Deskripsi Pekerjaan
Are you a seasoned security professional ready to lead the charge in protecting enterprise assets? NTT DATA is seeking a skilled Test Manager - Penetration Testing & Application Security to join our dynamic team in Kuala Lumpur. In this pivotal role, you will oversee critical security assessments, ensuring our applications and infrastructure are resilient against modern cyber threats.
You will drive the secure Software Development Life Cycle (SDLC) from concept to deployment, conducting rigorous penetration tests and code reviews. Your expertise will help identify vulnerabilities early, ensuring compliance with global standards such as ISO 27001 and PCI-DSS. If you are passionate about building a secure digital future and have a knack for leading high-impact security initiatives, this is the opportunity for you.
Tanggung Jawab
- Lead end-to-end penetration testing engagements, including web, mobile, and network security assessments.
- Perform comprehensive code reviews to identify security flaws in custom and third-party applications.
- Drive the implementation of a secure SDLC, integrating security best practices into every development phase.
- Ensure strict compliance with internal policies and external regulatory frameworks (e.g., ISO 27001, SOC 2).
- Collaborate with development teams to remediate critical vulnerabilities and provide actionable reporting.
- Stay abreast of the latest threat intelligence and emerging attack vectors to proactively defend systems.
Kualifikasi
- Minimum of 5-7 years of experience in Application Security, Penetration Testing, or a related field.
- Strong understanding of OWASP Top 10 and common web vulnerabilities (SQLi, XSS, CSRF).
- Experience with automated security testing tools (e.g., Burp Suite, OWASP ZAP) and scripting languages (Python/Perl).
- Proven ability to manage projects and lead cross-functional teams in a fast-paced environment.
- Relevant security certifications such as OSCP, CEH, CISSP, or CISM are highly desirable.
- Excellent communication skills to articulate complex technical risks to non-technical stakeholders.