Staff, IT Security Testing Unit
The Staff of the IT Security Testing Unit is responsible for conducting offensive security operations, including penetration testing, vulnerability assessments, and security control evaluations, to protect the bank’s IT infrastructure and applications. This role identifies vulnerabilities, recommends mitigations, and ensures that the bank’s security defenses remain resilient against emerging threats, supporting regulatory and business objectives.
Main Duties
- Conduct internal and external penetration tests on systems, networks, applications, and mobile platforms;
- Identify and exploit vulnerabilities to evaluate the effectiveness of existing security controls;
- Document detailed findings from testing activities and provide actionable recommendations;
- Present test results to technical teams and management, translating technical risks into business impacts;
- Stay updated on new threats, vulnerabilities, and offensive security tactics;
- Research emerging attack vectors and develop countermeasure recommendations;
- Collaborate with IT, application development, and infrastructure teams to plan and execute security tests;
- Coordinate internal and external penetration testing engagements and track remediation progress;
- Assist in assessing the effectiveness of security controls for compliance with regulatory frameworks (e.g., National Bank of Cambodia Technology and Cyber Risk Management Guidelines, SWIFT CSP, PCI DSS);
- Contribute to ongoing risk assessments and audit support activities;
- Share knowledge with junior team members and contribute to developing internal testing methodologies and processes;
- Present the results of penetration testing to management;
- Provide training and guidance to junior team members on offensive security practice;
- Perform other task as assigned by line manager.
Skills/ Experiences
- Bachelor’s degree or equivalent on Computer Science or information technology.
- Minimum 1 year of experience in penetration testing, vulnerability assessment, or offensive security operations.
- Holding any certification such as eJPT, eCPPT, CEH, CPENT, or OSCP or other penetration certifications are preferable;
- Strong knowledge of penetration testing tools (Kali Linux, Metasploit, Burp Suite, Nmap, Tenable).
- Understanding of operating systems (Windows, Linux) and network structures.
- Familiarity with regulatory and security standards (NBC TRMG, SWIFT CSP, PCI DSS, OWASP).
- Basic programming or scripting skills to assist in custom testing scenarios.
- Familiar with various operating systems and network structures, including Windows and Linux environments.
- Analytical thinking and problem-solving;
- Good communication verbally and written;
- Ability to explain technical issues to non-technical audiences.
- Good time management.
Download Job Announcement
Staff, IT Security Testing Unit
How to Apply:
Interested applicants, please send by email attached with a cover letter and your most updated CV (with current photo) to hr@ftb.com.kh or submit the hard copy at Our Head Office, Building No. 33 C-D, Tchecoslovaquie Blvd (169), Sangkat Veal Vong, Khan 7 Makara Phnom Penh. Only short-listed candidates will be contacted for an interview.
More information, please kindly contact phone number: 081 666 597 / 081 444 179
Please visit our website: https://ftb.com.kh/careers