Senior Engineer, Security & Observability Platform

PowTech Solution (M) Sdn. Bhd

Kuala Lumpur

On-site

MYR 180,000 - 260,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

PowTech Solution (M) Sdn. Bhd is seeking a Senior Engineer to lead end-to-end evaluation, design, and implementation of security and observability solutions for a container-based platform.

You will own the observability and security monitoring stack, collaborating with platform engineering, security operations, and SRE teams. This fixed-term 12-month contract role emphasizes architectural research, PoC work, production deployment, and ongoing operations, with ownership of telemetry pipelines and

Qualifications

  • 5+ years in platform engineering, SRE, or security engineering roles.
  • Experience with telemetry frameworks and instrumentation standards is required.
  • Knowledge of log analytics and alerting ecosystems.
  • Experience with vendor-neutral detection rule formats is a plus.

Responsibilities

  • Evaluate candidate tools against criteria including license compliance, governance, vendor independence, and technical fitness.
  • Perform proof-of-concept exercises to validate architectural decisions and performance.
  • Design unified telemetry pipelines using open standards for SRE and security ops.
  • Architect security detection workflows for portability across backends.
  • Deploy and operate observability and security monitoring stacks on Kubernetes or similar platforms.
  • Define and document operational runbooks and governance procedures.
  • Maintain vendor-independence contingency entries for tools in use.

Skills

Telemetry collection
Columnar databases
Metrics & alerting
Security monitoring
Kubernetes

Education

Bachelor’s degree in Computer Science or related field

Tools

Graph databases
SBOM tooling

Job description

Senior Engineer, Security & Observability Platform

We're hiring a Senior Engineer to own the end-to-end evaluation, design, and implementation of security and observability solutions for a container-based infrastructure platform. If you love architecting systems, evaluating tools for production readiness, and building security-first monitoring at scale, this role is for you.

You’ll be the technical owner of the platform’s observability and security monitoring stack, working across platform engineering, security operations, and SRE teams. This is a high-ownership role spanning architectural research, proof-of-concept work, production deployment, and ongoing operations.

This is a fixed-term contract role, 12 months engagement.

What You'll Do
Evaluation & Research

Conduct structured evaluation of candidate tools against criteria including license compliance, community governance, vendor independence, and technical fitness

Perform proof-of-concept exercises to validate architectural decisions (ingestion throughput, storage efficiency, query latency, operational complexity)

Assess and track governance posture of selected tools; maintain contingency paths for vendor-led dependencies

Engage with upstream open-source communities to stay current on project maturity and roadmap changes

Design unified telemetry pipelines using open standards to serve both SRE observability and security operations

Architect security detection workflows using vendor-neutral detection languages to ensure portability across backends

Design vulnerability aggregation and management workflows spanning container scanning, SCA, static analysis, infrastructure scanning, and SBOM generation

Design supply chain security controls including image signing, provenance attestation, and registry policy enforcement

Design exposure path analysis using graph-based tooling to map relationships across compute orchestration, identity, and vulnerability data

Design automated remediation and orchestration workflows integrated with alerting and incident management

Produce and maintain architecture decision records documenting rationale, trade-offs, and change history

Implementation & Operations

Deploy and operate observability stack: telemetry collection, analytical storage, dashboarding, metrics scraping, alerting, and log routing

Deploy and operate security monitoring stack: detection, vulnerability aggregation, and infrastructure scanning

Deploy and operate CI pipeline security: image scanning, dependency scanning, SBOM generation, static analysis, IaC scanning, and secrets detection

Implement container registry security with integrated scanning and admission policy enforcement

Implement identity, secrets management, and certificate lifecycle infrastructure

Implement collaboration and incident management tooling

Build and maintain detection rules, alerting rules, and automation playbooks

Operate all components on container orchestration platforms with fleet-wide deployment tooling

Process & Governance

Define and document operational runbooks for each capability area

Establish and maintain vendor-independence contingency entries for all vendor-led tools

Conduct periodic license and governance re-assessment of selected tools

Define SLOs for telemetry pipeline availability, ingestion latency, and detection coverage

Participate in security incident response using the tooling you build

What We're Looking For

5+ years in platform engineering, SRE, or security engineering roles

Strong hands-on experience with at least 3 of the following:

Telemetry collection frameworks and instrumentation standards

Columnar or analytical databases for log/trace/event storage

Metrics scraping and alerting ecosystems

SIEM operations and detection engineering (vendor-neutral detection rule formats preferred)

Search-based log analytics platforms

Production experience deploying and operating on Kubernetes or equivalent container orchestration

Experience with container security scanning and software composition analysis tooling

Familiarity with supply chain security concepts: SBOM, image signing, provenance attestation, admission control

Experience with at least one SOAR or automation/orchestration platform

Solid understanding of log collection and routing architectures

Experience writing detection rules or correlation logic for security monitoring

Ability to evaluate open-source projects for governance health, license risk, and production readiness

Bonus

Experience with host-based intrusion detection or endpoint detection and response tooling

Experience with graph databases and asset/infrastructure relationship mapping

Familiarity with vulnerability management and aggregation platforms

Experience with identity providers, directory services, and secrets management

Contributions to open-source security or observability projects

Experience operating in regulated environments with strict vendor-independence requirements

Familiarity with enterprise Linux and container platform ecosystems

Experience with GitOps workflows for infrastructure services

Static/dynamic application security testing tooling experience

Education & Certifications

Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience

Relevant certifications a plus (Kubernetes security, Linux administration, offensive security, cloud security specializations)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Platform Security & Observability Engineer
Senior Platform Security & Observability Engineer

PowTech Solution (M) Sdn. Bhd • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Senior Security Operations Engineer (SecOps)
Senior Security Operations Engineer (SecOps)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Platform Reliability Engineer
Senior Platform Reliability Engineer

HFG Insurance Recruitment • Cyberjaya

On-site
MYR 180,000 - 300,000
Senior Platform Reliability Engineer
Senior Platform Reliability Engineer

HFG (Hong Kong) Limited • Cyberjaya

On-site
MYR 180,000 - 300,000
Dev Ops Engineer
Dev Ops Engineer

PIXELATE EVERYTHING • Subang Jaya

On-site
MYR 120,000 - 240,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA • Sepang

On-site
MYR 80,000 - 120,000
SOC Lead
SOC Lead

XL Axiata • Kuala Lumpur

On-site
MYR 240,000 - 360,000
DevOps Engineer
DevOps Engineer

MTAI Sdn. Bhd. • Kuala Lumpur

On-site
MYR 200,000 - 320,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Application Security Specialist – AppSec / DevSecOps
Senior Application Security Specialist – AppSec / DevSecOps

Randstad Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 210,000