Senior Security Consultant
Date: 8 Oct 2026
Location: Kuala Lumpur, Malaysia
Company: LRQA
Senior Security Consultant (Penetration Testing, Shift-based)
Who are we?
As the world's leading global risk management partner, we're a force for good with sustainability at our core. We operate in over 150 countries and are recognised by over 30 accreditation bodies worldwide. Our world-class experts in cybersecurity, assessment, advisory, and inspection services work hand in hand with our clients to solve their biggest business challenges.
We're here to shape a better future together; helping our clients strengthen their cybersecurity maturity, source responsibly, achieve product integrity, navigate the energy transition and assure their assets and management systems. And while we're proud of our history of delivering game-changing market firsts, we're quick to embrace change and new ideas from diverse perspectives. Our people are ambitious, future focused and share our passion about driving positive change.
Your daily responsibilities
As a Senior Security Consultant at LRQA, you will independently deliver complex security engagements across a range of environments and technologies, taking responsibility for high-quality technical testing, reporting, and client communication.
You will be expected to operate with a high degree of autonomy, apply sound technical judgement during engagements, and support less-experienced consultants where required. You will also contribute to improving internal knowledge, methodologies, and delivery practices while continuing to develop your own technical depth across core security testing domains.
Your day-to-day responsibilities will include:
- Client Interaction: Managing day-to-day client communication during engagements, including kick-off discussions, testing updates, reporting, and technical debriefs.
- Quality Delivery: Delivering accurate, thorough, and high-quality security assessments and reports with minimal supervision, ensuring findings are clearly evidenced and communicated.
- Consultancy: Providing practical and risk-based security advice to clients, explaining technical findings and remediation recommendations to both technical and non-technical stakeholders.
- Project Delivery: Independently delivering small to medium-sized engagements and supporting larger or more complex projects under the direction of Lead or Principal Security Consultants.
- Technical Testing: Performing hands-on penetration testing across infrastructure, cloud platforms, mobile applications, web applications, APIs, and other relevant testing domains.
- Team Support: Providing technical guidance and informal mentoring to junior consultants, reviewing work where appropriate, and supporting the development of less-experienced team members.
- Technical Contribution: Contributing to internal knowledge sharing, testing methodologies, tooling, technical documentation, and improvements to delivery processes.
- Presales Support: Supporting scoping and presales activities by providing technical input, identifying likely testing requirements, and assisting with effort estimation where required.
This role is a shift-based role where you will be working standard (five) weekdays aligned to either standard Malaysian, KSA or UK business hours, depending on team allocation. For shifts with non-standard working hours a generous additional shift allowance is available on top of the base salary. Depending on circumstances there may be the option to move between shifts, but it is not intended to be a regular occurrence.
Location
This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. We support remote work across Malaysia; however, the office is in Kuala Lumpur. Applicants are required to be resident in Malaysia.
Key Skills & Certifications
You should have strong technical depth across multiple security domains, with particular expertise in infrastructure and cloud security assessments. Experience with Oracle Cloud Infrastructure (OCI), security benchmarking, and mobile testing would be particularly valuable.
We’re looking for someone who is an experienced hands-on security consultant but has also started taking greater ownership of engagements, supporting other consultants, and contributing to the development of team’s technical capabilities.
- At least 4 years of relevant penetration testing experience
- Strong hands-on penetration testing experience, particularly across mobile application, infrastructure, cloud platforms and other core testing domains. Practical experience conducting cloud security assessments, with particular expertise in Oracle Cloud Infrastructure (OCI) and exposure to platforms such as Azure, AWS, or GCP.
- Experience performing security configuration and benchmarking assessments against recognised standards and frameworks such as CIS or STIG Benchmarks, vendor security baselines, and industry good practices.
- A track record of mentoring and developing less-experienced consultants, with genuine investment in helping others grow.
- Excellent written and spoken English, with the ability to communicate complex technical findings clearly to both technical and non-technical audiences.
- Ability to work both independently and as part of a high-performing team, with the capability to lead, teach, present, and inspire colleagues.
We value capability over credentials. We’re not looking for badge collectors. That said, one or more of the following will serve as a distinct advantage.
- A BSc degree in relevant technical discipline (or equivalent experience).
- CREST Registered Tester (CRT) or CREST Certified Tester (CCT).
- Offensive Security certifications (e.g. OSCP, OSEP, OSWP).
- Cloud security certifications (e.g. OCI Security Professional 1Z0-1104-26 / Azure AZ-500).
- Broader security certifications (e.g. CISSP / CCSP / CSK).
- Any other relevant penetration testing or IT certification.
What We Offer
Join a global team where your expertise is valued and your development is supported. We offer a collaborative work environment, opportunities for professional growth, flexible working arrangements where applicable, a competitive salary aligned with the market, and a comprehensive benefits package.
Pre-Employment Checks
If you are successful in securing a role with us, we may carry out pre-employment checks, as permitted by local law, including verification of identity, right to work, employment history, education, and criminal records where applicable.
These checks are conducted by our trusted screening partner, cFIRST, in compliance with applicable data protection laws. Any personal data collected will be used solely for recruitment purposes, stored securely, and retained only as required.
For questions about the screening process, contact onboarding@lrqa.com. For queries regarding your personal data, contact dataprotection@lrqa.com.