safinglink.com

Cybersecurity skills that pay: bug bounty, security testing and online protection services. 能赚钱的网络安全技能:漏洞赏金、安全测试与在线防护服务。

Career Security | 职场安全

How to Spot Scams and Find Legit Cybersecurity Gigs: A Checklist

Published on safinglink.com · Cybersecurity · Tech | 网络安全 · 技术

Start With a 6-Point Scam Filter | 先用六点筛子过滤可疑机会

Before you reply to any cybersecurity gig, run six checks: who pays first, is the company registered, do they ask for your bank OTP, is the pay unrealistically high, do they rush you, and do they refuse a written contract. Any two red flags means stop.

看到任何网络安全兼职或外包机会,先跑六点筛子:一,对方是否要求你先付“培训费”或“押金”;二,公司能否在 SSM(马来西亚公司委员会)查到注册号;三,是否索要银行 OTP、TAC 或网上银行密码;四,报酬是否高得离谱(例如每天 800 令吉做基础数据整理);五,是否不断催你“今天内决定”;六,是否拒绝提供书面合约或工作范围。六点里踩中两点,直接停止沟通,不要抱侥幸心理。

Verify the Company on SSM and MyData SSM | 用 SSM 与 MyData SSM 核实公司

Get the exact registered name, then search it on SSM's MyData SSM portal. Check business status, registration date, and nature of business. A company claiming to do cybersecurity but registered as a food stall is a serious mismatch worth questioning.

向对方索取完整注册名称(不是品牌名),再到 SSM 的 MyData SSM 平台查询。重点看三项:公司状态是否为 Active、注册日期是否过新(例如三个月内成立却声称做过大型项目)、业务性质是否与网络安全相关。若一家声称做渗透测试的公司,注册业务却是餐饮或零售,就该追问原因。查证本身免费,花五分钟能省下几千令吉的损失。

Read the Payment Terms Before the Job | 先看清付款条件再谈工作内容

Legit clients pay via bank transfer to your own account, or through platforms like Upwork and Fiverr. Suspicious signs include paying you in crypto only, using a third party's account, or asking you to receive and forward money for others.

正规客户通常用银行转账到你本人名下的账户,或通过 Upwork、Fiverr、Toptal 等平台托管付款。危险信号包括:只肯用加密货币付款、用第三方账户转钱给你、要求你“帮忙收钱再转给其他人”(这可能是钱骡,触犯马来西亚刑事法典)。本地自由职业也可用 DuitNow 收款,但要注意对方是否愿意留下可追溯的转账记录。任何要求你先垫付设备费、软件授权费的,一律拒绝。

Match Pay Rates Against Real Market Data | 用真实行情判断报酬是否合理

Entry-level vulnerability triage or log review in Malaysia pays roughly MYR 25 to 60 per hour. Junior penetration testing engagements often run MYR 1,500 to 4,000 per project. If an offer promises MYR 15,000 a month for two hours daily, treat it as a scam.

在马来西亚,初级漏洞分类、日志审阅类工作时薪大约 25 至 60 令吉;初级渗透测试项目常见报价为 1,500 至 4,000 令吉一个项目;有 OSCP 或 CREST 认证的中级人员,日薪可达 800 至 1,500 令吉。若对方声称每天做两小时、月入 15,000 令吉,几乎可以判定是骗局。把报价与行情对照,低于行情太多是剥削,高于行情太多是诱饵,两者都要警惕。

Test Their Technical Depth With One Question | 用一个技术问题测试对方深度

Ask one concrete question about their stack: which SIEM do they run, how do they handle false positives, or what their last incident report looked like. Real security teams answer specifically. Scammers give generic praise and pivot back to money.

抛出一个具体技术问题,例如:你们用哪套 SIEM(Splunk、Elastic 还是 Wazuh)?误报率怎么处理?上一次事件响应的报告结构是什么?真实的安全团队会给出细节,甚至反问你的经验。骗局方通常只会夸你“很合适”,然后迅速把话题拉回交钱或提交个人资料。若对方连基本术语都用错(例如把防火墙说成防毒软件),基本可以结束对话。

Protect Your Identity and Bank Details | 守住身份证与银行资料

Never send a photo of your MyKad front and back to an unverified party. Never share online banking credentials. If a client insists on your MyKad before any contract exists, ask for their SSM number and a signed agreement first.

不要向未经核实的对象发送身份证(MyKad)正反面照片,也不要提供网上银行账号密码。若对方坚持在签约前就要身份证,先要求对方提供 SSM 注册号与正式合约。正规雇主会在录用流程中收集资料,但会说明用途并签署隐私条款。若有人要你“帮忙注册公司”或“借出银行账户收钱”,这已涉及洗钱风险,应立即拒绝并向警方或国家银行举报。

Build Verifiable Skills Weekly | 每周固定投入建立可验证技能

Block 8 to 10 hours weekly: two hours on TryHackMe or Hack The Box, two hours reading CVE details, two hours on a home lab, two hours writing up findings publicly. Documented work beats claimed experience every time.

每周固定投入 8 至 10 小时:2 小时做 TryHackMe 或 Hack The Box 的实战房间;2 小时读 CVE 详情与厂商公告;2 小时搭家庭实验室(可用 VirtualBox 加 Kali Linux);2 小时把发现写成公开笔记,放在 GitHub 或个人博客。持续三个月后,你手上会有可展示的成果,而不是空口说“我懂网络安全”。真实机会往往来自这些作品,而不是陌生私信。

Use Local Job and Freelance Channels | 善用本地求职与自由职业渠道

Legit openings appear on JobStreet, Hiredly, LinkedIn, and MyCareersFuture for cross-border roles. For freelance work, use Upwork or Fiverr with escrow. Avoid any opportunity that only exists inside a private chat group.

本地正规职位常见于 JobStreet、Hiredly、LinkedIn,以及政府支持的 MyFutureJobs。跨境远程岗位可看 MyCareersFuture(新加坡)与 Wellfound。自由职业优先选有托管机制的 Upwork、Fiverr、Toptal。凡是只在私密聊天群组里流传、没有公司页面、没有可查记录的机会,一律视为高风险。把时间花在可公开验证的渠道,回报率远高于追逐神秘内推。

Understand Tax and Invoice Basics | 搞懂报税与开票基本规则

Freelance income in Malaysia is taxable. Keep every invoice and bank statement. If annual income exceeds the threshold, register for MyInvois when required. Set aside roughly 15 to 25 percent of each payment for tax.

在马来西亚,自由职业收入属于应税收入,需向 LHDN 申报。保留每一张发票与银行对账单,至少存七年。若年收入达到规定门槛,需按 MyInvois 分阶段要求开具电子发票。建议每收到一笔款项,先拨出 15% 至 25% 作为税务储备,避免报税季手忙脚乱。若客户要求你开“服务费”却不愿提供公司资料,这既影响你的报税,也可能是对方在规避自身责任。

Write a One-Page Evidence Trail | 留下一页式证据链

Keep one document per opportunity: company name, SSM number, contact channel, agreed scope, rate, payment method, and dates. If things go wrong, this record supports a police report or a platform dispute.

为每个机会建立一页记录:公司全名、SSM 注册号、沟通渠道、约定工作范围、报价、付款方式、关键日期。若发生纠纷,这份记录可用于向平台申诉、向警方报案,或向马来西亚消费者索赔仲裁庭(TTPM)提出小额索偿。很多人吃亏就吃亏在“什么都没留下”。花十分钟记录,比事后花十小时追讨划算得多。这也是专业自由职业者的基本习惯。

Know When to Walk Away | 知道什么时候该抽身

If you feel rushed, if payment terms keep changing, if they avoid written confirmation, or if your gut says something is off, walk away. There is always another opportunity. Losing a fake job costs nothing.

当你感到被催促、付款条件一再更改、对方始终不愿书面确认、或直觉告诉你不对劲时,就抽身离开。市场上永远有下一个机会,放弃一个假机会的成本是零,而陷进去可能要赔上几千令吉、个人资料,甚至被卷入洗钱案件。把这份清单存下来,遇到新机会就逐条打勾。安全从业者的第一课,是先保护自己。

💡 Key Takeaway | 核心要点:把核查变成习惯:上 SSM 查公司、用马来西亚真实行情比对报酬、守住身份证与银行资料、留下书面证据链。冷静核实永远比急于接单更值钱,也更安全。 Use a repeatable checklist: verify the company on SSM, compare pay against real Malaysian rates, protect your MyKad and bank details, and keep a written evidence trail. Discipline beats desperation.

 · 

📚 Related Reading | 相关阅读: Previous Article | 上一篇 Earlier Article | 更早一篇 Home | 首页
← Back to Home | 返回首页