Now hiring

Offensive Security Analyst, Cyber Threat Unit, CSD @ BNMSCHOLAR

MalaysiaOnsiteFull-timeJob reference 728
Apply with ResuMinder

Opens on the employer's site

About this role

The role of the candidate is to be part of the Cyber Threat Unit and function as part of the Offensive Security team. The candidate is responsible for assisting in the evaluation and testing of security controls to help ensure the protection of the organization's assets.

Pricipal Accountabilities

• Conduct offensive security activities and security control assessments across endpoint, network, identity, cloud, and application environments to identify security weaknesses, potential gaps, and evaluate the effectiveness of security controls. • Conduct penetration testing activities to identify, validate, and report security vulnerabilities and associated risks. • Execute security testing activities and adversary emulation scenarios based on established test plans and methodologies. • Analyse and document test results, findings, and recommendations for security control improvements. • Support the verification and validation of remediation efforts implemented by relevant stakeholders. • Support Security Control Validation testing and attack simulations using internal and external threat intelligence. • Assist in developing attack scenarios based on threat intelligence to evaluate the effectiveness of security controls and detection capabilities. • Apply offensive security testing methodologies aligned with MITRE ATT&CK and threat modelling frameworks. • Participate in purple team exercises, red team activities, and continuous security control validation initiatives. • Assist in the development and maintenance of procedures, guidelines, and documentation related to offensive security activities. • Collaborate with control owners, blue team, and SOC personnel to improve security monitoring and defensive capabilities. • Prepare assessment reports and communicate findings to relevant stakeholders in a timely manner. • Escalate significant findings and security risks to the Offensive Security Specialist or relevant management as required.

Job Complexity & Problem Solving

• Perform continuous simulations of attackers techniques based on best-in-class industry framework (MITRE ATT&CK TTP) • Simulate specific kill-chain tactics from sophisticated malicious actors (APT –Advanced Persistence Threats) based on their known behaviours. • Support continuous improvement of the Bank's ability to prevent, detect, and respond to cyber threats.

Leadership & Stakeholder Management

• Good technical skills across Windows/Linux/macOS platforms and hands-on with offensive security tools (commercial/open-source). Proven experience in code review and vulnerability assessment. • Familiarity with MITRE ATT&CK and common adversary tactics, techniques, and procedures (TTPs). • Ability to analyse technical findings and communicate recommendations effectively. • Ability to prepare clear and actionable assessment reports for stakeholders. • Ability to work collaboratively with cross-functional teams to address identified security weaknesses.

Technical/Functional

• Conduct offensive security activities, including penetration testing and security control validation, to identify security weaknesses and control gaps. • Execute offensive security test plans and attack scenarios to assess the effectiveness of security controls. • Analyse assessment results, prepare reports, and recommend remediation actions. • Monitor and track the implementation of security control improvements.​ • Assist in the development and maintenance of offensive security testing procedures, playbooks and documentation.​

• Academic Qualifications: A bachelor's degree in computer science or information technology.​ • Licence / Certification: Relevant cyber security certifications e.g., eLearnSecurity Junior Penetration Tester (eJPT), Certified Ethical Hacker (CEH), CompTIA PenTest+, Offensive Security Certified Professional (OSCP), Certified Red Team Operator (CRTO). • Experience: Minimum 2 years of experience in cyber security, vulnerability assessment, penetration testing, or offensive security-related activities. Experience in red teaming or purple teaming would be an advantage.

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores