Senior Product Security Engineer
1 week ago
Senior Product Security Engineer – Penetration Testing and AI Security
Engineering & Technology, Kuala Lumpur, Malaysia
About Us:
At Sitecore, our mission is to simplify how brands reach, engage, and serve people by delivering intelligent, personalized digital experiences that connect the world. We empower the world's most iconic brands to build lifelong relationships with their customers—seamlessly, smartly, and at scale.
As the leading provider of agentic digital experience software, Sitecore brings together content, commerce, and data into one composable platform that enables brands to deliver millions of meaningful, adaptive experiences every day. Trusted by global leaders such as American Express, Porsche, Starbucks, and L'Oréal, Sitecore helps brands transform engagement through experiences that are not only personalized but predictive and dynamic.
Our foundation is our people—a diverse, passionate, and collaborative global team spanning over 25 countries. We believe that every experience matters, and that belief starts with how we work together.
Our values
guide how we lead, innovate, and connect. They are the behaviors that bring our mission and vision to life, every day, in every interaction.
As we continue to evolve, we are actively cultivating AI skills across our teams to unlock new levels of creativity, efficiency, and insight. From engineering to customer experience, AI capabilities are becoming integral to how we design, build, and deliver the next generation of digital experiences.
Learn more at
.
About the Role:
As a
Senior Product Security Engineer
with a focus on
Penetration Testing and AI Security
, you will play a critical role in identifying, exploiting, and mitigating vulnerabilities across Sitecore's platforms, infrastructure, and AI-driven features. You will work closely with product engineering teams, cloud operations, and compliance stakeholders to ensure our systems are resilient against evolving threats, including those introduced by AI technologies.
What You'll Do:
Penetration Testing & Vulnerability Assessment
- Perform advanced penetration tests on Sitecore products, services, and cloud environments.
- Simulate real-world attack scenarios to identify weaknesses in applications, APIs, and infrastructure.
- Develop and maintain automated testing frameworks for continuous security validation.
AI Security Testing
- Assess AI/ML models and pipelines for adversarial vulnerabilities, data poisoning, and model inversion risks.
- Evaluate prompt injection, jailbreak attempts, and other LLM-specific attack vectors.
- Collaborate with AI engineering teams to implement robust security controls for AI-driven features.
Security Research & Threat Modelling
- Stay ahead of emerging threats, attack vectors, exploit techniques, including AI-related risks.
- Conduct threat modelling for new features and architectures.
Collaboration & Remediation
- Work with engineering teams to prioritize and remediate vulnerabilities.
- Provide actionable guidance and best practices for secure coding and architecture.
Reporting & Compliance
- Document findings with detailed technical reports and executive summaries.
- Support compliance initiatives (ISO 27001, SOC 2, GDPR) through security testing and evidence collection.
WAF Administration
- Manage and optimize WAF configurations for security and performance.
- Implement and maintain WAF (Web Application Firewall) rules, DDoS protection, and bot mitigation.
- Collaborate with DevOps and infrastructure teams to ensure WAF integration aligns with security architecture.
What You Need to Succeed:
- 8+ years in security engineering with a strong focus on penetration testing.
- Hands-on experience with AI security testing or adversarial ML techniques is a strong plus.
- Expertise in tools such as Burp Suite, Metasploit, Nmap, and custom exploit development.
- Strong knowledge of OWASP Top 10, SANS CWE, and secure coding principles.
- Familiarity with AI/ML frameworks (TensorFlow, PyTorch) and LLM security considerations.
- Cloud security (Azure preferred) and containerized environments (Docker/Kubernetes).
- Comfortable working in a fast-paced, dynamic environment with shifting priorities.
Additional Skills That Could Set You Apart:
- Familiarity with headless CMS architecture, front-end frameworks, and web technologies.
- OSCP, CRTO, GPEN or similar advanced penetration testing certifications.
- AI security certifications or demonstrated research in adversarial ML.
- CISSP or equivalent for broader security knowledge.
Why Sitecore?
At Sitecore, we offer a vibrant work culture, a collaborative environment, and the opportunity to work on products that shape digital experiences globally. We're dedicated to fostering growth, innovation, and a commitment to our employees' professional and personal development. Be part of a visionary, innovation-driven team shaping the next era of AI-powered content management in a leading composable DXP.
