company-logo-image

Penetration Test Engineer

ashley-avatar-image

AI-generated summary

beta

This job is a Penetration Test Engineer, where you’ll test and enhance security for apps and systems. You might like this job because you'll work with diverse teams, tackle real risks, and help secure technology in exciting ways!

RM 5500 - RM 7000

Kota Damansara, Selangor

Job Description

The Role

As a Penetration Test Engineer at Section, you will design and execute security testing strategies across applications, APIs, infrastructure, and cloud environments, integrating tightly with engineering squads and platform teams. The role blends hands-on pen testing with security architecture guidance, secure SDLC enablement, and automation that elevates security posture at scale. Success looks like measurable risk reduction, faster secure releases, and a culture of continuous security improvement across distributed, multicultural teams in Southeast Asia and beyond.


Job Description and Responsibilities

Own the penetration testing lifecycle

● Plan, scope, and execute black/grey/white-box tests for web, mobile, microservices, and APIs.

● Perform secure code reviews in partnership with engineering leads.

Integrate security into DevSecOps

● Embed automated security testing into CI/CD (SAST/DAST/IAST/SCA), define gates, and tune pipelines for low false positives.

● Build and maintain reusable scripts, playbooks, and baselines for continuous security checks.


Findings management and remediation

● Produce clear, prioritized reports with reproduction steps, exploit details, and business risk context.

● Partner with developers to reproduce issues, validate fixes, and drive root-cause remediation.

Compliance and governance

● Support security audits, client assessments, and evidence collection.

● Map findings to frameworks and best practices (OWASP ASVS, Top 10, MAS TRM, CIS Benchmarks, NIST CSF).


Job Requirements

Experience

● 2–4 years in offensive security, penetration testing, including hands-on application and cloud testing.

● Proven experience embedding security in agile delivery and CI/CD environments.

Technical skills

● Strong in web/app/API testing: authentication/authorization flaws, injection, deserialization, SSRF, IDOR, XSS, etc.

● Cloud and infrastructure: Cloud security (IAM, network segmentation, key/secret management), containers/Kubernetes fundamentals.

● Proficiency with tools and frameworks: Burp Suite Pro, Nmap, Metasploit, Postman, SQLMap, Hydra, PowerShell/Bash/Python, Git.

● Familiarity with SAST/DAST/IAST/SCA tools and integrating them into CI/CD.

Education and Credentials

● Bachelor’s degree in Computer Science, Information Security, or related field; equivalent experience considered.

Preferred Qualifications

Certifications: 

● OSCP strongly preferred; OSWE, OSEP, OSWA , GXPN, GPEN, or similar are advantageous.

Experience with:

● E-commerce, fintech, public sector, or regulated environments (e.g., MAS TRM, PCI DSS).

● Data security for analytics platforms and warehouses (Snowflake governance, masking, RBAC, data exfiltration testing).

● Kubernetes security and supply chain security (SBOM, SLSA).

● Building security automation and custom tooling;

● Performing vulnerability prioritization using the CVSS framework to accurately evaluate the severity and business impact of security findings.


Skills

Cybersecurity Threat Identification
Penetration Testing
Application Security
Cloud Security
DevSecOps
Vulnerability Assessments

Company Benefits

Medical Expenses

We provide medical expenses available for claims because your health is the most important!

Career Path

We believe in a never-ending cycle of learning, and we'll provide trainings and design a career progression for you.

Flexible Hours

Our hours are incredibly flexible, but our main focus is being productive during working hours! We sometimes work from home too.

Stocked Pantry

Happy tummy = happy employees. We make sure our pantry's always stocked up. We have a beanbag for nap time too!

Work-life Balance

We believe in having work life balance, no matter what you do. Who says you can't do good work, and have a social life too?


Additional Info

Company Activity

Last active - few hours ago

Career Level

Senior Executive


Company Profile

Gravitas Digital-logo-image

Gravitas Digital

Gravitas Digital - a little Digital Marketing consultancy recently established with a clear mission of - doing good work. We want to empower and revolutionise access to digital solutions.Here are some of the services we offer: Strategy and Planning Website Development Social Media Management Performance Marketing Hit us up, and we'll talk more!hr@gravitas.my