Senior Security Penetration Tester
BAE
- Kuala Lumpur
- Permanent
- Full-time
- Delivery of end-to-end security testing engagements, including scoping and client wash-up meetings.
- Performing a wide range of security testing types such as web application, infrastructure and objective based/red teaming.
- Production of detailed reporting and presentations for both technical and non-technical stakeholders.
- Safe and responsible use of testing tools, ensuring controls are in place to limit risks during customer engagements.
- Developing improvements in terms of scripts, tools, or techniques to enhance the Security Testing team's capabilities.
- Maintaining an up-to-date knowledge of information security issues, continuously learning about new technologies, methodologies, and techniques.
- Knowledge sharing with colleagues in other teams, such as Threat Intelligence, Incident Response, and the wider Security Consulting community.
- Assist and support team members in troubleshooting complex technical issues, reviewing vulnerability findings, and validating penetration test results to uphold high standards of accuracy, consistency, and reporting quality.
- We are looking for those with a passion for cybersecurity. Those who contribute to cybersecurity related blogs, engage in vulnerability research/bug bounties or other community related events will be looked at favourably
- Experience in common offensive penetration testing domains such as testing of web applications, infrastructure and red teaming. Experience with wireless and mobile testing also an advantage.
- Evidenced skills through industry recognised certifications such OSCP, CREST or CRTO
- Confident communicator with excellent spoken and written English communication skills
- Experience using common industry tools such as Kali Linux, Nessus & Burpsuite
- Knowledge of C2 frameworks such as Cobalt Strike
- Threat hunting or compromised assessment experience
- You’ll have a dedicated line Manager to help you develop your career and guide you on your journey through BAE Systems Digital Intelligence
- We will support your personal training and development in the areas of cybersecurity by sponsoring training courses and certification exams (i.e OSCP, CREST, CRTO)
- Work-life balance is important; you’ll get 18 days holiday a year (increases to 21 after 5 years’ service)
- We support hybrid working and give flexibility for teams to decide on the balance between remote and office-based working
- Our benefits package includes private family medical cover, maternity (4 months), paternity (2 weeks), study leave & a Optical/Dental/Health screening allowance
- You’ll be part of our annual bonus and share award scheme