about the company
Our client is a leading and well-established financial institution in Malaysia with a strong focus on cybersecurity, cloud transformation and technology resilience.
The organisation is investing heavily in strengthening its cloud security capabilities across enterprise environments and enhancing its vulnerability management and DevSecOps practices. You will join a dedicated IT Security function working across cloud, engineering, security operations and risk teams to protect critical technology environments.
...
about the job
We are looking for a Senior Cloud Vulnerability Management & DevSecOps professional to strengthen the organisation's cloud security and Threat & Vulnerability Management capabilities.
This is a hands-on technical role combining Cloud Penetration Testing, Offensive Security, Cloud Vulnerability Management and DevSecOps.
You will be responsible for identifying and validating vulnerabilities across AWS, Microsoft Azure and GCP, performing cloud penetration testing and red team activities, driving remediation, and embedding security controls throughout CI/CD pipelines.
Key Responsibilities:
- Lead and perform cloud penetration testing and red team engagements across AWS, Azure and GCP environments.
- Identify and exploit cloud misconfigurations, vulnerabilities, privilege escalation paths and security weaknesses across cloud infrastructure.
- Manage end-to-end Cloud Vulnerability Management, including vulnerability identification, risk-based prioritisation, remediation tracking and post-remediation validation.
- Develop and maintain cloud security assessment and offensive testing methodologies.
- Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secrets scanning, container security and Infrastructure-as-Code (IaC) scanning.
- Support DevSecOps and software supply-chain security, including SBOM, software provenance, code signing and open-source governance.
- Assess cloud security across IAM, networking, compute, serverless, containers/Kubernetes, storage and logging.
- Work closely with Cloud Engineering, DevSecOps, Security Architecture, Security Operations and remediation teams to provide practical security recommendations.
- Develop custom scripts, tools and proof-of-concepts using Python, Bash or PowerShell where required.
- Utilise offensive security tools such as Pacu, ScoutSuite, Prowler, Burp Suite and Nmap.
- Apply MITRE ATT&CK for Cloud, adversary simulation and attacker TTPs to cloud security assessments.
- Define and track remediation SLAs, risk exceptions and risk treatment plans.
- Produce vulnerability dashboards, reports and metrics for technical and senior management stakeholders.
- Mentor and coach junior penetration testers and contribute to security knowledge-sharing initiatives.
about the manager/team
You will join the organisation's Threat & Vulnerability Management / IT Security function and report to the Lead for Cloud Vulnerability Management & DevSecOps, with matrix exposure to the Head of Threat & Vulnerability Management.
The team works closely with Cloud Engineering, DevSecOps, Security Architecture, Security Operations and Vulnerability Remediation teams to continuously improve the organisation's cloud security posture.