE ATT&CK, where applicable.
  • Prepare professional technical VAPT reports, executive summaries, vulnerability registers, assessment checklists, and supporting evidence.
  • Present assessment results to technical teams, management, and client stakeholders, clearly communicating identified risks and recommended remediation.
  • Provide post-assessment remediation support, including clarification of findings, remediation recommendations, evidence review, vulnerability re-scanning, and revalidation.
  • Work closely with infrastructure, network, cloud, application, and security teams to support effective vulnerability remediation.
  • Support cybersecurity presales activities including scope clarification, effort estimation, technical proposal preparation, and client discussions when required.
  • Continuously research emerging vulnerabilities, attack techniques, security tools, and industry cybersecurity trends.
  • Develop additional capabilities in OT/ICS security assessment, cloud security assessment, red teaming, and security configuration review based on business and project needs.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, Information Technology, Networking, or a related field.
  • Knowledge or hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).
  • Good understanding of TCP/IP, network protocols, Windows/Linux environments, Active Directory, web technologies, and common security vulnerabilities.
  • Experience or familiarity with security assessment tools such as Nmap, Nessus, Burp Suite, Metasploit, Nikto, Nuclei, Wireshark, Kali Linux, or equivalent tools.
  • Understanding of common vulnerability categories including OWASP Top 10, insecure configurations, outdated software, authentication weaknesses, network/service exposure, and access-control issues.
  • Ability to perform manual vulnerability validation and distinguish exploitable security issues from scanner-generated false positives.
  • Basic scripting or automation knowledge using Python, PowerShell, Bash, or equivalent is an advantage.
  • Ability to prepare clear technical documentation, assessment evidence, and professional cybersecurity reports.
  • Strong analytical and troubleshooting skills with willingness to continuously learn new security technologies and attack techniques.
  • Good verbal and written communication skills and ability to coordinate with technical and non-technical stakeholders.
  • Business-level proficiency in English and Malay is mandatory; proficiency in other languages is an advantage for stakeholder communication in multinational environments.

Preferred Qualifications

  • Certifications: CompTIA Security+, ISC2 Certified in Cybersecurity (CC), CEH, or equivalent entry-level cybersecurity certifications are an advantage.
  • Hands-on experience conducting infrastructure, network, web application, or cloud security assessments.
  • Knowledge of Active Directory security assessment and common attack techniques is an advantage.
  • Exposure to AWS, Azure, or other cloud security assessments is an advantage.
  • Exposure to OT/ICS environments and OT security concepts is an advantage; candidates with a strong willingness to develop OT security capabilities are also encouraged.
  • Knowledge of vulnerability remediation, system hardening, patch management, and security configuration improvement is advantageous.
  • Experience supporting re-scanning/revalidation and remediation discussions with clients is preferred.
  • Willingness to travel or work at client sites when required for cybersecurity assessment activities.
  • Ability to work independently as well as collaboratively within cybersecurity and cross-functional project teams.
  • Fresh graduates are encouraged to apply; candidates with 1–2 years of relevant cybersecurity or VAPT experience will be an added advantage.
  • Fresh graduates with Final Year Projects (FYP) related to OT/ICS cybersecurity, AI-driven cybersecurity automation, AI agents for security operations, or other relevant cybersecurity areas are highly encouraged to apply.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Linux environments

Vulnerability Assessment and Penetration Testing (VAPT)

Nuclei

Nikto

OT ICS security assessment

Security configuration review

Cloud security assessment

Similar Jobs

Malaysia, Selangor, Subang Jaya
Skills:
Vulnerability ManagementCloud SecuritySocWindowsIncident ResponsePenetration TestingDevSecOpsThreat HuntingIso 27001Linux SecurityAzure AdSiemKubernetesSecurity AuditsActive DirectoryEDRRisk Compliance