jobs in MIMOS Network Sdn Bhd

Kerja Sepenuh Masa, Security Engineer di MIMOS Network Federal Territory - Maukerja

Security Engineer

MIMOS Network Sdn Bhd

KL City, Federal Territory

Kongsi
Simpan

Lokasi Kerja

  • Jalan Merah Caga Kuala Lumpur Federal Territory Malaysia

Penerangan Kerja

Tanggungjawab

Role Purpose

The Security Engineer is responsible for the hands-on delivery of penetration testing and other security testing services offered by MNSB to government and enterprise clients, alongside supporting security-related activities under MNSB's IV&V and DQA engagements.

Reporting to the Head of Technical, this is a senior, execution-focused role: the incumbent is expected to personally conduct vulnerability assessments, exploitation testing and security reviews — not solely oversee or direct such work through others. The role is central to MNSB's ability to offer penetration testing as a licensed service under the National Cyber Security Agency's (NACSA) Cyber Security Services (Licensing) Regulations 2024, and carries direct responsibility for ensuring every engagement is conducted within the authorised scope, licensing conditions and consent requirements set out under that framework.

Key Responsibilities

1. Vulnerability Assessment & Penetration Testing (VAPT) Execution

  • Conduct end-to-end VAPT engagements, combining systematic vulnerability identification with controlled exploitation to validate real-world risk.
  • Personally plan, execute and report on penetration tests for client systems, networks and applications, including vulnerability identification and controlled exploitation to demonstrate real-world impact.
  • Conduct other relevant security testing activities as required by engagements, including configuration and hardening reviews, security code review, and threat modelling.
  • Conduct holistic Security Posture Assessments for clients, evaluating overall security maturity across technical controls, policies and processes beyond individual vulnerability findings.
  • Design test plans and methodologies appropriate to each engagement's scope, client environment and risk profile.
  • Produce clear, evidence-based findings reports suitable for both technical remediation teams and client/executive stakeholders.
  • Verify remediation of identified vulnerabilities through retesting where required by the engagement scope.

2. Licensing, Consent & Compliance

  • Ensure every penetration testing or security testing engagement is backed by explicit written client authorisation defining scope and boundaries before any testing activity begins, in line with NACSA requirements.
  • Operate within the conditions of MNSB's NACSA penetration testing services licence, and support the Head of Technical in maintaining compliance with licence conditions, including accurate record-keeping.
  • Maintain complete and auditable service records for each engagement, retained in line with NACSA's record-keeping requirements.
  • Flag any scope ambiguity, unauthorised access risk, or compliance concern to the Head of Technical before proceeding with testing activity.

3. IV&V / DQA Integration

  • Support MNSB's broader IV&V and DQA engagements by contributing security-testing perspective where client scope requires it.
  • Work with test and delivery teams to integrate security testing checkpoints into the wider assurance lifecycle without compromising independence of findings.

4. Reporting & Continuous Improvement

  • Provide regular updates to the Head of Technical on engagement progress, findings and any emerging risk or compliance issues.
  • Stay current on emerging vulnerabilities, attack techniques and security testing tools, and recommend improvements to MNSB's security testing methodology.
  • Contribute to building MNSB's internal security testing capability and documentation as the service line matures.

5. Additional Responsibilities

  • The Security Engineer may, from time to time, be assigned additional responsibilities by the Head of Technical and Management that are aligned with the role's mandate or required to support MNSB's strategic, operational or service-delivery objectives.
  • Complying with department guidelines and company policies and procedures.

Key Competencies and Experience

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or an equivalent relevant discipline.
  • Minimum 5–8 years' hands-on experience in penetration testing and/or security testing, with a demonstrable track record of personally executing engagements rather than managing them at arm's length.
  • Strong practical knowledge of common attack techniques, vulnerability classes (e.g. OWASP Top 10), and exploitation methods across web, network, application and infrastructure targets.
  • Working knowledge of security testing frameworks and standards (e.g. OSSTMM, PTES, NIST) and standard toolsets used in vulnerability assessment and exploitation.
  • Recognised security certifications strongly preferred (e.g. OSCP, CEH, CREST, GPEN or equivalent).
  • Sound understanding of the NACSA Cyber Security Act 2024 licensing framework for penetration testing and managed SOC monitoring services, including scope, consent and record-keeping obligations.
  • Holding an individual penetration testing licence issued by NACSA is an added advantage.
  • Experience in Managed Security Operation Centre (SOC) monitoring, in addition to penetration testing capability, is an added advantage
  • Ability to produce clear, well-structured findings reports for both technical and executive audiences.
  • High integrity, discretion and sound judgement when handling client systems, credentials and sensitive data during testing.
  • Effective stakeholder communication skills, able to explain technical findings and risk to both delivery teams and clients.
  • Working knowledge of ISO/IEC 27001 Information Security Management Systems (ISMS)

Benefits:

  • Free parking
  • Professional development

Work Location: In person

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut