Department:
Technology & IT Operations Dept, Solution Service Delivery Div, MIMOS Solutions Sdn. Bhd.
Job Purpose
Job Description
IT Security Engineer
Department:
Technology & IT Operations Dept, Solution Service Delivery Div, MIMOS Solutions Sdn. Bhd.
Job Purpose
The IT Security Engineer is responsible for supporting the organisation’s cybersecurity efforts by reducing the technical attack surface through secure asset hardening, continuous monitoring, and vulnerability management. The Engineer also help to ensure business continuity, regulatory compliance, and the protection of organisational assets against internal and external cyber threats.
Key Responsibilities:
- Security Architecture & Engineering (Building Defenses)
- Designing Secure Networks and Implementing Controls: Work with the Firewall team to secure routing architectures.
- Automation & Scripting: Work with the server team and developer team to automate mundane security checks, log alerts, and system configuration deployments.
- Vulnerability Management (Proactive Auditing)
- Vulnerability Scanning: Running automated tools like Nessus to spot missing patches or software flaws.
- Penetration Testing: Conducting controlled, simulated cyberattacks to discover hidden entry points before bad actors find them.
- Remediation & Patching: Working alongside system administrators to push security updates and system hardening configurations.
- Threat Hunting & Incident Response (Active Defense)
- Log Analysis: Checking server logs, user activities, and network packets to catch anomalies.
- Incident Triage: Investigating suspicious activity alerts, containing infected machines, and neutralizing active malware.
- Forensic Clean-up: Performing root-cause analysis after a breach, patching the vulnerability, and safely restoring systems.
- Identity & Access Management (IAM)
- Access Control and MFA Management: Monitoring access control and Multi-Factor Authentication systems by providing the report.
- Compliance & Threat Intelligence
- Framework Alignment: Ensuring configurations match global baselines like NIST, CIS, or the ISO 27001 guidelines mentioned in your document.
- Threat Intel Tracking: Keeping track of newly released Zero-Days and emerging cyber threat trends to secure systems against new attack vectors.
Qualification
- Bachelor’s degree in Computer Science/Information Technology/Engineering or equivalent.
Professional Qualification
- AWS Certified Security – Specialty or Azure Security Engineer (AZ-500).
- Cybersecurity certifications such as Comptia security+, CISSP, OSCP (Offensive Security) or BTL1 (Blue Team Level 1), etc is desirable.
Work Experience
- At least 1-5 years of working experience in IT enterprise infrastructure team.
- At least 1-2 years of working experience in security operations – networking and firewall.
- Experience in generating designs, documenting, installing, testing, implementing, monitoring, and maintaining complex systems and applications.
- Participated in project requirement design, implementation, deployment, and support.
- Performing any security framework auditing.
Technical Skills
- Cybersecurity Foundations: Strong foundational understanding of core security principles, common cyber-attack vectors (e.g., phishing, malware, OWASP Top 10), and basic defense mechanisms.
- Fundamental Networking Concepts: Solid knowledge of the OSI model, TCP/IP networking, subnetting, common ports, and basic packet analysis using Wireshark.
- Security Appliance Awareness: Basic familiarity with configuring or assisting in the maintenance of firewalls, Virtual Private Networks (VPNs), and basic endpoint protection agents.
- Multi-OS Familiarity: Ability to navigate and perform basic system administration tasks via command line in both Windows (Active Directory basics) and Linux environments.
- Vulnerability Scanning Basics: Familiarity with executing automated scanning tools (such as Nessus, OpenVAS, or Qualys) and extracting standard vulnerability reports for review.
- Basic Scripting (Highly Desirable): Exposure to reading and writing simple scripts (Python, Bash, or PowerShell) to automate repetitive administrative or scanning tasks.
Soft Skills
- Active Learning Mindset: A strong drive to continuously upskill, learn new enterprise security tools, and absorb mentorship from senior engineering staff.
- Clear Technical Reporting: Ability to accurately document security incidents, write clear ticket summaries, and communicate findings to the immediate team.
- Strong Teamwork & Support: Ability to collaborate effectively within a team environment and reliably support senior engineers on larger infrastructure projects.
- Attention to Detail: Keen observational skills to spot anomalies in system alerts, log files, or user access requests without overlooking discrepancies.
- Receptive to Feedback: Openness to constructive feedback, with a structured approach to troubleshooting and adapting to standard operational workflows.