Senior Security Operations lead

Randstad

Kuala Lumpur

On-site

MYR 140,000 - 210,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Randstad Malaysia is hiring a security engineering professional to conduct proactive offensive security testing across web, API, mobile, cloud and infrastructure. You will identify exploitable paths and drive remediation to closure, beyond automated scans.

Responsibilities include incident response leadership, SIEM monitoring, and developing detection and automation playbooks (Go). You will work with Alibaba Cloud, AWS, Tencent Cloud and Cloudflare to strengthen security controls in our

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, IT or related field.
  • 3+ years of hands-on cybersecurity experience including Security Operations or Offensive Security.
  • Hands-on Offensive Security experience with pen testing or vulnerability exploitation.
  • Ability to perform security testing against Web applications and APIs beyond automated scanners.
  • Experience with at least one major cloud platform (Alibaba Cloud, AWS or Tencent Cloud).

Responsibilities

  • Conduct proactive offensive security testing across Web, API, mobile, cloud and infra environments.
  • Perform penetration testing, vulnerability validation and red/blue exercises beyond scanners.
  • Run security monitoring and triage using our SIEM (Alibaba Cloud Threat Analysis / Agentic SOC + SLS).
  • Develop and tune detection rules to improve coverage and reduce false positives.
  • Translate attack techniques into practical detection, prevention and response controls.
  • Lead end-to-end Incident Response with clear written reports.
  • Develop SOAR playbooks, preferably using Go, to automate response activities.
  • Aggregate logs across Alibaba Cloud, AWS, Tencent Cloud, Cloudflare into the SIEM.
  • Operate cloud security capabilities such as Cloud Security Center, GuardDuty, WAF.

Skills

Offensive Security
Security Operations
Incident Response
Penetration Testing

Education

Bachelor's degree in Computer Science / Cybersecurity / IT

Tools

SIEM
Go
Cloud platforms: Alibaba Cloud / AWS / Tencent Cloud

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

About the company
Company is a forefront of technological advancement, integrating cutting-edge solutions into everyday life. Our culture thrives on innovation, collaboration, and a commitment to excellence. We foster an inclusive environment where every team member's contribution is valued and where everyone has the opportunity to grow.

About the job

  • Conduct proactive offensive security testing and attack validation across public-facing Web, API, mobile, cloud and infrastructure environments. Identify realistic and exploitable attack paths and drive remediation to closure.
  • Perform penetration testing, vulnerability validation and red/blue security exercises, going beyond automated vulnerability scanning to understand how weaknesses can be exploited in real-world scenarios.
  • Run security monitoring, alert triage, investigation and severity classification (P0–P3) using our SIEM environment (Alibaba Cloud Threat Analysis / Agentic SOC + SLS).
  • Develop and tune detection rules to improve coverage of key threats such as account takeover, automated attacks, credential or secret leakage, privilege misuse, ransomware and business-logic abuse, while continuously reducing false positives.
  • Translate identified attack techniques and vulnerabilities into practical detection, prevention and response controls.
  • Develop SOAR and security automation playbooks, preferably using Go, to automate repetitive response activities such as auto-blocking, isolation, credential handling and security enrichment.
  • Aggregate security logs across multiple platforms (Alibaba Cloud primary + AWS + Tencent Cloud + Cloudflare) into the SIEM for unified monitoring and analysis.
  • Operate and optimize native cloud and platform security capabilities such as Cloud Security Center, GuardDuty, WAF and other security controls


Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related field, or equivalent practical experience.
  • 3+ years of hands-on cybersecurity experience, including Security Operations, Incident Response, Product/Application Security or Offensive Security.
  • Hands-on Offensive Security experience is required, including practical experience in penetration testing, attack simulation or vulnerability exploitation.
  • Able to independently perform security testing against Web applications and APIs, identify realistic attack paths and validate vulnerabilities beyond automated scanner results.
  • Ability to develop PoCs, scripts or exploit scenarios to demonstrate and validate security weaknesses.
  • Familiarity with the security stack of at least one major public cloud platform such as Alibaba Cloud, AWS or Tencent Cloud.
Job Details

About the company
Company is a forefront of technological advancement, integrating cutting-edge solutions into everyday life. Our culture thrives on innovation, collaboration, and a commitment to excellence. We foster an inclusive environment where every team member's contribution is valued and where everyone has the opportunity to grow.

