Lrqa logo

Lead Security Consultant

Hiring from
Malaysia
Work type
Hybrid
Posted
Is this job info correct?

512,982 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

Who are we?

As the world's leading global risk management partner, we're a force for good with sustainability at our core. We operate in over 150 countries and are recognised by over 30 accreditation bodies worldwide. Our world-class experts in cybersecurity, assessment, advisory, and inspection services work hand in hand with our clients to solve their biggest business challenges.

We're here to shape a better future together; helping our clients strengthen their cybersecurity maturity, source responsibly, achieve product integrity, navigate the energy transition and assure their assets and management systems. And while we're proud of our history of delivering game-changing market firsts, we're quick to embrace change and new ideas from diverse perspectives. Our people are ambitious, future focused and share our passion about driving positive change.

Your daily responsibilities

As a Lead Security Consultant at LRQA, you will lead and deliver technically demanding security engagements across a wide range of environments and technologies, taking ownership from planning through to final delivery.

Alongside hands-on technical delivery, you will provide guidance to consultants within the team, review technical work, and help maintain a consistently high standard of assessment and reporting. You will support the development of methodologies, tooling, and internal knowledge, while acting as a technical point of contact for both clients and colleagues.

Your day-to-day responsibilities will include:

  • Client Interaction: Managing the end-to-end delivery of security engagements, including kick-off calls, testing, reporting, and client debriefs.
  • Quality Delivery: Producing high-quality, accurate, and thorough reports, while supporting peer review and maintaining strong delivery standards across engagements.
  • Consultancy: Building professional and consultative client relationships, providing practical security advice, and supporting scoping activities where required.
  • Project Leadership: Leading small to medium-sized projects, coordinating consultants where required, and supporting the delivery of larger or more complex engagements.
  • Team Development: Mentoring junior consultants, sharing technical knowledge, and contributing to improvements in team processes and delivery practices. Support presales activities by scoping engagements, advising principal security concerns and testing methodology.
  • Technical Contribution: Contributing to the development of internal tooling, methodologies, knowledge sharing, and technical guidance across the team.

This role is a shift-based role where you will be working standard (five) weekdays aligned to either standard Malaysian, KSA or UK business hours, depending on team allocation. For shifts with non-standard working hours a generous additional shift allowance is available on top of the base salary. Depending on circumstances there may be the option to move between shifts, but it is not intended to be a regular occurrence.

Location

This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. We support remote work across Malaysia; however, the office is in Kuala Lumpur. Applicants are required to be resident in Malaysia.

Key Skills & Certifications

You should have strong technical depth across multiple security domains, with particular expertise in infrastructure and cloud security assessments. Experience with Oracle Cloud Infrastructure (OCI), security benchmarking, and mobile testing would be particularly valuable.

We’re looking for someone who is an experienced hands-on security consultant but has also started taking greater ownership of engagements, supporting other consultants, and contributing to the development of team’s technical capabilities.

There is no single “perfect” profile. However, a strong candidate will demonstrate some or most of the following:

  • At least 6 years of relevant penetration testing experience.
  • Strong hands-on penetration testing experience, particularly across mobile application, infrastructure, cloud platforms and other core testing domains. Practical experience conducting cloud security assessments, with particular expertise in Oracle Cloud Infrastructure (OCI) and exposure to platforms such as Azure, AWS, or GCP.
  • Experience performing security configuration and benchmarking assessments against recognised standards and frameworks such as CIS or STIG Benchmarks, vendor security baselines, and industry good practices.
  • A track record of mentoring and developing less-experienced consultants, with genuine investment in helping others grow.
  • Excellent written and spoken English, with the ability to communicate complex technical findings clearly to both technical and non-technical audiences.
  • Ability to work both independently and as part of a high-performing team, with the capability to lead, teach, present, and inspire colleagues.

We value capability over credentials. We’re not looking for badge collectors. That said, one or more of the following will serve as a distinct advantage.

  • A BSc degree in relevant technical discipline (or equivalent experience).
  • CREST Registered Tester (CRT) or CREST Certified Tester (CCT).
  • Offensive Security certifications (e.g. OSCP, OSEP, OSWP).
  • Cloud security certifications (e.g. OCI Security Professional 1Z0-1104-26 / Azure AZ-500).
  • Broader security certifications (e.g. CISSP / CCSP / CSK).
  • Any other relevant penetration testing or IT certification.

What We Offer

Join a global team where your expertise is valued and your development is supported. We offer a collaborative work environment, opportunities for professional growth, flexible working arrangements where applicable, a competitive salary aligned with the market, and a comprehensive benefits package.

Pre-Employment Checks

If you are successful in securing a role with us, we may carry out pre-employment checks, as permitted by local law, including verification of identity, right to work, employment history, education, and criminal records where applicable.

These checks are conducted by our trusted screening partner, cFIRST, in compliance with applicable data protection laws. Any personal data collected will be used solely for recruitment purposes, stored securely, and retained only as required.

For questions about the screening process, contact onboarding@lrqa.com. For queries regarding your personal data, contact dataprotection@lrqa.com.

Similar jobs

Apply for this job