Jobless Developer
UpGrowth HR Sdn. Bhd. logo

Posted 1 month ago

Open

Ethical Hacker

Kuala LumpurHybrid

AI Summary

The Ethical Hacker / Penetration Tester proactively identifies and remediates security vulnerabilities across applications, infrastructure, and cloud environments through simulated attacks and collaborates with development and infrastructure teams.

About this role

JOB OVERVIEW:

We are looking for a highly skilled Ethical Hacker / Penetration Tester to proactively identify and eliminate security vulnerabilities across our applications, infrastructure, and cloud environments. You will simulate real-world cyberattacks to assess our security posture, work closely with development and infrastructure teams to remediate vulnerabilities, and help build a strong security-first culture.

JOB RESPONSIBILITIES:

  • Conduct penetration testing on web applications, APIs, networks, and cloud environments.

  • Perform vulnerability assessments and validate security findings.

  • Identify security issues such as SQL Injection, XSS, CSRF, broken authentication, access control flaws, and API vulnerabilities.

  • Assess network, server, firewall, VPN, and cloud security configurations.

  • Prepare clear security reports with risk ratings and remediation recommendations.

  • Collaborate with developers and IT teams to verify security fixes.

  • Stay up to date with the latest cybersecurity threats, tools, and best practices.

JOB REQUIREMENTS:

  • Bachelor's Degree in Computer Science, Cybersecurity, Information Technology, or a related field.

  • At least 2 years of experience in penetration testing or ethical hacking.

  • Strong understanding of web application, network, API, and cloud security.

  • Experience with security tools such as Burp Suite, Nmap, Metasploit, OWASP ZAP, Nessus, Wireshark, SQLmap, or Kali Linux.

  • Familiarity with Linux, Windows, Python/Bash, TCP/IP, HTTP/HTTPS, and SQL.

  • Strong analytical, problem-solving, and communication skills.

ADDED SKILLS (PREFERRED):

  • Experience in CTF competitions or bug bounty platforms (e.g. HackerOne, Bugcrowd).

  • Knowledge of DevSecOps, Docker, Kubernetes, and AI/LLM security.

  • Certifications such as OSCP, PNPT, CEH, eJPT, Security+, or PenTest+ are an advantage.

Skills

BashBurp SuiteCEHCISSPDockerHTTP/HTTPSKali LinuxKubernetesLinuxMetasploitNessusNMAPOWASP ZAPPythonSQLSqlmapTCP/IPWindowsWireshark

Explore related jobs

Browse these categories

Market data for this role

All reports →