Senior Security Engineer

2 weeks ago


Kuala Lumpur, Malaysia Crypto.com Full time
The Cybersecurity and Data Privacy team reports directly under the office of the CISO headed by Chief Information Security Officer (CISO) Jason Lau () who has over 23+ years of experience in the cybersecurity space, awarded Global Top 100 CISO, and also serves on the World Economic Forum, International Association of Privacy Professionals and more. The team comprises of multiple functions from Blockchain Security, Operational Security, Security Governance and Compliance and more. We drive a culture of having a growth mindset and being humble to help everyone achieve their potential. Security and Data Privacy Compliance first strategy which has been at the core of our company. The security team helped to drive us to be the first Crypto company worldwide to achieve ISO27001, ISO27701, ISO22301 and PCI:DSS (Level 1) certifications. Extremely detailed third party attested by international audit firm SGS and achieved "Adaptive (Tier 4)” – the highest level possible for the US National Institute of Standards and Technology (NIST) Cybersecurity Framework and the latest NIST Privacy Framework as well as SOC2 and many other regional certifications like the Data Protection Trust Mark. is seeking an experienced Senior Security Engineer to be at the forefront of securing our infrastructure. This role has the direct responsibility for supporting the Cloud Security, Vulnerability Management and Secure Configuration Management Programs. The Senior Security Engineer will support the improvement of the company’s cloud security posture primarily through the implementation & enhancement of native security controls across the organization’s cloud environments; the enforcement of configuration hardening & security compliance through cloud security posture management; and the implementation & enhancement of container security controls. The Senior Security Engineer will also contribute to cloud security logging, detection and response initiatives. The Senior Security Engineer will also support the company’s vulnerability and configuration management programs primarily through vulnerability lifecycle management - including advisory, scanning and reporting of vulnerabilities, and working with stakeholders to drive patching & remediation; and through the secure configuration management of the company’s workstations and servers. 

Responsibilities

Implement, manage and enhance cloud security controls - native cloud security controls, CSPM, CNAPP, container security controls, etc. Build, maintain, tune and enhance CSPM, CNAPP and container security rules and policies. Work with SIEM engineering on cloud security logging and cloud security threat detection use cases. Work with the SOC on cloud security response procedures and to implement automated containment runbooks. Improve cloud security logging, detection and response processes.  Manage and enhance the company’s vulnerability management lifecycle processes. Manage vulnerability and configuration scanning tools, setup vulnerability scanners, perform scheduled scans, tuning scanning profiles, etc. Review and triage vulnerability alerts/advisories to produce manageable reports for actionable next steps.  Assist in the analysis and remediation of findings discovered during scheduled internal and third party vulnerability scans and penetration tests Prepare security patch bundles for various types of endpoints (Windows, Linux, MacOS). Manage and enhance the company’s baseline security configuration program for workstations and servers. This involves maintaining and developing hardening standards and working with stakeholders to implement these standards across the organization. Ensure the timely delivery of compliance and regulatory reporting. Collaborate closely with the security compliance team to acquire the compliance and regulation requirements and ensure the program fulfill their needs Deliver on KRIs and KCIs for vulnerability management, secure configuration management and cloud security.

Requirements

7+ years of experience working in information security 5+ years of experience in cloud security or vulnerability management Cloud experience (AWS and Azure) in administrative management, policy management, platform management, cloud security controls management and DevOps integration is required. Coding, scripting, automation in GitHub and familiarity with Infrastructure as Code (IaC) in AWS/Azure will be an advantage.  Knowledge of common security frameworks such as CIS, NIST, PCI DSS etc. Able to articulate how vulnerabilities translates to cyber-risks Experience conducting security risk assessments Experience of using vulnerability management tools like Tenable, Qualys, InsightVM, Tripwire CCM, etc. Familiarity with Qualys will be an advantage.  Proficiency in a scripting language like Python, Ruby, PowerShell, or Bash is preferred. Information Security certifications (CISSP, SANS GIAC, Security+, etc.) a plus. High work ethic and sense of ownership for the delivered results. Excellent communication skills in English (spoken & written) and comfort communicating security risks and controls to technical and non-technical partners required. #LI-SF1#LI-MidSenior#LI-Hybrid

  • Kuala Lumpur, Malaysia Crypto.com Full time

    The Cybersecurity and Data Privacy team reports directly under the office of the CISO headed by Chief Information Security Officer (CISO) Jason Lau () who has over 23+ years of experience in the cybersecurity space, awarded Global Top 100 CISO, and also serves on the World Economic Forum, International Association of Privacy Professionals and more. The team...


  • Kuala Lumpur, Malaysia Snaphunt Full time

    The Offer5-day work week with a hybrid working arrangement.Excellent growth and career advancement opportunities.Competitive remuneration package.Great MNC (energy sector) working culture.The JobYou will be responsible for : Responsible for the end-to-end overall solution and services activities related to CyberSecurity requirements and new emerging related...


  • Kuala Lumpur, Malaysia Arashs Technology Full time

    "To begin as an INTEGRATOR, and finally an INNOVATOR."Arashs Technology is an information technology firm dedicated to assist institutions and organizations achieve their financial objectives by more effectively managing solutions that encompass analyzing, planning, and managing implementation of their information systems. It is in line with the company...


  • Kuala Lumpur, Malaysia Global Blue Full time

    Nature and aim of the position In this pivotal role as a Senior Network Engineer, you will integrate into a great team of senior network engineers at the forefront of shaping and nurturing our expansive worldwide data center networks. Your core mandate will involve architecting, designing, implementing, and operating cutting-edge enterprise data...


