About the job
Appspace is looking for a Senior Web Application Penetration Tester based in Kuala Lumpur, Malaysia. This role leads internal penetration testing efforts and works directly with application developers to identify and address security vulnerabilities, especially those outlined in the OWASP Top 10. Collaboration with cross-functional teams is key, with a focus on strengthening secure Software Development Life Cycle (SDLC) practices.
Key Responsibilities
- Conduct penetration tests on web applications, cloud environments, and mobile apps using both manual and automated methods, including black-box, gray-box, and white-box testing.
- Utilize dynamic and static analysis tools (DAST & SAST) and a range of penetration testing techniques.
- Apply red teaming skills when required.
- Assess platforms such as network equipment, servers, APIs, wireless, mobile, and databases for vulnerabilities, including injection flaws, privilege escalation, fuzzing, and buffer overflows.
- Demonstrate a strong track record of uncovering web application security issues like input validation errors, broken access controls, session management flaws, cross-site scripting, SQL injection, and server misconfigurations.
- Work with tools such as web proxies, port scanners, vulnerability scanners, and exploit frameworks (examples: Burp, Nessus, Nmap, Metasploit).
- Advise development teams on resolving security vulnerabilities and help establish secure coding standards by sharing up-to-date security knowledge.
Preferred Skills
- Understanding of application architectures and business goals.
- Programming experience in Python, Perl, Java, or Shell Scripting is considered a plus.
Location
This position is based in Kuala Lumpur, Malaysia.

