JOB DETAILS
Offensive Security Analyst, Cyber Threat Unit, CSD
CompanyBank Negara Malaysia
LocationMalaysia
Work ModeOn Site
PostedOctober 5, 2026

About The Company
Bank Negara Malaysia is Malaysia’s central bank. Founded in 1959, our mission is to promote monetary and financial stability that is conducive to sustainable economic growth. Within our mandates, we strive to make Malaysia a better place.
About the Role
The role of the candidate is to be part of the Cyber Threat Unit and function as part of the Offensive Security team. The candidate is responsible for assisting in the evaluation and testing of security controls to help ensure the protection of the organization's assets.
Responsibilities
Pricipal Accountabilities
- Conduct offensive security activities and security control assessments across endpoint, network, identity, cloud, and application environments to identify security weaknesses, potential gaps, and evaluate the effectiveness of security controls.
- Conduct penetration testing activities to identify, validate, and report security vulnerabilities and associated risks.
- Execute security testing activities and adversary emulation scenarios based on established test plans and methodologies.
- Analyse and document test results, findings, and recommendations for security control improvements.
- Support the verification and validation of remediation efforts implemented by relevant stakeholders.
- Support Security Control Validation testing and attack simulations using internal and external threat intelligence.
- Assist in developing attack scenarios based on threat intelligence to evaluate the effectiveness of security controls and detection capabilities.
- Apply offensive security testing methodologies aligned with MITRE ATT&CK and threat modelling frameworks.
- Participate in purple team exercises, red team activities, and continuous security control validation initiatives.
- Assist in the development and maintenance of procedures, guidelines, and documentation related to offensive security activities.
- Collaborate with control owners, blue team, and SOC personnel to improve security monitoring and defensive capabilities.
- Prepare assessment reports and communicate findings to relevant stakeholders in a timely manner.
- Escalate significant findings and security risks to the Offensive Security Specialist or relevant management as required.
Job Complexity & Problem Solving
- Perform continuous simulations of attackers techniques based on best-in-class industry framework (MITRE ATT&CK TTP)
- Simulate specific kill-chain tactics from sophisticated malicious actors (APT –Advanced Persistence Threats) based on their known behaviours.
- Support continuous improvement of the Bank's ability to prevent, detect, and respond to cyber threats.
Leadership & Stakeholder Management
- Good technical skills across Windows/Linux/macOS platforms and hands-on with offensive security tools (commercial/open-source). Proven experience in code review and vulnerability assessment.
- Familiarity with MITRE ATT&CK and common adversary tactics, techniques, and procedures (TTPs).
- Ability to analyse technical findings and communicate recommendations effectively.
- Ability to prepare clear and actionable assessment reports for stakeholders.
- Ability to work collaboratively with cross-functional teams to address identified security weaknesses.
Technical/Functional
- Conduct offensive security activities, including penetration testing and security control validation, to identify security weaknesses and control gaps.
- Execute offensive security test plans and attack scenarios to assess the effectiveness of security controls.
- Analyse assessment results, prepare reports, and recommend remediation actions.
- Monitor and track the implementation of security control improvements.
- Assist in the development and maintenance of offensive security testing procedures, playbooks and documentation.
Qualifications
- Academic Qualifications: A bachelor's degree in computer science or information technology.
- Licence / Certification: Relevant cyber security certifications e.g., eLearnSecurity Junior Penetration Tester (eJPT), Certified Ethical Hacker (CEH), CompTIA PenTest+, Offensive Security Certified Professional (OSCP), Certified Red Team Operator (CRTO).
- Experience: Minimum 2 years of experience in cyber security, vulnerability assessment, penetration testing, or offensive security-related activities. Experience in red teaming or purple teaming would be an advantage.
Key Skills
Penetration testingVulnerability assessmentOffensive securityMITRE ATT&CKRed teamingPurple teamingSecurity control validationThreat intelligenceAdversary emulationEndpoint securityNetwork securityCloud securityApplication securityLinuxWindowsMacOS
Categories
Security & SafetyTechnologySoftware
Job Information
📋Core Responsibilities
The candidate will conduct offensive security activities, including penetration testing and security control assessments, to identify vulnerabilities across various environments. They will also collaborate with blue teams and SOC personnel to improve defensive capabilities and document findings for remediation.
📋Job Type
full time
📊Experience Level
2-5
💼Company Size
3355
📊Visa Sponsorship
No
💼Language
English
🏢Working Hours
40 hours
Apply Now →
You'll be redirected to
the company's application page