Staff IT Security Engineer

Michael Page

Penang

On-site

MYR 194,000 - 238,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive benefits
Permanent position

Job summary

Michael Page in Penang seeks a Staff IT Security Engineer to lead architecture and security initiatives across IT and OT. You will analyze threat intelligence, drive vulnerability programs and manage penetration testing.

You will support security monitoring, incident response, and vendor risk assessments while collaborating with GRC and cross-functional teams to strengthen the enterprise security posture.

Qualifications

  • Needs 8+ years in cybersecurity, security engineering, security operations or security architecture.
  • Experience with SIEM, EDR/XDR, threat detection and monitoring.
  • Hands-on in IT and OT security environments.
  • Familiar with ISO 27001, ISMS, risk governance, and security policy development.
  • Strong communication and teamwork skills.

Responsibilities

  • Lead cybersecurity architecture and security improvement initiatives across IT and OT.
  • Analyze threat intelligence and attack techniques to identify organizational risks.
  • Drive vulnerability and threat management programs with remediation prioritization.
  • Manage penetration testing and remediation of findings.
  • Oversee security monitoring, incident response, and threat hunting.
  • Collaborate with GRC teams on risk governance and security assessments.
  • Conduct vendor security risk assessments.
  • Support security operations across IT and OT environments.

Skills

Cybersecurity strategy
Threat intelligence
Incident response
Vulnerability management
Security monitoring
Stakeholder management
Project leadership

Education

Degree in Information Technology or Cybersecurity

Tools

SIEM
EDR/XDR
Vulnerability scanners
Firewalls
IT/OT security

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

Strong work cultureCompetitive Salary
  • Lead enterprise cybersecurity architecture and security improvement initiatives across IT and OT environments.
  • Analyze cyber threat intelligence and emerging attack techniques to identify organizational risks.
  • Correlate threat intelligence, vulnerabilities, and attack methodologies to develop effective defensive strategies.
  • Drive vulnerability and threat management programs, including prioritization and remediation of security findings.
  • Manage penetration testing engagements and oversee remediation of identified vulnerabilities.
  • Lead security monitoring, threat detection, threat hunting, and incident response activities.
  • Design and implement security controls to strengthen enterprise security posture.
  • Support development of security policies, standards, and governance frameworks.
  • Collaborate with GRC teams on risk governance, compliance, and security assessments.
  • Conduct vendor and third-party security risk assessments.
  • Manage cybersecurity projects, vendors, and cross-functional stakeholders.
  • Support security operations across both enterprise IT and OT environments, including OT threat detection and remediation activities.
  • Lead enterprise cybersecurity architecture and security improvement initiatives across IT and OT environments.
  • Analyze cyber threat intelligence and emerging attack techniques to identify organizational risks.
  • Correlate threat intelligence, vulnerabilities, and attack methodologies to develop effective defensive strategies.
  • Drive vulnerability and threat management programs, including prioritization and remediation of security findings.
  • Manage penetration testing engagements and oversee remediation of identified vulnerabilities.
  • Lead security monitoring, threat detection, threat hunting, and incident response activities.
  • Design and implement security controls to strengthen enterprise security posture.
  • Support development of security policies, standards, and governance frameworks.
  • Collaborate with GRC teams on risk governance, compliance, and security assessments.
  • Conduct vendor and third-party security risk assessments.
  • Manage cybersecurity projects, vendors, and cross-functional stakeholders.
  • Support security operations across both enterprise IT and OT environments, including OT threat detection and remediation activities.
A successful Staff IT Security Engineer should have:
  • A degree in Information Technology, Cybersecurity, or a related field.
  • Strong knowledge of IT security principles and best practices.
  • Experience with security tools such as firewalls, intrusion detection systems, and vulnerability scanners.
  • Familiarity with regulatory compliance standards and frameworks.
  • Proven ability to manage and respond to cybersecurity incidents effectively.
  • Analytical thinking and problem-solving skills.
  • Excellent communication and teamwork abilities.8+ years of experience in cybersecurity, security engineering, security operations, or security architecture.
  • Strong expertise in cyber threat intelligence, attack techniques, incident response, and vulnerability management.
  • Hands-on experience with SIEM, EDR/XDR, threat detection, and security monitoring platforms.
  • Strong understanding of security architecture, network security, and enterprise security controls.
  • Proven experience leading remediation programs and driving risk reduction initiatives.
  • Experience managing penetration testing activities and security assessments.
  • Working knowledge of IT and OT security environments.
  • Familiarity with ISO 27001, ISMS, risk governance, and security policy development.
  • Strong stakeholder management, vendor management, and project leadership capabilities.
Preferred Experience
  • OT/ICS security experience.
  • Experience with NIST, ISA/IEC 62443, or Purdue Model.
  • Third-party/vendor security review experience.
  • Cloud security experience (Azure, AWS, GCP).
  • Security certifications such as CISSP, CISM, GCIH, GCIA, GICSP, or equivalent.

My client is a high-tech regional hub in Penang shaping the future of power through advanced, large-scale manufacturing.

  • Competitive salary ranging from MYR 194400 to MYR 237600 annually.
  • Comprehensive benefits package.
  • Permanent position within a stable industry.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services Malaysia • Kuala Lumpur

On-site
MYR 89,000 - 167,000
Salary 8k-15k MYR
Certifications support
Career development
Cyber Security Engineer
Cyber Security Engineer

Crestino Tech Solution • Selangor

On-site
MYR 90,000 - 150,000
Cybersecurity Engineer
Cybersecurity Engineer

Blue Fortress Sdn. Bhd. • Alor Setar

On-site
MYR 90,000 - 130,000
Security Engineer
Security Engineer

Job Search Asia • Petaling Jaya

On-site
MYR 90,000 - 150,000
EPF
SOCSO
EIS
System Engineer (Cybersecurity)
System Engineer (Cybersecurity)

Blue Fortress Sdn. Bhd. • Alor Setar

On-site
MYR 36,000 - 60,000
IT Security Assistant Manager / Manager
IT Security Assistant Manager / Manager

NTT DATA Payment Services • Subang Jaya

On-site
MYR 90,000 - 150,000
IT CYBERSECURITY
IT CYBERSECURITY

Tasco Berhad • Shah Alam

On-site
MYR 72,000 - 120,000
Cyber Security Analyst (Contract)
Cyber Security Analyst (Contract)

Experian • Kuala Selangor

On-site
MYR 100,000 - 160,000
Manager, Cybersecurity Engineering - Operations
Manager, Cybersecurity Engineering - Operations

SD Guthrie • Selangor

Hybrid
MYR 240,000 - 420,000
Flexible Benefits
Hybrid Workplace
Learning on Demand
+3
Information Security Analyst
Information Security Analyst

Ricoh • Shah Alam

Hybrid
MYR 60,000 - 120,000
Work from home
Vision insurance