About the job

  • Conduct proactive offensive security testing and attack validation across public-facing Web, API, mobile, cloud and infrastructure environments. Identify realistic and exploitable attack paths and drive remediation to closure.
  • Perform penetration testing, vulnerability validation and red/blue security exercises, going beyond automated vulnerability scanning to understand how weaknesses can be exploited in real-world scenarios.
  • Run security monitoring, alert triage, investigation and severity classification (P0–P3) using our SIEM environment (Alibaba Cloud Threat Analysis / Agentic SOC + SLS).
  • Develop and tune detection rules to improve coverage of key threats such as account takeover, automated attacks, credential or secret leakage, privilege misuse, ransomware and business-logic abuse, while continuously reducing false positives.
  • Translate identified attack techniques and vulnerabilities into practical detection, prevention and response controls.
  • Lead end-to-end Incident Response, including detection → investigation → containment → eradication → recovery → post-mortem, with clear written incident reports.
  • Develop SOAR and security automation playbooks, preferably using Go, to automate repetitive response activities such as auto-blocking, isolation, credential handling and security enrichment.
  • Aggregate security logs across multiple platforms (Alibaba Cloud primary + AWS + Tencent Cloud + Cloudflare) into the SIEM for unified monitoring and analysis.
  • Operate and optimize native cloud and platform security capabilities such as Cloud Security Center, GuardDuty, WAF and other security controls


Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related field, or equivalent practical experience.
  • 3+ years of hands-on cybersecurity experience, including Security Operations, Incident Response, Product/Application Security or Offensive Security.
  • Hands-on Offensive Security experience is required, including practical experience in penetration testing, attack simulation or vulnerability exploitation.
  • Able to independently perform security testing against Web applications and APIs, identify realistic attack paths and validate vulnerabilities beyond automated scanner results.
  • Ability to develop PoCs, scripts or exploit scenarios to demonstrate and validate security weaknesses.
  • Familiarity with the security stack of at least one major public cloud platform such as Alibaba Cloud, AWS or Tencent Cloud.
Skills
no additional skills requiredQualification
no additional qualifications requiredEducation
Bachelor Degree
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior CyberSecurity Analyst
Senior CyberSecurity Analyst

SF International • Selangor

On-site
MYR 60,000 - 120,000
Penetration Tester (Security)
Penetration Tester (Security)

VeecoTech • Bayan Lepas

On-site
MYR 60,000 - 100,000
Travel for on-site assessments
On-site security assessments
Regional Assistant Manager, Security Operations
Regional Assistant Manager, Security Operations

ZUS Coffee • Kuala Lumpur

On-site
MYR 60,000 - 110,000
Information Security Analyst
Information Security Analyst

Media.Monks • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Cloud - Cyber Security Engineer
Cloud - Cyber Security Engineer

Niaga Prestasi • Kuala Lumpur

On-site
MYR 90,000 - 130,000
Information Security Operations Lead (Penang / Johor)
Information Security Operations Lead (Penang / Johor)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Security Analyst (Intelligence - Operations)
Security Analyst (Intelligence - Operations)

GXS Bank • Selangor

On-site
MYR 90,000 - 130,000
Senior Security Operations & Incident Response Lead
Senior Security Operations & Incident Response Lead

Randstad • Kuala Lumpur

On-site
MYR 140,000 - 210,000
Principal Security Consultant (Penetration Tester)
Principal Security Consultant (Penetration Tester)

Sysarmy • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Puresoftware • Kuala Lumpur

On-site
MYR 90,000 - 180,000