ABOUT THE JOB
The role is responsible for leading Offensive Security Advisory engagements covering penetration testing, vulnerability assessment, red teaming, adversary simulation, purple teaming and advanced security testing.
The role owns engagements from opportunity identification, presales advisory and assessment design through controlled technical execution, quality assurance, executive reporting, remediation validation and project closure. The position contributes to the growth and development of TM One's Offensive Security Advisory services
KEY RESPONSIBILITIES
Customer Advisory & Business Development
- Act as the lead customer-facing SME for Offensive Security Advisory opportunities.
- Lead discovery and scoping workshops.
- Assess customer threat profiles, critical assets and testing objectives.
- Recommend appropriate testing approaches and methodologies.
- Develop proposals, Statements of Work (SOW), testing plans and effort estimates.
- Define Rules of Engagement, authorisation requirements and success criteria.
- Support RFP/RFQ/tender activities and customer presentations.
- Identify cybersecurity improvement and follow-on opportunities.
Advisory & Technical Delivery
- Lead infrastructure, web application, API, mobile, cloud and identity security assessments.
- Lead penetration testing engagements.
- Lead Red Team and adversary simulation exercises.
- Oversee Active Directory attack-path, privilege escalation and assumed breach assessments.
- Conduct ransomware simulation and authorised social engineering engagements.
- Lead Purple Team exercises and attack-path validation activities.
- Ensure vulnerabilities and attack paths are appropriately validated.
- Facilitate remediation workshops, retesting and closure validation activities.
Engagement Governance & Quality Assurance
- Serve as engagement lead for offensive security assignments.
- Approve scope, methodologies, testing plans and Rules of Engagement.
- Ensure delivery remains within approved engagement boundaries.
- Manage critical finding escalation and customer communication.
- Review evidence, findings and remediation recommendations.
- Review technical and executive reports before customer submission.
- Ensure secure retention and disposal of testing artefacts and customer data.
Practice Development
- Develop offensive security methodologies and playbooks.
- Develop reporting templates, Rules of Engagement and estimation models.
- Evaluate new offensive security tools and techniques.
- Support controlled testing laboratories and secure testing infrastructure.
- Contribute to knowledge-sharing, customer workshops and thought leadership initiatives
CANDIDATE MUST HAVE
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering or related field.
- A relevant Master's Degree is an advantage
WE VALUE
- Minimum 5 years in cybersecurity architecture and consulting, hands-on Offensive Security experience.
- Certification expectation: At least one advanced hands-on offensive security certification is strongly preferred. Leadership credentials are advantageous.
- Advance Offensive: SCP, OSEP, OSWE, OSED, CREST Registered Penetration Tester, CREST Certified Tester, CREST Certified Simulated Attack Specialist, GPEN or GXPN.
- Specialist: CRTO, CRTP/CRTE, Burp Suite Certified Practitioner, cloud, mobile, Active Directory, OT or ICS security certification.
- Leadership/Consulting: CISSP, CISM, CCSP, PMP or PRINCE2.
LOCATION
- TM Annexe 2, Telekom Malaysia Berhad, Jalan Pantai Baharu, Kuala Lumpur.