Search by job, company or skills

8-15 Years
MYR 9,000 - 10,000 per month
Quick Apply
  • Posted 9 hours ago
  • Be among the first 10 applicants

Job Description

The Resident Engineer shall provide dedicated, on-site programme management for TNB's enterprise-wide Vulnerability Assessment and Penetration Testing (VAPT) programme. The role is management and governance focused, with sufficient technical depth to review and challenge test results. 

The Resident Engineer acts as the single point of coordination between TNB system owners, internal security teams and appointed VAPT service providers, and is accountable for ensuring all VAPT engagements are planned, executed, reported and closed in a consistent and auditable manner. 

Key Responsibilities

• Develop and maintain the annual VAPT plan and testing calendar covering IT, cloud, application and network assets, prioritised on a risk basis. 

• Receive, scope and prioritise VAPT requests from business units and system owners, and prepare the rules of engagement, test authorisation and approvals for each engagement. 

• Verify pre-test readiness environment, test accounts, rollback plans and safe-testing controls, particularly for production and OT systems. 

• Coordinate and monitor day-to-day execution of multiple concurrent engagements across appointed service providers. 

• Perform quality assurance review of all VAPT reports, including technical accuracy, evidence sufficiency, risk rating consistency and false-positive validation. 

• Maintain a central findings register and drive remediation with system owners against TNB's remediation SLA by severity. 

• Coordinate retesting and formal closure of remediated findings, and administer the risk acceptance and exception process. 

• Produce monthly programme reports and quarterly management dashboards, including KPIs, trend analysis and recurring root causes. 

• Support internal audit, external audit and regulatory requirements by providing VAPT evidence and status. 

• Manage the day-to-day performance of appointed VAPT service providers and verify deliverables against contracted scope.

• Maintain and continuously improve TNB's VAPT policy, methodology, templates and standard operating procedures. 

Requirements

• Bachelor's Degree in Computer Science, Information Technology, Engineering, Cyber Security or equivalent. 

• Minimum [8] years working experience in ICT, of which minimum [5] years in cyber security. 

• Minimum [3] years hands-on experience in VAPT delivery as a tester, team lead or technical reviewer. 

• Minimum [3] years experience managing security assessment projects and third-party service providers. 

• Proven ability to manage multiple concurrent security testing engagements in a large, complex organisation. 

• Working knowledge of VAPT methodologies and standards: OWASP Top 10 and Testing Guide, PTES, NIST SP 800-115, CVSS and MITRE ATT&CK. 

• Working knowledge of ISO/IEC 27001, NIST CSF, the Malaysia Cyber Security Act 2024 and PDPA 2010. 

• Proficient in written and spoken Bahasa Malaysia and English, with the ability to produce management-grade reports. 

• Malaysian citizen, able to pass TNB security screening and execute a Non-Disclosure Agreement. 

Certification:

Mandatory — at least one (1) of the following: 

• CISSP, CISM or CISA 

• OSCP, GPEN, GWAPT or GXPN 

• CREST CRT / CCT, or CEH (Practical preferred) 

Added advantage: 

• Project management — PMP or PRINCE2 Practitioner 

• OT / ICS security — GICSP or IEC 62443 Cyber Security Practitioner 

• ISO/IEC 27001 Lead Implementer or Lead Auditor 

• Prior experience in utilities, energy, oil and gas, or other Critical National Information Infrastructure (CNII) sectors. 

• Exposure to OT / ICS environments (SCADA, DCS, PLC, RTU) and the constraints of testing live control systems.

Deliverables:

• Annual VAPT plan and testing calendar. 

• VAPT governance pack — policy, methodology, templates and SOP 

• Scoping and authorisation documents for each engagement. 

• Quality-assured VAPT reports for each engagement. 

• Central findings register, maintained and current at all times. 

• Monthly programme status report and quarterly management dashboard. 

• Audit and regulatory evidence pack, on demand. 

More Info

Job Type:
Function:
Employment Type:

Job ID: 153102033

Similar Jobs

Kuala Lumpur

Skills:

VaptVulnerability AssessmentVulnerability ManagementPenetration TestingDASTPen testingSAST

Beware of Scammers

We don’t charge money for job offers