Sekuro Asia logo

Offensive Security Analyst (Penetration Testers)

Sekuro Asia Kuala Lumpur, Kuala Lumpur, Malaysia

onsitefull-time
Posted Aug 27, 2026Apply by Sep 26, 2026
  • Role & seniority

    • Red Team / Offensive Security Consultant (Client-facing)

    • ~2+ years consulting experience requirement

  • Stack/tools

    • Penetration testing methodologies & workflows

    • Web/app & web API testing

    • Manual source code reviews

    • Static code analysis

    • Secure architecture / cloud security reviews

    • (Certifications referenced: OSCP, CREST CRT/CCT, OSCE)

  • Top 3 responsibilities

    • Perform penetration testing & broader security assessments across multiple technologies/environments

    • Identify and report vulnerabilities (notably in web apps/web APIs and via code review/static analysis), including remediation guidance

    • Lead/plan and manage security engagements (test plans, coordination with clients/SMEs, and capability development; may include mentoring juniors)

  • Must-have skills

    • Strong penetration-testing methodology/techniques and ability to remediate/security-risk manage

    • Ability to find web/API vulnerabilities and conduct manual source-code reviews (with static code analysis support)

    • Understanding of threats across environments (cloud, endpoints, IoT), including hardening control reviews

    • Adaptability to evolving threats/technologies

  • Nice-to-haves

    • OSCE or CREST CCT or other specialist certifications

    • Executive/client leadership experience

    • Capability development focus (e.g., **secure cloud architectu

Full Description

About the job

The Role

Our Red Team, Offensive Security Consultants work with organisations and technical teams to perform a variety of assessments and provide practical advice to keep them secure. Red team members are generally familiar with and apply themselves to most aspects of cybersecurity but specialize in web application security, code reviews, architecture design, network security, attack simulations or even specialist fields such as mainframe or SCADA systems. They help to ensure cybersecurity issues and identified along with their associated risks, and guide organisations to manage this risk in a practical manner.

You will be

Conducting security assessments for various technology types and environments, with a focus on penetration testing; Guiding junior talent to become cybersecurity experts as well; Doing project management and developing security test plans around larger complex projects; Coordinate with clients and other subject matter experts in different fields, as required in projects; and Drive and develop capabilities in specific security areas, (E.g. Secure system architecture design in the cloud).

A suitable candidate would have some or most of the following attributes

  • Demonstrate deep understanding of penetration-testing methodologies, techniques, and remediation of security risks;
  • Be able to identify vulnerabilities in web apps/web APIs, and pick up issues in code through manual source code reviews/static code analysis;
  • Understand threats in different environments, from cloud, to endpoints or IoT systems. Perform review of hardening controls for such systems; and
  • Think on your feet and adapt to new threats and technologies are they develop.

Experience and Certification

2 years of client facing consulting experience.

Must have: OSCP and/OR CREST CRT

Nice to have: OSCE or CREST CCT or other specialist certifications Some Executive Experience

The Mission

Protect and enable growth of value creators, through excellence and integrity. To be the first choice for visionary organisations and talents, and to turn every client into a client for life. We are passionate about providing opportunities to our team members to be the best version of themselves and building partnerships with our clients to ensure cybersecurity empowers them towards their business goals.

The Team

Our team is made up of Information Security professionals coming from all types of professional and personal backgrounds - we have a unique, international environment and believe in having fun at work. We offer benefits to help you in your career progression and in addition, we have training and certification opportunities, flexible hours, a great workplace environment, a culture focused on helping you become a balanced consultant while working in a technically strong, diverse team.

About Privasec

Privasec is an independent cybersecurity consulting firm and we have been operating for more than 7 years. We have offices located in Singapore and Malaysia, as well as in 6 different cities in Australia. We offer Cybersecurity services ranging from Offensive Security to Strategy, Governance, Risk and Compliance services, including ISO27001 implementation and adoption of other International Standards for our clients. We are ISO27001 certified, CREST Accredited and a PCI QSA company.

Penetration TestingWeb Application SecurityCode ReviewNetwork SecurityAttack SimulationCloud SecuritySecure Architecture DesignVulnerability AssessmentStatic Code AnalysisIoT SecurityProject ManagementClient Consultingmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.