ITFull-Time

Senior Penetration Testing Engineer

Malaysia · Singapore

Who Are We?

dtcpay is a MAS licensed payment service provider that bridges traditional finance and digital assets. We enable businesses to accept and make payments in both fiat and digital currencies, delivering secure, efficient, and seamless payment experiences across borders. As we expand globally, we are shaping the future of digital payments. We are also recognised as one of Singapore’s Top 10 Startups in the LinkedIn Top Startups 2025 list, a reflection of our momentum and the exciting journey ahead for our team.

What You'll Do:

  • Lead end-to-end penetration testing engagements for web applications, mobile applications, APIs, internal networks, and enterprise systems.
  • Execute the complete penetration testing lifecycle, including reconnaissance, vulnerability discovery, exploitation, privilege escalation, post-exploitation, and lateral movement.
  • Identify, validate, and assess security vulnerabilities, with a strong focus on the OWASP Top 10 and other modern attack techniques.
  • Perform source code security reviews for Java-based applications and identify security weaknesses across common frameworks.
  • Conduct mobile application security assessments, including static analysis, dynamic analysis, reverse engineering, API security testing, and hardening evaluation.
  • Prepare clear, detailed penetration testing reports with risk assessments, proof of concepts, and remediation recommendations.
  • Present findings and work directly with engineering teams and clients to support vulnerability remediation.
  • Participate in red team exercises, attack simulations, incident investigations, and security assessments.
  • Support enterprise security initiatives and compliance assessments, including Multi-Level Protection Scheme (MLPS)or similar security frameworks.
  • Contribute to internal security research, security awareness programs, and knowledge sharing.

What We're Looking For:

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related discipline.
  • Minimum 5 years of hands-on experience in penetration testing, offensive security, or application security.
  • Experience leading penetration testing projects independently from planning through reporting.
  • Excellent analytical, troubleshooting, communication, and technical documentation skills.
  • Strong understanding of penetration testing methodologies, attack chains, and post-exploitation techniques.
  • Experience performing internal network penetration testing, privilege escalation, Active Directory assessments, and lateral movement.
  • Proficient with industry-standard security tools such as: Burp Suite, Nmap, SQLMap, AWVS, AppScan, Metasploit.
  • Strong knowledge of web application security, including: SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Command Injection, Insecure Deserialization, Authentication and Authorization flaws, Server-Side Request Forgery (SSRF), Remote Code Execution (RCE).
  • Experience conducting Java source code security reviews across frameworks such as Spring, Spring Boot, Spring MVC, and MyBatis.
  • Proficient in Python for developing security tools, automation scripts, proof-of-concept exploits, or vulnerability research.
  • Experience with Android or iOS application security testing, including reverse engineering, static analysis, dynamic analysis, and API security testing.
  • Familiarity with middleware security, operating system hardening, and host security assessments.
  • Proficiency in both English and Mandarin as you will need to work closely with Chinese vendors.
  • The role is based fully onsite, requiring your presence in the office.

Nice to Have:

  • Security certifications such as OSCP, OSEP, GXPN, CEH, CISSP, or equivalent.
  • Published vulnerabilities through CVE, CNVD, or other recognized vulnerability disclosure programs.
  • Experience performing penetration testing for highly regulated industries such as financial services, government, or critical infrastructure.
  • Participation in red team engagements, cyber defense exercises, or adversary simulation projects.
  • Experience delivering technical training, presenting at security conferences, contributing to open-source security projects, or publishing security research.

Benefits

  • Competitive compensation and benefits packages

  • Regional exposure and career growth opportunities

  • Opportunity to work with a dynamic and innovative digital payments

  • Exposure to cross-functional collaboration and involvement

  • Mentorship and guidance from experienced professionals