
Information security Engineering specialist
- Kuala Lumpur
- Tetap
- Sepenuh masa
- Develop and implement platform security standards and co-design security schemas to ensure quality at the infrastructure build and configuration stage. Identify opportunities to automate manual security processes wherever feasible.
- Collaborate with business partners to implement security strategies and coordinate remediation efforts to ensure products meet safety and compliance requirements.
- Act as a subject matter expert in at least one core domain—cloud, infrastructure, or data.
- Provide hands-on support to teams on secure configurations and remediation approaches.
- Align security strategy, processes, and decision-making across multiple teams.
- Actively participate in governance frameworks and contribute to an inclusive, collaborative environment with engineers, developers, product owners, and managers.
- Drive the evolution of the security roadmap to anticipate and address future challenges.
- Offer technical guidance and manage dependencies and risks for squads and teams.
- Develop and communicate materials to help embed and measure security across cloud, infrastructure, and data environments.
- Mentor peers and promote continuous learning and professional development.
- 3+ years in security engineering or technical infrastructure roles.
- Minimum 3 years of cybersecurity experience focused on one or more of these areas: Cloud (AWS, Azure), Infrastructure (IAM, networking, endpoints), or Data (DLP, data lifecycle management).
- Hands-on experience designing scalable, secure architectures for data infrastructure, cloud, and data products in complex environments.
- Development experience in one or more object-oriented languages such as Python, Scala, Java, or C#, and/or cloud development experience (AWS, Azure, Alibaba, etc.).
- Familiarity with full-stack development.
- Proficiency with automation and scripting for security tasks, including infrastructure as code (IaC), CI/CD integration, and security tooling (e.g., vulnerability scanners, CNAPP, endpoint security, DLP).
- In-depth knowledge of technologies covering all stages of the data lifecycle.
- Foundational understanding of security standards and regulations including PCI-DSS, GDPR, CCPA, and SOX.
- Strong collaboration and influencing skills with the ability to guide teams through technical challenges.
- Commitment to continuous learning and improvement.