Sitecore is proud to be an equal opportunity workplace. We are committed to equal employment opportunity without unlawful regard to race, color, ancestry, religion, gender, national origin, sexual orientation, age, citizenship, marital status, disability, veteran status or any other local legally protected characteristic.
Carmen Cheong
-
Senior Product Security Engineer
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Sitecore Malaysia Sdn. Bhd. Full timeEngineering & TechnologyKuala Lumpur,MalaysiaDescription*Senior Product Security Engineer – Penetration Testing and AI Security* Engineering & Technology, Kuala Lumpur, MalaysiaAbout Us:At Sitecore, our mission is to simplify how brands reach, engage, and serve people by delivering intelligent, personalized digital experiences that connect the world. We...
-
Senior Product Security Engineer
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Sitecore Full time $1,000,000 - $1,500,000 per yearDescriptionSenior Product Security Engineer – Penetration Testing and AI Security Engineering & Technology, Kuala Lumpur, Malaysia About Us: At Sitecore, our mission is to simplify how brands reach, engage, and serve people by delivering intelligent, personalized digital experiences that connect the world. We empower the world's most iconic brands...
-
Senior Information Security Engineer
3 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Oxydata Software Full timeNow Hiring: Senior Information Security EngineerEmployment Type: Full-time Experience Required: Minimum 3 Years | Certification: CISSP MandatoryWe are seeking a proactive and technically strong Senior Information Security Engineer to design and implement enterprise-wide security infrastructure. The ideal candidate will have solid hands-on experience,...
-
Senior Cloud Security Engineer
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Edison Smart® Full timeSenior Cloud Security Engineer (AWS)We're looking for a hands-onSenior Cloud Security Engineerto take ownership of cloud and container security across complex AWS environments. The focus is onZero Trust, Terraform automation, Kubernetes hardening, encryption, and threat detection at scale.What You'll DoDesign and secure multi-VPC architectures with full...
-
Senior Network Security Engineer
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Singapore Telecommunications Limited Full timeBe a part of something BIGThe Senior Network Security Engineer is responsible for working on network security projects, including the design, implementation, and operations of Network security infrastructure. This role involves working on technologies such as but not limited to Firewalls (Palo Alto/Checkpoint/Fortinet), VPN, IPS/IDS, NAC (Forescout/ISE), F5...
-
Senior IT Security Engineer
7 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia amIT Global Solutions Pvt Ltd Full time•A Bachelor's Degree in Computer Science, Engineering, Information Systems or its equivalent.•Minimum 8-15 years of related working experience. Knowledge of IT security is essential. Industry certifications will be a plus e.g. CRISC, CISSP, CEH, CISM and CISA.•Highly result oriented and can work independently. Must be a self-reliant team player who is...
-
Senior Pre-Sales Security Engineer(TPE)
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Sekuro Asia Full timeAbout SekuroWe are the challenger in the cyber security market both in Australia and Southeast Asia. We are founder-led and have a fresh and direct approach to working with our clients. Over our journey we have helped many organisations of different sizes in improving their understanding of cyber security through uplifting their existing capability. We do...
-
Senior Product Development Engineer
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia Airswift Full timePurposeThe FPSO Product Development senior engineer has the responsibility to assist the vessel product development team with naval architecture expertise and project engineering support. The role focuses on advancing new vessel products to a stage where they are ready for project implementation—either as part of technical framing, bid stages, or...
-
Senior Security Engineer
3 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia iSoftStone Full timeAbout Us:A leading global technology group, renowned for its extensive ecosystem of digital services and platforms. With a strong presence in cloud computing, mobile gaming, social media, and enterprise solutions, the organization supports millions of users and businesses worldwide. It emphasizes innovation, scalability, and security, making it a key player...
-
Senior Product Development Engineer
7 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia SBM Offshore Full timeSenior Product Development EngineerReq Id: 20604Job Family: Product DevelopmentLocation:Kuala Lumpur, MY, 50470Description:Imagine your career taking you to the depths of innovation and the heights of impact. Our people enable continuous progress. Their commitment, collective expertise, and unique capabilities are the engine room behind SBM Offshore's True....