Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
SNSoft SDN BHD seeks a Senior Security Operations Engineer to own threat detection, incident response, and automation across multi‑cloud environments. You will drive offensive security testing, validate vulnerabilities beyond automated scans, and implement detection rules to improve security coverage.
You will also develop SOAR playbooks and contribute to on‑call incident response, collaborating with Engineering and Product teams to strengthen security early in development.
At SNSoft, we're at the forefront of technological advancement, integrating cutting-edge solutions into everyday life. Our culture thrives on innovation, collaboration, and a commitment to excellence. We foster an inclusive environment where every team member's contribution is valued and where everyone has the opportunity to grow.
Competitive salary range depending on experience.
Project Incentive (upon Company Declaration based on project performance)
Sports Activities (Badminton & Basketball), Company Outing
Training and certification sponsored by company (Selected employees).
Optical, Dental, Body Check Up Claim (upon Confirmation)
Own security monitoring, threat detection, and incident response across our multi-cloud environment, and drive automation of detection and response.
Conduct proactive offensive security testing and attack validation across public-facing Web, API, mobile, cloud and infrastructure environments. Identify realistic and exploitable attack paths and drive remediation to closure.
Perform penetration testing, vulnerability validation and red/blue security exercises, going beyond automated vulnerability scanning to understand how weaknesses can be exploited in real-world scenarios.
Run security monitoring, alert triage, investigation and severity classification (P0–P3) using our SIEM environment (Alibaba Cloud Threat Analysis / Agentic SOC + SLS).
Develop and tune detection rules to improve coverage of key threats such as account takeover, automated attacks, credential or secret leakage, privilege misuse, ransomware and business-logic abuse, while continuously reducing false positives.
Translate identified attack techniques and vulnerabilities into practical detection, prevention and response controls.
Develop SOAR and security automation playbooks, preferably using Go, to automate repetitive response activities such as auto-blocking, isolation, credential handling and security enrichment.
Aggregate security logs across multiple platforms (Alibaba Cloud primary + AWS + Tencent Cloud + Cloudflare) into the SIEM for unified monitoring and analysis.
Operate and optimize native cloud and platform security capabilities such as Cloud Security Center, GuardDuty, WAF and other security controls.
Conduct security reviews of new systems, features and APIs before production release, working closely with Engineering and Product teams to identify potential attack vectors and security risks early.
Participate in the on-call rotation to ensure timely investigation and response to critical security alerts and incidents.
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related field, or equivalent practical experience.
3+ years of hands-on cybersecurity experience, including Security Operations, Incident Response, Product/Application Security or Offensive Security.
Hands-on Offensive Security experience is required, including practical experience in penetration testing, attack simulation or vulnerability exploitation.
Able to independently perform security testing against Web applications and APIs, identify realistic attack paths and validate vulnerabilities beyond automated scanner results.
Ability to develop PoCs, scripts or exploit scenarios to demonstrate and validate security weaknesses.
Strong understanding of common Web and API attack techniques, authentication and authorization weaknesses, business-logic vulnerabilities and attacker methodologies.
Hands-on experience with SIEM and log analytics platforms such as SLS, Splunk, ELK or equivalent, including developing and tuning detection rules.
Practical experience in security investigation and incident response, with the ability to independently investigate and respond to security incidents.
Strong security fundamentals across network, operating systems, Web applications, APIs and cloud environments.
Development or scripting capability for security automation; Go is preferred, while Python or other scripting languages are also welcome.
Familiarity with the security stack of at least one major public cloud platform such as Alibaba Cloud, AWS or Tencent Cloud.
Able to think from an attacker's perspective, understand how vulnerabilities can be chained into realistic attack paths, and translate those findings into effective defensive controls.
Detail-oriented, accountable and comfortable participating in an on-call rotation.
Red Team / Purple Team experience in a production or professional security environment.
Bug bounty, VDP, CTF, CVE or other demonstrable offensive security achievements.
Threat Hunting and MITRE ATT&CK mapping experience.
Experience building or operating SOAR workflows and security automation.
Security experience supporting high-traffic, public-facing consumer platforms, payments, e-commerce, social platforms or other transaction-intensive environments.
Experience investigating account abuse, automated attacks, bot activity, transaction abuse or business-logic attacks.
Experience with risk engines, device fingerprinting, behavioural analysis or bot detection.
Hands-on experience with DDoS and application-layer attack mitigation.
Multi-cloud security operations experience across Alibaba Cloud, AWS, Tencent Cloud and Cloudflare.
Experience working closely with Engineering and Product teams on security assessment, remediation and secure-by-design initiatives.
About SNSoft SDN BHD
SNSoft SDN BHD, founded in 2016, is a leading software and game development studio specializing in social media and mobile games. Our diverse team of experts from Malaysia and across Asia delivers cutting-edge solutions in software, web, and database development.
We seek creative, growth-driven talent to shape the future of gaming and technology. With strong innovation, operational expertise, and global expansion plans, SNSoft is building a dynamic interactive entertainment platform. Join us and be part of something extraordinary!
About SNSoft SDN BHD
SNSoft SDN BHD, founded in 2016, is a leading software and game development studio specializing in social media and mobile games. Our diverse team of experts from Malaysia and across Asia delivers cutting-edge solutions in software, web, and database development.
We seek creative, growth-driven talent to shape the future of gaming and technology. With strong innovation, operational expertise, and global expansion plans, SNSoft is building a dynamic interactive entertainment platform. Join us and be part of something extraordinary!