jobs in Ascendion

Full Time Security Engineer – Vulnerability Management - VAPT Jobs, in Ascendion Selangor - Maukerja

Security Engineer – Vulnerability Management - VAPT

Ascendion

Share
Save

Working Location

  • Cyberjaya Selangor Malaysia

Job Description

Responsibilities


Role:

  • We’re looking for a hands-on security engineer to support the external attack surface management and crowdsourced security programmes.
  • This role sits between offensive security and enterprise vulnerability management.
  • You’ll manually validate vulnerabilities affecting externally exposed applications and systems—including findings submitted by security researchers—and stay involved through risk assessment, remediation and retesting.
  • If you enjoy understanding whether a vulnerability is genuinely exploitable rather than simply reviewing scanner results, this could be a strong fit.


Responsibilities:

  • Investigate vulnerabilities affecting externally exposed applications, infrastructure and services.
  • Manually reproduce reported vulnerabilities and determine their real-world exploitability.
  • Perform vulnerability assessment and penetration testing using tools such as Burp Suite, Nmap, cURL or equivalent security tools.
  • Conduct reconnaissance, service fingerprinting and hands-on web/application security testing.
  • Prioritise vulnerabilities based on exploitability, exposure, severity and potential business impact.
  • Validate findings submitted through crowdsourced security and vulnerability disclosure programmes.
  • Work with application, infrastructure and security teams to explain findings and agree practical remediation actions.
  • Track vulnerabilities through remediation and independently verify that fixes have resolved the issue.
  • Monitor vulnerability trends, outstanding findings and remediation progress.


Required Skills:

  • Relevant experience from areas such as vulnerability management, vulnerability assessment & penetration testing (VAPT), application security/appSec, penetration testing, offensive security, product security, and attack surface management.
  • Security certifications such as OSCP, eJPT, CISSP, GSEC, Security+ or CEH are preferred.
  • The key requirement is demonstrated experience personally investigating and validating security vulnerabilities.
  • Hands-on vulnerability assessment and security testing and using tools such as Burp Suite, Nmap, cURL or comparable tools.
  • Manually reproducing vulnerabilities and confirming whether reported issues are exploitable.
  • Working with application and infrastructure teams to move vulnerabilities from identification through remediation and retesting.
  • Experience testing web applications, APIs or externally exposed services will be particularly relevant.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More