Vulnerability & Security Posture Management Engineer
1 week ago
**BAT is evolving at pace into a global multi-category business. Our purpose is to create A Better Tomorrow by Building a Smokeless World.
To achieve our ambition, we are looking for colleagues who are ready to join us on this journey Tomorrow can't wait, let's shape it together
BAT Digital Business Solution has an exciting opportunity for a Vulnerability & Security Posture Management Engineer in Subang Jaya
Your Key Responsibilities Will Include
Security Posture Management**
- Develop and implement continuous monitoring and enforcement of security configurations and policies across various platforms, leveraging tools like Microsoft E5 capabilities (e.g., Defender External Attack Surface Management, Defender for Identity, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps)
- Drive the reduction of configuration drift and ensure compliance with BAT security and technical standards, and external regulations
Vulnerability Management
- Lead the execution and optimization of vulnerability scanning using Qualys and other tools
- Analyze, prioritize, and report on vulnerabilities based on risk, exploitability, and business impact
- Proactively monitor threat intelligence feeds and advisories (e.g., CVE, CISA, NCSC, vendor bulletins) to stay current on emerging vulnerabilities and exploits
- Collaborate with IT and BAT partners to ensure timely and effective remediation efforts are implemented and tracked
Attack Surface Management
- Continuously discover and inventory all internal and external assets, including cloud resources, to maintain a comprehensive view of the attack surface
- Monitor for changes in the attack surface and proactively assess new exposures
Reporting & Strategy
- Generate clear, actionable reports and dashboards for technical teams and leadership detailing vulnerability status, trends, and risk reduction over time
- Contribute to the strategic planning and selection of security tools and technologies
What are we looking for?
- Minimum 3+ years of experience in information security, with hands-on focus on vulnerability management, threat analysis, or security posture management.
Deep hands-on experience with commercial and open-source security tools, including
Qualys (or similar platforms like Tenable/Rapid7).
- Microsoft E5 Security Stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Cloud Apps) and Microsoft Exposure Management.
Cloud (e.g., Azure, AWS)
Understanding of threat intelligence sources (e.g., CVE, CISA, vendor advisories) and how to apply them to remediation efforts.
- Strong ability to translate raw technical data into business-relevant risk and remediation priorities
- Excellent communication, collaboration, and project management skills to drive cross-functional security initiatives
What we offer you?
- We offer a market leading annual performance bonus (subject to eligibility)
- Our range of benefits varies by country and includes diverse health plans, initiatives for work-life balance, transportation support, and a flexible holiday plan with additional incentives
- Your journey with us isn't limited by boundaries; it's propelled by your aspirations. Join us at BAT and become a part of an environment that thrives on internal advancement, where your career progression isn't just a statement – it's a reality we're eager to build together. Seize the opportunity and own your development; your next chapter starts here.
- You'll have access to online learning platforms and personalized growth programs to nurture your leadership skills
- We prioritise continuous improvement within a transformative environment, preparing for ongoing changes
**WHY JOIN BAT?
We're one of the few companies named as a Global Top Employer by the Top Employers Institute – certified in offering excellent employee conditions.
Collaboration, inclusion and partnership underpin everything we do here at BAT. We are looking forward to enabling every individual to thrive, regardless of gender, sexual orientation, marital or civil partnership status, gender reassignment, race, religion or belief, colour, nationality, ethnic or national origin, disability, age, skills, experience, education, socio-economic and professional background, veteran status, perspectives and thinking styles. We know that embracing talent from all backgrounds is what makes us stronger and best prepared to meet our business goals.
We see the career breaks as opportunities not obstacles. Through The Global Returners program, we support professionals looking to restart their careers after an extended absence from the workforce (e.g. time out caring for family, parental leave, national service, sabbatical and/or starting an own venture).
Come bring your difference and see what is possible for you at BAT. Learn more about our culture and our award winning employee experience here.
