- Type
- Full-time
- Department
- Engineering
- Education
- Master
- Closing date
- Today
- Source
- CareersPage
Description
JOB SUMMARY
We are looking for a skilled and proactive Cybersecurity Engineer to join our IT/Security team. In this role, you will be responsible for designing, implementing, and maintaining security measures that protect our organization's systems, networks, and data from cyber threats. You will play a key role in identifying vulnerabilities, responding to incidents, and strengthening our overall security posture.
JOB DESCRIPTION
- Design, implement, and maintain security infrastructure including firewalls, IDS/IPS, SIEM, endpoint protection, and VPN solutions.
- Conduct regular vulnerability assessments, penetration testing, and security audits across networks, applications, and systems.
- Monitor security alerts and logs to detect, investigate, and respond to potential security incidents in a timely manner.
- Develop and maintain incident response plans, playbooks, and disaster recovery procedures.
- Perform root cause analysis for security incidents and recommend corrective/preventive actions.
- Implement and manage identity and access management (IAM) controls, including least-privilege and role-based access.
- Collaborate with IT and DevOps teams to embed security best practices into system architecture, CI/CD pipelines, and cloud environments.
- Stay current with emerging threats, vulnerabilities, and security technologies, and recommend improvements accordingly.
- Ensure compliance with relevant security standards and regulations (e.g., ISO 27001, PCI-DSS, NIST, PDPA).
- Conduct security awareness training and support internal teams with security best practices.
- Maintain documentation for security policies, procedures, and configurations.
- Participate in on-call rotation for critical security incident response, as needed.
JOB REQUIREMENTS
- 3–6 years of hands-on experience in cybersecurity engineering, network security, or a related field.
- Bachelor's degree in Computer Science, Information Security, IT, or a related field (or equivalent practical experience).
- Solid understanding of network security concepts (firewalls, VPNs, IDS/IPS, network segmentation).
- Experience with SIEM tools (e.g., Splunk, QRadar, Microsoft Sentinel) and log analysis.
- Familiarity with vulnerability scanning and penetration testing tools (e.g., Nessus, Qualys, Burp Suite, Metasploit).
- Experience securing cloud environments (AWS, Azure, or GCP).
- Knowledge of scripting/automation languages (Python, Bash, PowerShell) for security tooling.
- Understanding of security frameworks and standards (ISO 27001, NIST CSF, CIS Controls, MITRE ATT&CK).
- Experience with endpoint detection and response (EDR) and antivirus/anti-malware solutions.
- Familiarity with identity and access management (IAM), Active Directory, and multi-factor authentication (MFA).
- Relevant certifications such as CEH, CompTIA Security+, CISSP, OSCP, or GIAC certifications are an advantage.
- Experience with DevSecOps practices and integrating security into CI/CD pipelines.
- Exposure to regulatory compliance requirements in Malaysia (e.g., PDPA) or the region.
- Prior experience in incident response or digital forensics.
- Strong analytical and problem-solving abilities.
- Excellent communication skills, with the ability to explain technical risks to non-technical stakeholders.
- Ability to work independently and collaboratively in a fast-paced environment.
- High attention to detail and a proactive, security-first mindset.
GET IN TOUCH :
Please apply online or send your CV to [email protected]
For more details, feel free to reach out directly at :
WhatsApp link: wa.me/6282137682541