Apply Edge Start your job search

Senior Cybersecurity Consultant

Antarex · Petaling Jaya, Selangor, Malaysia

Apply & track with Apply Edge

JOB ROLEThe Senior Cybersecurity Consultant is responsible for delivering high-quality cybersecurity consulting and technical security assessment services to clients. The role requires strong hands-on expertise in vulnerability assessment, penetration testing, mobile and web application security, server and database hardening, and security risk assessment. The incumbent will lead and execute client engagements from scoping and assessment through reporting, remediation guidance, and stakeholder presentation. The role also supports governance, risk and compliance (GRC) initiatives, delivers technical training including red-team related topics, and serves as a trusted cybersecurity advisor to clients throughout the engagement lifecycle. PRIMARY DUTIES & RESPONSIBILITIESThe responsibilities of the Senior Cybersecurity Consultant shall include, but are not limited to, the following: Plan and conduct comprehensive vulnerability assessments across network infrastructure, applications, operating systems, cloud environments, and other in-scope technologies.Analyse findings, validate risks, and provide practical remediation recommendations.Perform advanced penetration testing and attack simulations across networks, systems, web applications, APIs, and other approved environments to identify exploitable weaknesses and evaluate the effectiveness of existing security controls.Assess the security of mobile and web applications using recognised methodologies and industry best practices, including OWASP guidance.Identify application vulnerabilities, validate business impact, and recommend appropriate remediation measures.Review server and database security configurations, identify configuration weaknesses, and recommend or implement hardening measures aligned with recognised security benchmarks and client requirements.Support cybersecurity risk assessments, audits, compliance reviews, and the development or enhancement of security policies, procedures, standards, and control frameworks in line with applicable regulatory and industry requirements.Design and deliver technical training, workshops, and knowledge-sharing sessions on red-team tactics, techniques, procedures, attack simulation, and defensive considerations for internal teams and clients.Prepare clear, accurate, and professionally structured assessment reports covering scope, methodology, findings, risk ratings, evidence, business impact, and actionable remediation recommendations.Review remediation progress and perform revalidation where required.Present technical findings and cybersecurity risks to both technical and non-technical stakeholders.Translate complex security issues into clear business implications and practical recommendations.Support engagement scoping, planning, scheduling, execution, and closure.Manage deliverables, timelines, client expectations, and project communications to ensure assignments are completed to the required quality standards.Provide technical guidance to junior consultants and contribute to internal methodologies, playbooks, and knowledge development.Keep abreast of emerging cybersecurity threats, vulnerabilities, attack techniques, and industry developments to support continuous improvement of the team’s capabilities.Maintain timely, professional, and proactive communication with clients through email, calls, meetings, and presentations, ensuring issues, dependencies, risks, and progress are clearly communicated throughout the engagement.Undertake other duties and responsibilities as assigned by the superior or Management in support of business and operational requirements. REQUIREMENTSBachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, or a related discipline. Equivalent relevant professional experience may also be considered. Minimum 5 years of hands-on experience in cybersecurity consulting, penetration testing, vulnerability assessment, security assessment, or other relevant technical cybersecurity roles. Proven experience managing client-facing cybersecurity engagements independently, including planning, execution, reporting, presentation of findings, and remediation discussions. Strong practical knowledge of network and system security, web and mobile application security, vulnerability management, security hardening, common attack techniques, and cybersecurity risk assessment. Good working knowledge of recognised cybersecurity standards, frameworks, and methodologies such as OWASP, NIST, CIS Benchmarks, ISO/IEC 27001, and other relevant regulatory or industry requirements. Hands-on experience with security assessment and penetration-testing tools such as Burp Suite, Nmap, Nessus or equivalent vulnerability scanners, Metasploit, Kali Linux toolsets, and other relevant testing utilities. Strong analytical, problem-solving, and technical writing skills, with the ability to produce clear, accurate, and actionable security assessment reports. Strong communication, presentation, and stakeholder-management skills, with the ability to explain complex cybersecurity findings to both technical and non-technical audiences. Ability to manage multiple engagements, prioritise tasks effectively, meet project deadlines, and provide practical, risk-based recommendations in a consulting environment. Ability to mentor junior team members, review technical work, share knowledge, and contribute to the continuous improvement of internal cybersecurity methodologies and capabilities. High level of integrity, attention to detail, professionalism, and commitment to continuous learning, with the ability to handle confidential and sensitive information responsibly. Relevant professional certifications are an advantage, including OSCP, OSWE, OSEP, CREST certifications, GPEN, GWAPT, CEH, CISSP, CISM, CRISC, ISO/IEC 27001-related certifications, or other equivalent recognised cybersecurity credentials.