If you require any reasonable adjustments or accommodations to help you perform at your best during the recruitment process, you are encouraged to notify us. We are fully committed to support you by making appropriate arrangements for you to demonstrate your full potential.**
-
Patching and Vulnerability Engineer
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Ekco Full timeAbout Ekco:Founded in 2016 Ekco is now one of the fastest growing cloud solution providers in EuropeWe specialise in enabling companies to progress along the path of cloud maturity, managing transformation and driving better outcomes from our customers' existing technology investments. In a few words, we take businesses to the cloud and backWe have over 600...
-
Lead Security Engineer
6 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia amIT Global Solution Full timeKey ResponsibilitiesActs as a team leader providing guidance to Security Engineering team and sets goals and assists the team in accomplishing those goals.Manage security architecture and provide consultancy to strengthen security designCoordinate with the team to manage security tools (IPS, SIEM, VA scan, DLP, AV, ATP)Coordinate with project manager to...
-
Information Security Engineer
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Lavu Tech Solutions Sdn Bhd Full time 60,000 - 120,000 per yearKey Responsibilities• Coordinate with the team to manage security tools (IPS, SIEM, VA scan, DLP, AV, ATP)• Coordinate with project manager to deliver security projects/initiatives and provide technicalconsultancy• Coordinate with the vendor to perform maintenance and enhancement activities on security tools.• Coordinate vulnerability/security...
-
Vulnerability Management
15 hours ago
Kuala Lumpur, Kuala Lumpur, Malaysia Qboyd software solutions Full timePosition: Vulnerability ManagementLocation: Kuala Lumpur, MalaysiaDuration: 14 Months ContractExperience: 7+ YearsJob Description:Primary Skills :- Vulnerability Management, Process GovernanceSecondary Skills:- Good communication, patchingCyber Security (CS) is a critical function within Standard Chartered Bank. The CS team is instrumental in ensuring the...
-
Junior Cyber Security Engineer
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Skill Quotient Technologies Inc Full time 42,000 - 80,000 per yearJob Title: Junior Cyber Security EngineerExperience Required: 6 months to 2 yearsLocation: On-site (Bangsar South, Malaysia)OverviewWe are looking for a motivated Junior Cyber Security Engineer to support our security operations and help strengthen our overall security posture. This role is ideal for early-career professionals who are eager to grow, learn,...
-
Vulnerability Management Analyst
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Avows Technologies Sdn Bhd Full timeExperience: 1 to 3 yearsMalaysian OnlyPosition Objective:The role of the candidate is to be a part of GIS Cybersecurity team and lead the analysis of vulnerabilities .Roles and Responsibilities:Vulnerability Management - Work collaboratively with Product and Technology team members to identify, validate, communicate, and track vulnerabilities in AIA's...
-
Security Engineer, Group Tech
15 hours ago
Kuala Lumpur, Kuala Lumpur, Malaysia Hong Leong Bank Berhad Full timeOverview:The Security Engineer is a critical role responsible for driving and executing the security engineering strategy across the organization. This individual will play a key role in designing, implementing, and maintaining secure systems, applications and infrastructure. The ideal candidate is a highly motivated and experienced security professional...
-
VP, Information Security Engineering Lead
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia UOB Full time 80,000 - 180,000 per yearAbout UOBUnited Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...
-
Sr. Specialist – Vulnerability Management
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Kris Infotech Sdn Bhd Full timeWe're Hiring: Sr. Specialist – Vulnerability Management (Remediation) 12-Month Contract | Leading Global Bank**We are looking for an experiencedSenior Specialist – Vulnerability Management (Remediation)to join our client, a top-tier global financial institution. This role plays a critical part in strengthening the bank's cyber defense and ensuring...
-
Network System Security Engineer
1 week ago
Kuala Lumpur, Kuala Lumpur, Malaysia Smart Screen Asia Full timeKey ResponsibilitiesNetwork & System Security ArchitectureDesign and implement secure network architectures (e.g., segmentation, zero-trust, VPNs, firewalls) to protect data in transit and at rest.Define security requirements for new systems, applications, and network changes.Collaborate with infrastructure, DevOps, and application teams to embed security...