Required Qualifications
Education
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Network Engineering, or a related discipline.
Experience
2–5 years of relevant experience in information security, cybersecurity operations, vulnerability management, security assessment, or related areas.
Hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT).
Experience identifying and evaluating vulnerabilities across infrastructure, applications, mobile applications, and network environments.
Exposure to security assessment methodologies and common cybersecurity attack techniques.
Working knowledge of security frameworks, risk management, and GRC principles.
Technical Skills
Vulnerability management and remediation processes.
Penetration testing tools and security assessment methodologies.
Network security fundamentals, including TCP/IP, DNS, routing, switching, and firewalls.
Understanding of common web application and infrastructure vulnerabilities.
Ability to analyse technical security findings and assess associated business risks.
Basic knowledge of SIEM and security monitoring technologies.
Working knowledge of ISO 27001 controls and Information Security Management Systems (ISMS).
Understanding of data protection and privacy requirements, including PDPA and related regulations.
Basic understanding of cloud security concepts and cloud environments.
Preferred Qualifications
Experience participating in red team, blue team, tabletop, or adversary simulation exercises.
Hands-on experience with network traffic analysis and DNS security investigations.
Experience with SIEM platforms and security monitoring tools.
Exposure to cloud security technologies and environments.
Experience supporting ISO 27001 audits, risk assessments, or compliance programs.
Knowledge of additional cybersecurity, risk, compliance, or privacy frameworks.
Relevant professional certifications such as CEH, Security+, ISO 27001, OSCP, or equivalent would be an advantage.
Core Competencies
Strong analytical and problem-solving skills.
Attention to detail and strong documentation skills.
Strong technical curiosity and willingness to learn.
Ability to work collaboratively with technical and business stakeholders.
Ability to translate technical security findings into business risks.
Strong written and verbal communication skills.
Process-oriented and organized approach to security activities.