Sr Cloud Security Engineer

15 hours ago


Greater Kuala Lumpur, Malaysia YO HR Consultancy Full time 120,000 - 200,000 per year

Job location: Kuala Lumpur, Malaysia

Qualifications

● 6–8+ years in Cloud Security Engineering, with AWS specialization.

● Deep knowledge of VPC segmentation, subnets, firewalling, and Zero Trust architectures.

● Strong expertise in Kubernetes/EKS security (network policies, admission controllers, pod runtime security).

● Proven track record implementing EDR, DLAP/DLP, and DNS protection strategies.

● Strong experience with Terraform and IaC security automation.

● Advanced knowledge of encryption-in-transit, -at-rest, and -in-use (KMS, TLS, Nitro, Enclaves).

● Hands-on with SIEM, anomaly detection, and ML-based attack prevention.

● Familiarity with compliance frameworks (CIS, NIST 800-53, ISO 27001, SOC2, GDPR, ASIC, ESMA).

Preferred Certifications

● AWS Certified Security – Specialty (required)

● AWS Solutions Architect – Professional

● AWS Advanced Networking – Specialty

● Certified Kubernetes Security Specialist (CKS)

● HashiCorp Terraform Associate (with security modules focus)

● CISSP (Certified Information Systems Security Professional)

● CCSP (Certified Cloud Security Professional)

● SANS GIAC Cloud Security Certifications (GCSA, GCLD, GDSA)

● ISO 27001 Lead Implementer/Auditor (plus for regulatory readiness)

Key Responsibilities

1. Network & VPC Segmentation

● Design and implement multi-VPC architectures with subnet micro-segmentation and Transit Gateway routing enforcement.

● Enforce Zero Trust network segmentation between workloads, users, and external partners.

● Apply strict ingress/egress controls with AWS Network Firewall, Security Groups, and NACLs.

2. Firewalling, DNS & Threat Prevention

● Deploy AWS Network Firewall with custom Suricata/DPI rulesets.

● Apply AWS WAF Advanced Protections for APIs, trading platforms, and client portals.

● Harden DNS with Route 53 Resolver DNS Firewall, enforcing global anti-tunneling and anti-spoofing policies.

● Define and monitor DLAP/DLP prevention policies to prevent data exfiltration across all workloads.

● Integrate EDR (CrowdStrike, SentinelOne) for all EC2, container, and serverless workloads.

3. Encryption & Data Security

● Enforce encryption at rest, in transit, and in use (KMS, ACM, HSM, TLS 1.3, Nitro Enclaves).

● Automate key lifecycle management and cross-region rotation.

● Apply confidential computing protections for financial and trading workloads.

4. Kubernetes & Virtualization Security

● Secure EKS, ECS, and Kubernetes clusters with pod-level network policies, RBAC/ABAC, and runtime security.

● Implement container image scanning (ECR, third-party registries) and vulnerability management pipelines.

● Deploy Kubernetes-native firewalls and admission controllers for Zero Trust enforcement.

● Harden virtualized workloads (VMs, WorkSpaces, VMware on AWS) with endpoint monitoring and network micro-segmentation.

● Establish runtime anomaly detection for containerized and virtualized workloads (Falco, GuardDuty for EKS, Datadog).

5. Anomaly Detection & Attack Prevention

● Implement AI/ML-based anomaly detection for network, DNS, and workload behaviors.

● Define preventive playbooks for insider threats, DNS tunneling, and privilege escalation.

● Correlate findings from GuardDuty, WIZ, Inspector, and SIEM platforms to predict and prevent attacks.

● Lead threat modeling and red team exercises across cloud and container environments.

6. Infrastructure as Code & Automation

● Build secure Terraform modules for AWS, Kubernetes, and firewall policies.

● Embed compliance-as-code into CI/CD pipelines (OPA, Sentinel).

● Automate posture drift detection with Terraform + WIZ/Security Hub integrations.

● Drive adoption of GitOps workflows for immutable security deployment.

7. Observability & Incident Response

● Design multi-region SIEM dashboards (AWS OpenSearch, CloudWatch, Grafana, Loki).

● Integrate ISeeFirst alerting into Jira, Slack, and PagerDuty workflows.

● Lead incident response and containment for anomalies in AWS, Kubernetes, and virtualized workloads.

● Build automated response pipelines (e.g., isolate compromised containers or VPC subnets automatically).