  • Kuala Lumpur, Malaysia AMK TECHNOLOGY SDN BHD Full time

    Application Security EngineerWhat you will do: Discover security vulnerabilities through design review, source code review and penetration testing, either manually or by using automated tools, and follow up on the remediation process Participant in relevant agile scrum meetings and provide professional recommendations on the design of security controls,...


  • Kuala Lumpur, Malaysia United Overseas Bank Full time

    AVP, Senior Platform Security Engineer, T&O Posting Date: 13-May-2023 Location: Kuala Lumpur, Wilayah Persekutuan, MY Company: United Overseas Bank (Malaysia) Bhd About UOB United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia...


  • Kuala Lumpur, Malaysia Speedcast Full time

    Sr. IP Network/Security EngineerThe Sr. IP Network/Security Engineer is an individual contributor with an advanced background in IP Network Engineering and NGFW deployment, configuration and administration.The primary objective of this role is to collaboratively extrapolate customer requirement as it primarily relates to the network security requirement and...


  • Kuala Lumpur, Malaysia VDart Technologies Pvt. LTD Full time

    VDart Malaysia is looking for a Senior DevOps Engineer.The RoleWe are looking for a Senior DevOps Engineer for a our on-site role. Your responsibilities will include:Designing, implementing, and maintaining our continuous integration and delivery pipeline. Work closely with cross-functional teams, including Developers, Quality Assurance (QA), and...


  • Kuala Lumpur, Malaysia MVC Resources Full time

    Working Arrangement: Hybrid We are looking for an experienced Endpoint Security Engineer to join our team. The ideal candidate will have a strong background in endpoint security, with experience in designing, implementing, and maintaining endpoint security solutions. The candidate should be familiar with the latest endpoint security technologies and have...


  • Kuala Lumpur, Malaysia MVC Resources Full time

    Job DescriptionWorking Arrangement: Hybrid We are looking for an experienced Endpoint Security Engineer to join our team. The ideal candidate will have a strong background in endpoint security, with experience in designing, implementing, and maintaining endpoint security solutions. The candidate should be familiar with the latest endpoint security...


  • Kuala Lumpur, Malaysia bp Full time

    Location - Malaysia - Kuala Lumpur - Travel required - No travel is expected with this role - Job category - Digital & technology - Relocation available - This role is not eligible for relocation - Job type - Professionals - Job code - RQ066706 - Experience level - Senior Job summary **Entity**: Innovation & Engineering **Job Family Group**: IT&S...


  • Kuala Lumpur, Malaysia FWD Life Insurance Corporation Full time

    About FWD Group FWD Group is a pan-Asian life insurance business with approximately 11 million customers across 10 markets, including some of the fastest growing insurance markets in the world. Established in 2013, FWD is focused on making the insurance journey simpler, faster and smoother, with innovative propositions and easy-to-understand products,...


  • Kuala Lumpur, Malaysia Averis Full time

    Grow your career with usHere at Averis, our common purpose is to improve lives by developing resources sustainably. Our people are crucial in helping us to realise our vision to be one of the best Global Business Solution (GBS) organization to support our customers in creating value for the Community, Country, Climate, Customer and Company.Role...


  • Kuala Lumpur, Malaysia Endava Full time

    Responsibilities Detect and respond to malicious behavior on cloud systems, SaaS, workstations, servers, and networks Optimizes threat detection products for data loss prevention (DLP), security information and event management (SIEM), advanced email protection, endpoint detection and response (EDR), antivirus, cloud security products, intrusion...


  • Kuala Lumpur, Malaysia Agensi Pekerjaan BTC Sdn Bhd Full time

    Open Position: IT System Security Engineer (MNC Organisation) An MNC Organisation is currently looking for IT System Security Engineer to join the team and based at the Kuala Lumpur office.Key responsibilities includes:Strong knowledge and experience in implementing Network Security or Server Security related productsExperience in vulnerability management,...


  • Kuala Lumpur, Malaysia United Overseas Bank Full time

    VP, Senior Information Security Specialist Posting Date: 06-May-2023 Location: Kuala Lumpur, Wilayah Persekutuan, MY Company: United Overseas Bank (Malaysia) Bhd About UOB United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia...


  • Kuala Lumpur, Malaysia Petroplan Full time

    KEY OBJECTIVE Lead the Engineering Data Management for the Project Development, ensuring efficient and impactful data utilization throughout the project lifecycle. Be the focal person to supervise and execute in Project database management and project insights development. Responsible to look after the Projects Document Control Management System, and...


  • Kuala Lumpur, Malaysia GO Markets Full time

    Basic Requirements:degree or higher in Computer Science, Information Technology, or related field preferred.of 5 years of experience as a network engineer or database administrator, with team management experience preferred.understanding of cloud service providers' network services, such as AWS VPC, Direct Connect, Route 53; IBM cloud services; Microsoft...


  • Kuala Lumpur, Malaysia GO Markets Full time

    Basic Requirements:degree or higher in Computer Science, Information Technology, or related field preferred.of 5 years of experience as a network engineer or database administrator, with team management experience preferred.understanding of cloud service providers' network services, such as AWS VPC, Direct Connect, Route 53; IBM cloud services; Microsoft...


  • Kuala Lumpur, Malaysia Snaphunt Full time

    The OfferWork within a company with a solid track record of successExcellent career development opportunitiesLeadership RoleThe JobYour responsibilities will include:Designing, implementing, and maintaining our continuous integration and delivery pipeline.Work closely with cross-functional teams, including Developers, Quality Assurance (QA), and...