Lead Engineer – Cloud & Endpoint

Dyson Institute

Kuala Lumpur

On-site

MYR 180,000 - 360,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Dyson Institute is seeking a Cloud & Endpoint Security Engineer to lead cross-domain security engineering across cloud and endpoint ecosystems. You will manage Defender Vulnerability Management, Defender for Cloud Apps, and automated posture controls to provide visibility and remediation across workplace platforms.

You will bridge cloud security services with endpoint telemetry, deliver security projects, and partner with IT operations to enforce governance and policy changes across hybrid

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, IT, or equivalent experience
  • 5–7 years' cybersecurity experience with focus on cloud-delivered endpoint protection, CASB, and exposure management platforms
  • Hands-on experience deploying and running unified Microsoft Defender security stacks across cloud and hybrid estates
  • Certifications such as MS SC-400/SC-200, CISSP, CCSP are desirable

Responsibilities

  • Own the architecture and operational health of Defender for Endpoint cloud capabilities
  • Lead Defender Vulnerability Management and exposure reduction initiatives
  • Architect Defender for Cloud Apps integrations to secure SaaS usage
  • Build posture monitoring, compliance reporting, and automated remediation
  • Deliver telemetry integration to central monitoring (e.g., Sentinel) and lead security projects

Skills

Cloud security
Endpoint protection
Threat analysis
Leadership

Education

Bachelor's degree in CS or Cybersecurity

Tools

Microsoft Defender for Endpoint
Defender for Cloud Apps
Defender Vulnerability Management
Microsoft Sentinel
API integrations

Job description

Role Purpose

As the Cloud & Endpoint Security Engineer, you are accountable for engineering integrated cloud-connected and endpoint security capabilities to maintain a high security posture across all workspace platforms. Operating as a cross-domain engineering lead, you will bridge the gap between cloud security services and endpoint telemetry. By managing Defender Vulnerability Management, maintaining Defender for Cloud Apps integrations, and implementing automated security posture controls, you will provide visibility and technical remediation across the workplace ecosystem. In this role, you will lead and manage the following domains:

  • Defender for Endpoint & Cloud Integration: Owning the architecture and operational health of MDE cloud capabilities.
  • Vulnerability & Exposure Management: Implementing and optimizing Defender Vulnerability Management to continuously identify exposure.
  • Cloud App Security (CASB): Engineering and governing Defender for Cloud Apps to secure SaaS usage and shadow IT.
  • Security Posture Management: Building posture monitoring tools, compliance reporting frameworks, and automated posture remediation.
  • Telemetry & Engineering Projects: Leading workplace security engineering projects and providing telemetry integration into central monitoring solutions.
Key Skills & Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related technical discipline (or equivalent practical experience).
  • A minimum of 5–7 years' cybersecurity experience with focus on cloud-delivered endpoint protection, CASB, and exposure management platforms.
  • Proven hands-on experience deploying and running unified Microsoft Defender security stacks across cloud and hybrid client estates.
  • Relevant industry certifications such as Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400), SC-200, CISSP, or CCSP are highly desirable.
Security Expertise & Architecture

Deep technical expertise in cloud-delivered security solutions, exposure management, CASB architecture, API integrations, and threat vector analysis across hybrid workspaces.

Tooling & Technical Proficiency

Expertise with Microsoft Defender for Endpoint (MDE), Defender Vulnerability Management, Defender for Cloud Apps (MDA), Microsoft Sentinel integration, and Security Posture Management tools.

Risk Management & Prioritisation

Ability to leverage vulnerability scoring models (CVSS, EPSS) and asset business context to prioritize exposure remediation across cloud and endpoint boundaries.

Governance, Process & Control Design

Experience designing cloud access policies, sanctioning SaaS applications, and establishing vulnerability management exception tracking mechanisms.

Service Delivery & Operational Management

Track record of managing enterprise-scale security tooling platforms, maintaining seamless API connections, and delivering against operational SLAs.

Data Analysis, Reporting & Insight

Strong data-analysis skills using KQL and API data feeds to create executive dashboards demonstrating security posture improvements and risk trends.

