company-logo-image

Senior Pentester

ashley-avatar-image

AI-generated summary

beta

This job is for a Senior Pentester at Ensign. You might like this job because you’ll simulate cyberattacks and uncover security weaknesses in apps and networks, helping protect valuable data using the latest tools in a dynamic environment.

Undisclosed

Malaysia (Selangor), Kuala Lumpur

Job Description

Ensign is hiring !

Key Responsibilities
 

1. Penetration Testing & Security Assessments

  • Conduct penetration testing on:

    • Web applications (OWASP Top 10)

    • Mobile applications (iOS / Android)

    • Internal and external networks

    • APIs and web services

    • Cloud environments (AWS, Azure, GCP)

  • Perform vulnerability assessments using automated and manual techniques.

  • Simulate real-world attack scenarios including privilege escalation and lateral movement.
     

2. Exploitation & Validation

  • Identify and exploit security weaknesses in systems and applications.

  • Develop proof-of-concept (PoC) exploits to validate findings.

  • Assess impact and risk severity of vulnerabilities discovered.
     

3. Reporting & Documentation

  • Prepare detailed penetration testing reports including:

    • Executive summary

    • Technical findings

    • Risk ratings

    • Remediation recommendations

  • Present findings to technical teams and management.

  • Provide remediation validation (retest) services.
     

4. Tools & Techniques

  • Utilize industry tools such as:

    • Burp Suite

    • Metasploit

    • Nmap

    • Nessus / OpenVAS

    • Wireshark

    • SQLmap

    • Kali Linux toolsets

  • Develop custom scripts (Python, Bash, PowerShell) where necessary.

  • Stay updated on latest attack techniques, CVEs, and threat trends.
     

5. Compliance & Standards

  • Conduct testing aligned with:

    • OWASP Testing Guide

    • PTES (Penetration Testing Execution Standard)

    • NIST frameworks

    • ISO 27001 controls

  • Support compliance-driven assessments (e.g., PCI-DSS).
     

Requirements

  • Bachelor’s Degree in Cybersecurity, Computer Science, IT, or related field.

Experience

  • 2–5 years of experience in penetration testing or offensive security.

  • Hands-on experience conducting web and network penetration tests.

  • Experience preparing formal penetration testing reports.

(Senior level: 5+ years with leadership or project ownership experience.)


Job Requirements


Company Benefits

Health Benefits

Medical insurance for employees and dependents.

On-Site Meals and Snacks

Ensiders are served free bento sets every Monday and Friday.

On-Site Fitness Centre

Sweat it out in our own indoor gym, within a few walking steps from your office space.

Teach@Ensign / Brown Bag Sessions

Dive deeper into a variety of topics at Ensign’s regular knowledge-sharing sessions, taught by Ensign’s very own staff.

E-Learning Platform

Expand your knowledge in a wide range of subjects including cloud, cyber, and other technology-related courses.


Additional Info

Company Activity

Last active - 1 week ago

Job Specialisation


Company Profile

Ensign Infosecurity (Malaysia)-logo-image

Ensign Infosecurity (Malaysia)

Ensign InfoSecurity, one of Asia’s largest pure play cyber security firms, formed as a result of a joint venture (JV) between Temasek and StarHub. Certis’s cyber security arm, Quann will be merged with StarHub’s Centre of Excellence and fully owned subsidiary, Accel Systems & Technologies Pte Ltd (ASTL). Quann, formerly known as e-Cop, is a Singapore-based cyber security services provider since 2000. The company...
Upload Resume