Senior DevSecOps & Cloud Security Engineer

MIMS Pte Ltd

Petaling Jaya

Hybrid

MYR 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Bonus program
Flexible hours
13th month pay
Salary adjustment

Job summary

MIMS Pte Ltd in Malaysia is seeking a Senior Cybersecurity & Cloud Security Engineer to secure MPF’s apps, Azure cloud environments, development platforms and production services.

The role covers cloud security, identity and access management, vulnerability management, security monitoring and incident response, working with engineering teams to promote secure coding and security-by-design practices.

Qualifications

  • Degree or diploma in Cybersecurity, Computer Science, Information Technology or a related field.
  • At least five years of experience in cybersecurity, cloud security, application security or DevSecOps.
  • At least three years of hands-on experience with Microsoft Azure.
  • Strong knowledge of cloud security, IAM, vulnerability management and application security.
  • Experience with Cloudflare WAF, DNS, CDN, bot-management or equivalent technologies.
  • Experience integrating security scanning into Azure DevOps or GitHub Actions.
  • Familiarity with .NET applications, REST APIs and distributed architectures.
  • Experience with Azure Monitor, Application Insights, Log Analytics and KQL.
  • Knowledge of OWASP, API security and secure-development practices.
  • Experience supporting security incidents and technical root-cause analysis.
  • Strong troubleshooting, documentation and communication skills.

Responsibilities

  • Cloud and Platform Security: Assess and improve the security posture of Microsoft Azure environments.
  • Secure Azure App Service, Front Door, Key Vault, Storage, Redis, Service Bus, Azure SQL and related services.
  • Review cloud networking, public exposure, access permissions and configuration risks.
  • Configure and maintain DNS, subdomains, custom domains, SSL/TLS certificates and certificate renewals.
  • Manage Azure Front Door routes, origins, health probes and related security configurations.
  • Support Azure App Service configuration, deployment slots, scaling, health checks and application settings.
  • Maintain security baselines, architecture diagrams and operational procedures.

Skills

Azure security
IAM
Vulnerability management
Application security
DevSecOps
Cloud security
APIs security
Security monitoring
Incident response
Communication skills

Education

Degree in Cybersecurity/CS/IT

Tools

Azure DevOps
GitHub Enterprise
Cloudflare
SonarCloud
Terraform
Bicep

Job description

Who We Are:

MIMS is Asia-Pacific’s leading multi-channel provider of trusted, quality medical information, medical education, and knowledge services connecting healthcare communities. Our work empowers healthcare professionals to improve patient outcomes by facilitating knowledge exchange and better decision-making. Today, MIMS has a strong regional presence in 17 countries and regions across Asia-Pacific with approximately two million healthcare professionals subscribed to its drug & resource portal, digital and print publications. We provide solutions to leading pharmaceutical companies and established healthcare institutions across the world.

Who We are Looking For:

The Senior Cybersecurity & Cloud Security Engineer is responsible for securing MPF’s applications, Azure cloud environments, development platforms and production services.

This is a hands-on technical role covering cloud and application security, identity and access management, vulnerability management, security monitoring, incident response and selected cloud-platform operations.