Stakeholder Management & Influence

Effective communicator capable of collaborating with cloud operations, networking, and IT operations teams to implement security posture changes.

Threat Intelligence Integration

Ability to utilize threat intelligence indicators to identify malicious SaaS application usage, unusual tenant activities, and high-risk endpoint vulnerabilities.

Leadership & Execution

Proven execution capability to lead complex engineering projects, translate security outcomes into practical steps, and guide operational teams.

Continuous Improvement & Automation

A drive to automate security checks, vulnerability ticketing workflows (e.g., via ITSM integrations), and cloud app policy adjustments.

Key Accountabilities & Success Measures
Vulnerability & Posture Management Engineering Accountability
  • Deploy, operate, and optimize Defender Vulnerability Management to identify, prioritize, and drive technical exposure reduction.
Success Measures
  • Maintain >95% accurate scan and telemetry coverage across all active cloud-managed devices;
  • Measurable structural reduction in organizational Exposure Score within Defender Vulnerability Management.
Cloud App Security & Shadow IT Governance Accountability
  • Architect and manage Defender for Cloud Apps integrations to enforce SaaS governance, detect anomalous cloud behavior, and control unsanctioned applications.
Success Measures
  • 100% of cloud app traffic monitored and evaluated against security risk policies;
  • Automated block controls enforced for high-risk, unsanctioned cloud platforms.
Security Telemetry & Platform Automation Accountability
  • Drive end-to-end security telemetry pipelines between MDE, Cloud Apps, and centralized monitoring tools (e.g., Sentinel/ServiceNow).
Success Measures
  • 100% platform uptime and event ingestion reliability across security tool integrations;
  • Significant reduction in manual tracking through automated posture and vulnerability ticketing workflows.

Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.

At Dyson we are focused on solving the problems that others have ignored; solving them first using our technology and ingenuity. In order to achieve this we need to pioneer technologies that are different and authentic. This is the core of what we do and who we are. We must strive to create the future, every single day by developing new things, different things, things that go against the grain with a diverse and global team of ingenious minds. Dyson employs 14,000 people and is present in more than 80 countries. And while we are growing fast we want Dyson to remain a start-up in spirit with the freedom of experimentation and learning, constantly reinventing our products as well as reinventing how we work, how we sell and how we support our owners. At the same time we are working through the James Dyson Foundation, James Dyson Award and Dyson Institute to inspire future engineers and pioneering a new approach to engineering education. Underlining everything we do in this diverse environment is the need to always show respect, supporting each other as one team to overcome whatever challenges we encounter. We drive empowerment, development and equality in an inclusive environment for our people around the world. The future doesn’t just happen, we look to make it happen, to achieve leaps through pioneering new ideas.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Engineer – Endpoint Security
Lead Engineer – Endpoint Security

Dyson Institute • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Health insurance
Employee banking benefits
Lead Engineer – Identity & Access Security
Lead Engineer – Identity & Access Security

Dyson Institute • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Lead Engineer – Multi-Platform Endpoint
Lead Engineer – Multi-Platform Endpoint

Dyson Institute • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Lead Engineer – M365 & Exchange Platform
Lead Engineer – M365 & Exchange Platform

Dyson Institute • Kuala Lumpur

On-site
MYR 240,000 - 380,000
IT Service Operations Management Process Owner
IT Service Operations Management Process Owner

Dyson Institute • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Service Engineering Change Specialist
Service Engineering Change Specialist

Dyson Institute • Johor Bahru

Hybrid
MYR 120,000 - 180,000
Transport allowance
Medical care & insurance
Professional growth
+5
Senior Business Analyst, Treasury
Senior Business Analyst, Treasury

Dyson Institute • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Project Engineer
Project Engineer

Dyson Institute • Johor Bahru

On-site
MYR 60,000 - 120,000
Senior Test Engineer
Senior Test Engineer

Dyson Institute • Johor Bahru

On-site
MYR 180,000 - 300,000
Operational Engineering, Senior Technician
Operational Engineering, Senior Technician

Dyson Institute • Johor Bahru

Hybrid
MYR 60,000 - 120,000