Job Search and Career Advice Platform

Enable job alerts via email!

Cloud Security & Compliance Officer

Silverlake Axis

Selangor

On-site

MYR 80,000 - 120,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading tech company in Malaysia is seeking a professional to manage and execute cloud security and compliance for AWS and Huawei environments. This role involves implementing security policies, conducting audits, and overseeing compliance with PCI DSS standards. The ideal candidate will have 3-5 years of experience, deep knowledge of security tools, and relevant certifications. Join a team dedicated to ensuring the security and integrity of cloud operations in a growing company.

Qualifications

  • 3-5 years of experience in cloud security, compliance, audit, or risk management.
  • Hands-on experience with cloud security tools.
  • Expert-level knowledge of IAM and KMS.

Responsibilities

  • Own and execute the cloud security and compliance posture.
  • Implement and manage cloud security policies and standards.
  • Serve as the primary subject matter expert for PCI DSS audits.

Skills

Cloud security expertise
PCI DSS v4.0 knowledge
IAM management
Risk management
Compliance auditing

Education

Professional certifications (CISSP, CCSP, etc.)

Tools

AWS Security Hub
Huawei Cloud SIS
SIEM tools
Job description

To own and execute the cloud security and compliance posture across Huawei and AWS production environments, ensuring continuous protection and regulatory compliance of the Cardholder Data Environment (CDE). This role acts as the technical implementer of security controls while also bridging the security and operations teams to ensure cloud operations, processes, and configurations consistently adhere to internal policies and external regulatory requirements, particularly PCI DSS, with a strong focus on governance, risk management, and audit evidence.

Security Governance & Policy & Compliance

Implement and manage cloud security policies, standards, and baselines. Enforce security controls using native tools (AWS Security Hub, Huawei Cloud SIS) and third‑party solutions.

Translate PCI DSS control requirements into actionable operational tasks for the cloud engineering teams. Deliver compliance training and awareness to the operations staff.

Threat & Vulnerability Management

Conduct regular vulnerability scans and coordinate remediation. Monitor and investigate security events from WAF, SIEM, and cloud‑native tools. Manage WAF rules and Security Group/NSG policies.

Maintain the risk register for the cloud environment. Work with the team to assess and remediate compliance‑related risks.

Identity & Access Management (IAM)

Govern the IAM framework, ensuring least privilege. Conduct periodic access reviews and certification for both AWS IAM and Huawei Cloud IAM.

Compliance & Auditing

Serve as the primary cloud security subject matter expert for PCI DSS audits. Ensure configuration compliance (e.g., using AWS Config and Huawei Cloud RMS). Manage the encryption key lifecycle using AWS KMS and Huawei Cloud KMS.

Manage and operate compliance monitoring tools (e.g., AWS Config, Huawei Cloud RMS, Scuba) to detect drift from PCI DSS baselines. Generate weekly compliance reports and dashboards for management.

Audit operational processes (change management, incident response, access reviews) to ensure they meet compliance requirements. Collect and curate evidence for internal and external audits. Validate that L1/L2 support runbooks and SOPs are compliant.

What You’ll Bring
  • 3-5 years of experience in cloud security, compliance, audit, or risk management role with expertise in AWS and at least one other major cloud provider (Huawei Cloud strongly preferred).
  • Deep knowledge of PCI DSS v4.0 requirements and their implementation in cloud environments.
  • Hands‑on experience with cloud security tools (CSPM, CWPP, SIEM, EASM).
  • Expert‑level knowledge of IAM, KMS, and network security in the cloud.
  • One or more professional certifications: CISSP, CCSP, AWS Certified Security – Specialty, or equivalent.
  • Certification such as PCI Professional (PCIP), CISA, or CRISC is highly desirable.
  • Experience with HSM (Hardware Security Module) lifecycle management and integration.
  • Knowledge of VISA VCX security requirements.
  • Familiarity with security frameworks like NIST, ISO 27001.

Be careful - Don’t provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.