Senior Security Specialist
Indexed description
Job Responsibilities
We are looking for an experienced and highly analytical Senior Security Specialist to help strengthen our cybersecurity posture and drive high-impact security initiatives across the organization. In this role, you will lead vulnerability management, advanced penetration testing, incident response support, and security hardening efforts that directly protect our business, products, and customers.
You will work closely with engineering, infrastructure, cloud, risk, compliance, and business stakeholders to translate technical findings into practical risk reduction. This is a role for someone who combines deep hands-on expertise with sound judgment, strong communication, and the ability to influence security outcomes across the enterprise.
- Lead vulnerability assessments across networks, applications, cloud environments, and infrastructure, providing clear, risk-based remediation guidance to both technical and non-technical stakeholders.
- Plan and execute advanced penetration testing activities across network, web, cloud, and infrastructure layers, and deliver high-quality reports with prioritized recommendations.
- Review, strengthen, and optimize security controls, including firewall policies, network segmentation, endpoint hardening, and other defensive safeguards.
- Monitor, investigate, and respond to security alerts and incidents, ensuring effective triage, containment, eradication, and root cause analysis.
- Serve as an escalation point for complex security incidents and coordinate cross-functional response efforts through resolution.
- Review, validate, and prioritize bug bounty submissions, partnering with researchers and engineering teams to remediate confirmed issues.
- Collaborate with IT, DevOps, Cloud, Risk, and Compliance teams to embed security best practices into development and operational workflows.
- Advise business stakeholders on security risks, control design, and secure decision-making.
- Support security awareness initiatives and help strengthen security culture across the organization.
- Contribute to security strategy, standards, continuous improvement, and lessons learned based on threat intelligence and emerging risks.
- Use AI-assisted tools and automation to improve security testing, triage, reporting, threat analysis, and repeatable security workflows.
- Perform additional duties as assigned by the Team Lead or Manager to support departmental goals.
- Bachelor’s degree, postgraduate diploma, or professional qualification in Computer Science, Information Security, IT, or a related field; equivalent practical experience is welcome.
- Minimum 5 years of hands-on experience in cybersecurity, ethical hacking, web application penetration testing, and IT/
- information security.
- Industry certifications such as Security+, CEH, OSCP, eJPT, eWPT, GIAC, or similar are highly valued.
- Demonstrated leadership in team guidance, project ownership, and cross-functional influence for senior-level roles.
- Strong experience with offensive and defensive security tools such as Burp Suite, Metasploit, Nessus, Qualys, Splunk, SIEM platforms, and similar tools.
- Solid understanding of network protocols, web application security, OWASP Top 10, vulnerability analysis, and threat detection methodologies.
- Hands-on experience with AWS security controls, IAM, networking, and Linux system administration.
- Strong analytical, problem-solving, and independent working skills in a fast-paced environment.
- Excellent communication and reporting skills, with the ability to explain technical risk to non-technical stakeholders.
- Working knowledge of AI tools, AI-assisted security analysis, and automation using AI to improve security operations, triage, reporting, and detection workflows.
- Willingness to work on-site in i-City Shah Alam
Are you game?
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search