Deskripsi Pekerjaan
Public Mutual Berhad is seeking a highly skilled and proactive Senior System Security Engineer to join our infrastructure team in Kuala Lumpur. As a key member of our security operations, you will be responsible for fortifying our core system infrastructure, ensuring robust defense mechanisms against evolving cyber threats.
You will play a critical role in the lifecycle of our OS and application security posture, from vulnerability remediation and patch management to policy fine-tuning. The ideal candidate possesses a deep understanding of hardened operating systems, container security, and the intricacies of enterprise-grade application security. If you are passionate about building secure environments and have a knack for systematic problem-solving, we want to hear from you.
Tanggung Jawab
- Develop and maintain comprehensive patch management strategies for OS and middleware infrastructure.
- Implement and tune security policies across firewalls, endpoints, and application gateways to minimize attack surfaces.
- Lead system hardening initiatives to comply with internal and industry security standards.
- Monitor and analyze system logs to detect anomalies and proactively mitigate security vulnerabilities.
- Collaborate with cross-functional teams to integrate security best practices into the development and deployment lifecycle (DevSecOps).
- Perform periodic security assessments, penetration testing support, and remediation tracking.
- Manage incident response protocols for OS and application-level security breaches.
Kualifikasi
- Bachelor’s degree in Computer Science, Information Security, or a related technical field.
- Minimum 5+ years of experience in system security engineering or infrastructure security.
- Expertise in Linux/Unix hardening and Windows Server security administration.
- Strong understanding of OWASP principles and application security testing (SAST/DAST).
- Proficiency in scripting languages such as Python, Bash, or PowerShell for security automation.
- Experience with vulnerability management tools (e.g., Nessus, Qualys) and SIEM solutions.
- Relevant certifications such as CISSP, CISM, GSEC, or OSCP are highly preferred.