Roles & Responsibilities:
Cloud and Platform Security
  • Assess and improve the security posture of Microsoft Azure environments.
  • Secure Azure App Service, Front Door, Key Vault, Storage, Redis, Service Bus, Azure SQL and related services.
  • Review cloud networking, public exposure, access permissions and configuration risks.
  • Configure and maintain DNS, subdomains, custom domains, SSL/TLS certificates and certificate renewals.
  • Manage Azure Front Door routes, origins, health probes and related security configurations.
  • Support Azure App Service configuration, deployment slots, scaling, health checks and application settings.
  • Maintain security baselines, architecture diagrams and operational procedures.
Application and DevSecOps Security
  • Integrate security controls into Azure DevOps, GitHub Actions and CI/CD pipelines.
  • Implement code, dependency, vulnerability, secret and infrastructure scanning.
  • Establish security and release-approval gates.
  • Review application architecture, APIs, authentication, authorisation and data-protection controls.
  • Coordinate penetration testing and track remediation actions.
  • Work with engineering teams to promote secure coding and security-by-design practices.
Web and Edge Security
  • Administer Cloudflare DNS, CDN, WAF, bot-management and rate-limiting controls.
  • Monitor malicious traffic, automated attacks, credential abuse and suspicious activities.
  • Review firewall rules, exclusions, false positives and authentication-route protections.
  • Ensure security rules are tested, approved and supported by rollback procedures.
  • Troubleshoot DNS, SSL/TLS, routing, origin connectivity and certificate issues.
Identity, Access and Vulnerability Management
  • Manage privileged access across Azure, GitHub Enterprise, Azure DevOps, Cloudflare and production platforms.
  • Conduct access reviews and enforce least-privilege principles.
  • Coordinate user onboarding, role changes and timely leaver-access removal.
  • Manage service accounts, certificates, secrets, tokens and credential-rotation procedures.
  • Maintain a register of vulnerabilities and security findings.
  • Prioritise and track remediation, patching and accepted risks to closure.
Security Monitoring and Incident Response
  • Maintain security alerts, dashboards, detection rules and escalation procedures.
  • Use Cloudflare, Azure Monitor, Application Insights, Log Analytics and KQL for investigations.
  • Lead or support security-incident triage, containment, recovery and root-cause analysis.
  • Preserve relevant logs and technical evidence.
  • Coordinate response activities with engineering, infrastructure, Corporate IT and vendors.
  • Participate in critical after-hours incident support when required.
Security Tool and Licence Administration
  • Administer tools such as SonarCloud, GitHub Enterprise, Cloudflare, Azure security services and vulnerability-scanning platforms.
  • Manage administrators, user access, integrations, support contacts and licences.
  • Track subscription costs, usage, renewal dates and cancellation deadlines.
  • Coordinate software renewals and purchase requirements with Finance and Procurement.
  • Maintain primary and backup ownership for critical platforms
What Skills and Experience You will Bring:
  • Degree or diploma in Cybersecurity, Computer Science, Information Technology or a related field.
  • At least five years of experience in cybersecurity, cloud security, application security or DevSecOps.
  • At least three years of hands-on experience with Microsoft Azure.
  • Strong knowledge of cloud security, IAM, vulnerability management and application security.
  • Experience with Cloudflare WAF, DNS, CDN, bot-management or equivalent technologies.
  • Experience integrating security scanning into Azure DevOps or GitHub Actions.
  • Familiarity with .NET applications, REST APIs and distributed architectures.
  • Experience with Azure Monitor, Application Insights, Log Analytics and KQL.
  • Knowledge of OWASP, API security and secure-development practices.
  • Experience supporting security incidents and technical root-cause analysis.
  • Strong troubleshooting, documentation and communication skills.
Preferred
  • Experience with Azure Front Door, Key Vault, App Service, Redis, Service Bus and Azure SQL.
  • Experience administering GitHub Enterprise and SonarCloud.
  • Knowledge of Terraform, Bicep or equivalent infrastructure-as-code tools.
  • AZ-500, SC-200, SC-300, Security+, CISSP or CCSP certification is an advantage.
  • AZ-400 or AZ-104 certification is beneficial.
Why Work with Us:
  • You will be part of huge in-house IT team with multi-cultural environment.
  • You will be directly involved in developing the products with vast opportunity to experience cloud technology.
  • We offer a vast opportunity for continuous improvement involving latest technologies.
  • Excellent career growth opportunity.
Perks You Will Enjoy:
  • On top of 13th month pay, we provide annual performance-based bonus and annual salary adjustment.
  • Incentive structure that rewards quality as much as quantity of work.
  • Flexible time and telecommuting arrangements.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Solution Sales Lead
Security Solution Sales Lead

Noventiq India, Ltd. • Kuala Lumpur

On-site
MYR 120,000 - 240,000
Bonus & allowances
Premium healthcare for employees and a
Training opportunities
Cybersecurity Analyst
Cybersecurity Analyst

Tune Protect Group Berhad • Kuala Lumpur

On-site
MYR 36,000 - 72,000
Medical
Dental
Education support
+2
Senior Cloud Vulnerability Management & DevSecOps I IT Security
Senior Cloud Vulnerability Management & DevSecOps I IT Security

Maybank • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Senior DevSecOps & Cloud Security Engineer (Remote)
Senior DevSecOps & Cloud Security Engineer (Remote)

MIMS Pte Ltd • Petaling Jaya

Hybrid
MYR 120,000 - 180,000
Bonus program
Flexible hours
13th month pay
+1
Application Security Engineer
Application Security Engineer

Respond.io • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Mental health allowance
Flexible working hours
Competitive compensation
+1
Senior DevSecOps Security Engineer
Senior DevSecOps Security Engineer

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Public transport access
Professional development
Insurance coverage
Application Security Engineer II
Application Security Engineer II

Mintel (M) Consulting Sdn Bhd • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000
Hybrid working
Learning & development
Hands-on with Microsoft security tools
Senior Cloud And Infrastructure Engineer (Level 3)
Senior Cloud And Infrastructure Engineer (Level 3)

Doherty • Kuala Lumpur

Hybrid
MYR 180,000 - 260,000
Competitive salary
Performance-related bonus
Hybrid working
+4
IT Manager
IT Manager

Private Advertiser • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Infrastructure, Network & Cloud Engineer Kuala Lumpur, Malaysia Infrastructure, Network & Cloud[...]
Infrastructure, Network & Cloud Engineer Kuala Lumpur, Malaysia Infrastructure, Network & Cloud[...]

Sitecore • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Career path to principal/architecture
Certifications & training
Flexible international team
+1