Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
About the company
Company is a forefront of technological advancement, integrating cutting-edge solutions into everyday life. Our culture thrives on innovation, collaboration, and a commitment to excellence. We foster an inclusive environment where every team member's contribution is valued and where everyone has the opportunity to grow.
About the job
- Conduct proactive offensive security testing and attack validation across public-facing Web, API, mobile, cloud and infrastructure environments. Identify realistic and exploitable attack paths and drive remediation to closure.
- Perform penetration testing, vulnerability validation and red/blue security exercises, going beyond automated vulnerability scanning to understand how weaknesses can be exploited in real-world scenarios.
- Run security monitoring, alert triage, investigation and severity classification (P0–P3) using our SIEM environment (Alibaba Cloud Threat Analysis / Agentic SOC + SLS).
- Develop and tune detection rules to improve coverage of key threats such as account takeover, automated attacks, credential or secret leakage, privilege misuse, ransomware and business-logic abuse, while continuously reducing false positives.
- Translate identified attack techniques and vulnerabilities into practical detection, prevention and response controls.
- Develop SOAR and security automation playbooks, preferably using Go, to automate repetitive response activities such as auto-blocking, isolation, credential handling and security enrichment.
- Aggregate security logs across multiple platforms (Alibaba Cloud primary + AWS + Tencent Cloud + Cloudflare) into the SIEM for unified monitoring and analysis.
- Operate and optimize native cloud and platform security capabilities such as Cloud Security Center, GuardDuty, WAF and other security controls
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related field, or equivalent practical experience.
- 3+ years of hands-on cybersecurity experience, including Security Operations, Incident Response, Product/Application Security or Offensive Security.
- Hands-on Offensive Security experience is required, including practical experience in penetration testing, attack simulation or vulnerability exploitation.
- Able to independently perform security testing against Web applications and APIs, identify realistic attack paths and validate vulnerabilities beyond automated scanner results.
- Ability to develop PoCs, scripts or exploit scenarios to demonstrate and validate security weaknesses.
- Familiarity with the security stack of at least one major public cloud platform such as Alibaba Cloud, AWS or Tencent Cloud.
Job DetailsAbout the company
Company is a forefront of technological advancement, integrating cutting-edge solutions into everyday life. Our culture thrives on innovation, collaboration, and a commitment to excellence. We foster an inclusive environment where every team member's contribution is valued and where everyone has the opportunity to grow.
About the job
- Conduct proactive offensive security testing and attack validation across public-facing Web, API, mobile, cloud and infrastructure environments. Identify realistic and exploitable attack paths and drive remediation to closure.
- Perform penetration testing, vulnerability validation and red/blue security exercises, going beyond automated vulnerability scanning to understand how weaknesses can be exploited in real-world scenarios.
- Run security monitoring, alert triage, investigation and severity classification (P0–P3) using our SIEM environment (Alibaba Cloud Threat Analysis / Agentic SOC + SLS).
- Develop and tune detection rules to improve coverage of key threats such as account takeover, automated attacks, credential or secret leakage, privilege misuse, ransomware and business-logic abuse, while continuously reducing false positives.
- Translate identified attack techniques and vulnerabilities into practical detection, prevention and response controls.
- Lead end-to-end Incident Response, including detection → investigation → containment → eradication → recovery → post-mortem, with clear written incident reports.
- Develop SOAR and security automation playbooks, preferably using Go, to automate repetitive response activities such as auto-blocking, isolation, credential handling and security enrichment.
- Aggregate security logs across multiple platforms (Alibaba Cloud primary + AWS + Tencent Cloud + Cloudflare) into the SIEM for unified monitoring and analysis.
- Operate and optimize native cloud and platform security capabilities such as Cloud Security Center, GuardDuty, WAF and other security controls
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related field, or equivalent practical experience.
- 3+ years of hands-on cybersecurity experience, including Security Operations, Incident Response, Product/Application Security or Offensive Security.
- Hands-on Offensive Security experience is required, including practical experience in penetration testing, attack simulation or vulnerability exploitation.
- Able to independently perform security testing against Web applications and APIs, identify realistic attack paths and validate vulnerabilities beyond automated scanner results.
- Ability to develop PoCs, scripts or exploit scenarios to demonstrate and validate security weaknesses.
- Familiarity with the security stack of at least one major public cloud platform such as Alibaba Cloud, AWS or Tencent Cloud.
Skillsno additional skills required
Qualificationno additional qualifications required
EducationBachelor Degree