About the job
About Appspace
Appspace helps organizations improve work experiences worldwide. The company supports flexible work arrangements so employees can perform at their best. Appspace values well-being, encourages strong connections, and invests in professional development.
Role Overview: Senior Web Application Penetration Tester
This position leads internal penetration testing and works closely with application developers to find and address security vulnerabilities, especially those highlighted in the OWASP Top 10. The role also partners with cross-functional teams to strengthen secure Software Development Life Cycle (SDLC) practices.
What You Will Do
- Perform penetration testing on web applications, cloud setups, and mobile apps using black-box testing tools, dynamic and static analysis (DAST & SAST), and a range of penetration test techniques.
- Apply black box, gray box, and white box testing methods. Red teaming skills are important for this role.
- Understand application architectures and business goals. Help establish secure coding standards by staying current with security trends and sharing knowledge with the team.
- Use both manual and automated approaches to test platforms such as network equipment, servers, web applications, APIs, wireless, mobile, and databases. Run vulnerability assessments for issues like injection flaws, privilege escalation, fuzzing, buffer overflows, and more.
- Show a strong record of finding web application security issues defined by OWASP, including input validation, broken access controls, session management, cross-site scripting, SQL injection, and server misconfigurations.
- Programming skills in Python, Perl, Java, or Shell Scripting are a plus.
- Work with tools such as web proxies, port scanners, vulnerability scanners, and exploit frameworks (for example, Burp, Nessus, Nmap, Metasploit).
- Advise development teams on effective ways to resolve security vulnerabilities.
Location
Kuala Lumpur, Malaysia

