Senior IT Security Engineer

GXBank

Petaling Jaya

On-site

MYR 120,000 - 180,000

Full time

40 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

GXBank is seeking a cybersecurity engineer to lead the implementation and management of endpoint security platforms (EDR/XDR), collaborate with the SOC, and enhance detection rules and playbooks. You will analyze IoCs, manage DLP, and drive endpoint hardening across regions.

The role requires 3–5 years in cybersecurity, hands-on experience with SIEM, threat intelligence, IAM/Iga, PAM, and scripting. You will work with risk, IT and business teams to enforce least-privilege access and regulatory

Qualifications

  • Minimum 3–5 years of experience in cybersecurity engineering or operations.
  • Hands-on experience with EDR/XDR platforms including detection tuning and incident handling.
  • Experience working with SOC team, SIEM tools and threat intelligence feeds.
  • Understanding of IoCs, attack techniques and threat hunting concepts.
  • Familiarity with network security and DDoS mitigation.
  • Experience in vulnerability management and endpoint hardening.
  • Experience in IAM/IGA administration, privileged access or enterprise identity management.
  • Hands-on experience with PAM solutions and endpoint privilege management is a plus.
  • Ability to lead compliance programs, access review initiatives and IAM platform improvements.
  • Basic scripting/automation skills (PowerShell, Python) is a plus.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Lead implementation and management of endpoint security platforms (EDR/XDR) including tuning, threat detection and response improvements.
  • Work closely with SOC team to investigate alerts, respond to incidents and enhance detection rules and playbooks.
  • Analyze and act on Indicators of Compromise (IoCs) using threat intelligence to proactively detect and mitigate threats.
  • Manage and optimize DLP solutions to prevent data exfiltration across endpoints and platforms.
  • Perform continuous endpoint hardening, vulnerability remediation and attack surface reduction.
  • Monitor and respond to DDoS alerts and network-based threats, coordinating with infrastructure teams.
  • Lead IAM platform operations including SailPoint IGA, PAM solutions and endpoint privilege management.
  • Conduct access reviews and regulatory workflows for privileged users.
  • Collaborate with risk, cybersecurity, IT and business teams to enforce RBAC and least-privilege access policies.
  • Ensure security controls align with policies and regulatory requirements (e.g., BNM FinTips).
  • Support incident response activities including containment, eradication and recovery.
  • Evaluate and implement new security tools, automation and improvements to enhance operational efficiency.
  • Maintain technical documentation and operational procedures for security platform s

Skills

EDR/XDR platforms
Incident handling
Threat detection
Threat intelligence
SOC collaboration
Vulnerability management
IAM/IGA administration
PAM / privileged access
RBAC / least privilege
Scripting (PowerShell, Python)

Tools

SIEM tools
SailPoint IGA
PAM solutions
Threat intelligence feeds
DLP

Job description

We are a regional digital bank group, passionately Built With Heart, revolutionizing financial banking services across Southeast Asia. Our mission is to unlock big dreams and drive financial inclusion throughout the region. We believe that real impact starts with people, serving Southeast Asia with empathy, respect, and a commitment to building trust. We have the right foundation—data, technology, and trust—and are looking for individuals who are ready to Own The Mission, taking responsibility for the successful outcomes, impact and legacy we will leave behind. Join us in shaping the future of Digital banking.

Responsibilities
  • Lead implementation and management of endpoint security platforms (EDR/XDR) including tuning, threat detection and response improvements
  • Work closely with SOC team to investigate alerts, respond to incidents and enhance detection rules and playbooks
  • Analyze and act on Indicators of Compromise (IoCs) using threat intelligence to proactively detect and mitigate threats
  • Manage and optimize DLP solutions to prevent data exfiltration across endpoints and platforms
  • Perform continuous endpoint hardening, vulnerability remediation and attack surface reduction
  • Monitor and respond to DDoS alerts and network-based threats, coordinating with infrastructure teams
  • Lead IAM platform operations including SailPoint IGA, PAM solutions and endpoint privilege management
  • Conduct access reviews and regulatory workflows for privileged users
  • Collaborate with risk, cybersecurity, IT and business teams to enforce RBAC and least-privilege access policies
  • Ensure security controls align with policies and regulatory requirements (e.g., BNM FinTips)
  • Support incident response activities including containment, eradication and recovery
  • Evaluate and implement new security tools, automation and improvements to enhance operational efficiency
  • Maintain technical documentation and operational procedures for security platforms
Requirements
  • Minimum 3–5 years of experience in cybersecurity engineering or operations
  • Hands-on experience with EDR/XDR platforms including detection tuning and incident handling
  • Experience working with SOC team, SIEM tools and threat intelligence feeds
  • Understanding of IoCs, attack techniques and threat hunting concepts
  • Familiarity with network security and DDoS mitigation
  • Experience in vulnerability management and endpoint hardening
  • Experience in IAM/IGA administration, privileged access or enterprise identity management
  • Hands-on experience with PAM solutions and endpoint privilege management is a plus
  • Ability to lead compliance programs, access review initiatives and IAM platform improvements
  • Basic scripting/automation skills (PowerShell, Python) is a plus
  • Strong analytical and problem-solving skills
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Endpoint Protection (Operation)
Manager Endpoint Protection (Operation)

Telekom Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Head of Security Operations & Cyber Defense
Head of Security Operations & Cyber Defense

Krisvconsulting Services Pte Ltd • Kuala Lumpur

On-site
MYR 350,000 - 550,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Axonect • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Engineer - Offensive Security (Red Team)
Security Engineer - Offensive Security (Red Team)

Axonect • Kuala Lumpur

On-site
MYR 100,000 - 180,000
Lead Endpoint Security & IAM Defense Engineer
Lead Endpoint Security & IAM Defense Engineer

GXBank • Petaling Jaya

On-site
MYR 120,000 - 180,000
Information Security Operations Lead (Penang / Johor)
Information Security Operations Lead (Penang / Johor)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Group Head Information Security, SVP
Group Head Information Security, SVP

RHB Banking Group • Kuala Lumpur

On-site
MYR 320,000 - 520,000
EDR - Cloud Security Support Specialist
EDR - Cloud Security Support Specialist

Pride Global • Cyberjaya

On-site
MYR 90,000 - 150,000
Managed Security Engineer
Managed Security Engineer

Accenture Southeast Asia • Petaling Jaya

On-site
MYR 90,000 - 130,000