  • Kuala Lumpur, Kuala Lumpur, Malaysia EPS Ventures Sdn Bhd Full time 80,000 - 150,000 per year

    Location: Bangsar South, KLWorking Hour: Monday-Friday, 9am-6pm (Onsite, Flexi Working Hour)Industry: E-wallet IndustryResponsibilities:Design and implement secure cloud architectures in AWS, Azure, or Alibaba Cloud.Implement and enforce strong Identity and Access Management (IAM) controls, including least privilege, RBAC, MFA, and privileged access...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Aarorn Technologies Inc Full time 50,000 - 80,000 per year

    Company DescriptionAarorn Technologies Inc., based in Guelph, ON, is a technology firm specializing in Intelligent Process Automation and consulting services. The company offers Managed RPA as a Service, cloud-based configurable bots, as well as comprehensive development and maintenance of process automation solutions. AarornTech collaborates with...


  • Greater Kuala Lumpur, Malaysia LanceSoft, Inc. Full time 120,000 - 180,000 per year

    Job Title: Sr. Infrastructure & Cloud SpecialistLocation: QATARContract: 3 YearsOverview:Responsible for designing, architecting, and managing secure, scalable, and resilient hybrid (on-prem + cloud) infrastructures across Azure, AWS, and/or GCP. The role requires strong technical leadership, deep cloud/infrastructure expertise, and hands-on experience with...


  • Greater Kuala Lumpur, Malaysia Appnovation Full time 120,000 - 200,000 per year

    About UsAppnovation is a global, full-service digital partner that combines Strategy, Experience & Design, Engineering and Managed Services. We build digital solutions that deliver real impact today and serve as foundations for future growth. Bold ambition. Practical action. Endless possibilities.About The RoleAs a member of the IT team, the Sr. Associate,...


  • Greater Kuala Lumpur, Malaysia InfoTech Consultancy Full time 80,000 - 200,000 per year

    experience in AWS IT/ Security Infra Design and Implementation.Good experience in AWSGood experience in IT Security and Infra DesignMust have Done ImplementationGood communicational SkillsGood Experience in Cloud Security


  • Kuala Lumpur, Kuala Lumpur, Malaysia G2G Full time $80,000 - $120,000 per year

    Security Architecture & Implementation:  Design and implement secure, scalable, and resilient cloud infrastructure architectures across AWSIdentity & Access Management (IAM):  Enforce the principle of least privilege by implementing and managing robust IAM policies, Role-Based Access Control (RBAC), and Multi-Factor Authentication (MFA).Network Security:...


  • Kuala Lumpur, Kuala Lumpur, Malaysia hiringplug™ Full time 120,000 - 240,000 per year

    Senior Cloud Security Engineer – AWS & KubernetesLocation:On-site - Kuala Lumpur, MalaysiaAbout the Company:Our client is a global fintech company delivering advanced online trading platforms, combining innovation, scalability, and high-performance solutions for clients worldwide.Industry:Global Fintech / Trading PlatformsRole OverviewWe are seeking...


  • Greater Kuala Lumpur, Malaysia LanceSoft, Inc. Full time 160,000 - 240,000 per year

    Position- Senior Security Operations SpecialistLocation- QatarContract Period- 3 yearsSUMMARYSenior Security Operations Specialist responsible for designing, implementing, and optimizing security controls across on-prem and cloud environments, while acting as the internal technical authority for SOC operations, incident validation, and overall security...


  • Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, , Malaysia Cloud Kinetics Technology Solutions Private Full time 60,000 - 120,000 per year

    Job Role: CloudPlatform EngineerWork Location: TRX, KualaLumpur, MalaysiaMode: Work fromOffice 5 days a week Applicants must have work authorization in Malaysia  SUMMARY:Provides integrations with corporate datacenters, sharedcloud infrastructure services, Works on engineering and continuous improvementof infrastructure stacks, templates, images, and other...


  • Bangsar South, Kuala Lumpur, Malaysia GAMER2GAMER SDN. BHD. Full time $100,000 - $130,000 per year

    Security Architecture & Implementation: Design and implement secure, scalable, and resilient cloud infrastructure architectures across AWS/GCP/AzureIdentity & Access Management (IAM): Enforce the principle of least privilege by implementing and managing robust IAM policies, Role-Based Access Control (RBAC), and Multi-Factor Authentication (MFA).Network...