Cyber Security Consultant
Cyber Security Consultant
abeam consulting malaysia1-2 Years
- Posted 7 hours ago
- Be among the first 10 applicants
Job Description
Key Responsibilities
- Perform Vulnerability Assessment and Penetration Testing (VAPT) for internal and external infrastructure, servers, endpoints, network devices, web applications, and cloud environments.
- Conduct asset discovery, service enumeration, vulnerability scanning, manual validation, exploitation testing, and security configuration assessments within the approved scope.
- Validate identified vulnerabilities to minimize false positives and determine actual security impact and associated risk.
- Perform penetration testing activities using appropriate tools and methodologies while adhering to client-approved Rules of Engagement (RoE).
- Analyze vulnerabilities and map findings to relevant standards and references such as CVSS, CWE, OWASP, and MITRE ATT&CK, where applicable.
- Prepare professional technical VAPT reports, executive summaries, vulnerability registers, assessment checklists, and supporting evidence.
- Present assessment results to technical teams, management, and client stakeholders, clearly communicating identified risks and recommended remediation.
- Provide post-assessment remediation support, including clarification of findings, remediation recommendations, evidence review, vulnerability re-scanning, and revalidation.
- Work closely with infrastructure, network, cloud, application, and security teams to support effective vulnerability remediation.
- Support cybersecurity presales activities including scope clarification, effort estimation, technical proposal preparation, and client discussions when required.
- Continuously research emerging vulnerabilities, attack techniques, security tools, and industry cybersecurity trends.
- Develop additional capabilities in OT/ICS security assessment, cloud security assessment, red teaming, and security configuration review based on business and project needs.
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, Information Technology, Networking, or a related field.
- Knowledge or hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).
- Good understanding of TCP/IP, network protocols, Windows/Linux environments, Active Directory, web technologies, and common security vulnerabilities.
- Experience or familiarity with security assessment tools such as Nmap, Nessus, Burp Suite, Metasploit, Nikto, Nuclei, Wireshark, Kali Linux, or equivalent tools.
- Understanding of common vulnerability categories including OWASP Top 10, insecure configurations, outdated software, authentication weaknesses, network/service exposure, and access-control issues.
- Ability to perform manual vulnerability validation and distinguish exploitable security issues from scanner-generated false positives.
- Basic scripting or automation knowledge using Python, PowerShell, Bash, or equivalent is an advantage.
- Ability to prepare clear technical documentation, assessment evidence, and professional cybersecurity reports.
- Strong analytical and troubleshooting skills with willingness to continuously learn new security technologies and attack techniques.
- Good verbal and written communication skills and ability to coordinate with technical and non-technical stakeholders.
- Business-level proficiency in English and Malay is mandatory; proficiency in other languages is an advantage for stakeholder communication in multinational environments.
Preferred Qualifications
- Certifications: CompTIA Security+, ISC2 Certified in Cybersecurity (CC), CEH, or equivalent entry-level cybersecurity certifications are an advantage.
- Hands-on experience conducting infrastructure, network, web application, or cloud security assessments.
- Knowledge of Active Directory security assessment and common attack techniques is an advantage.
- Exposure to AWS, Azure, or other cloud security assessments is an advantage.
- Exposure to OT/ICS environments and OT security concepts is an advantage; candidates with a strong willingness to develop OT security capabilities are also encouraged.
- Knowledge of vulnerability remediation, system hardening, patch management, and security configuration improvement is advantageous.
- Experience supporting re-scanning/revalidation and remediation discussions with clients is preferred.
- Willingness to travel or work at client sites when required for cybersecurity assessment activities.
- Ability to work independently as well as collaboratively within cybersecurity and cross-functional project teams.
- Fresh graduates are encouraged to apply; candidates with 1–2 years of relevant cybersecurity or VAPT experience will be an added advantage.
- Fresh graduates with Final Year Projects (FYP) related to OT/ICS cybersecurity, AI-driven cybersecurity automation, AI agents for security operations, or other relevant cybersecurity areas are highly encouraged to apply.
More Info
Key Skills
Linux environments
Vulnerability Assessment and Penetration Testing (VAPT)
Nuclei
Nikto
OT ICS security assessment
Security configuration review
Cloud security assessment

