Kuala Lumpur, Malaysia | Posted on 05/12/2026
We are seeking a Windows OS / Desktop Security Developer to design, develop, harden, and maintain secure Windows desktop operating system configurations and endpoint security solutions. This role focuses on Windows OS security, endpoint hardening, automation, and secure configuration engineering, working closely with infrastructure, SOC, and security architecture teams.
Key Responsibilities
Windows OS & Endpoint Security Development
- Design and implement secure Windows OS baseline configurations (Windows10/11)
- Develop and maintain desktop security configurations aligned with CIS, Microsoft, or internal security benchmarks
- Harden OS services, registry settings, firewall policies, and system controls
- Support secure OS image creation, customization, and validation
Security Engineering & Automation
- Develop PowerShell scripts and automation for security configuration, compliance checks, and remediation
- Package and deploy security configurations using MDM / endpoint management tools (e.g., Intune, SCCM, Group Policy)
- Implement and enhance endpoint security controls such as:
- Application control (AppLocker / WDAC)
- Device control and exploit protection
Policy, Compliance & Vulnerability Management
- Implement and test desktop security policies (password, encryption, device control, DLP)
- Support OS patching, vulnerability remediation, and security updates
- Conduct security assessments and validation testing on Windows endpoints
- Assist with endpoint compliance reporting and audit support
- Work closely with Security Operations, Infrastructure, and IAM teams
- Provide technical input on endpoint security architecture and roadmap
- Troubleshoot complex OS and security-related issues
- Maintain technical documentation, standards, and run books
Requirements
- Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field
- 4–8 years of experience in Windows OS, endpoint, or desktop security engineering
- Strong knowledge of:
- Windows10 / 11 internals and security architecture
- Group Policy, Local Security Policy, Registry
- OS hardening and endpoint protection concepts
- Hands‑on experience with:
- Application control (AppLocker / WDAC)
- BitLocker and encryption technologies
- Solid understanding of security principles and attack vectors (malware, privilege escalation, lateral movement)
Preferred / Added Advantage
- Experience with Microsoft Intune, SCCM, or other UEM tools
- Knowledge of Zero Trust and endpoint security frameworks
- Exposure to CIS benchmarks, ISO 27001, or NIST standards
- Familiarity with Azure AD (Entitlement ID) device security and Conditional Access
- Security certifications (Microsoft, GIAC, CISSP, or similar)
- Strong attention to detail and security mindset
- Ability to work independently in regulated environments
- Strong documentation and communication skills
- Analytical and problem‑solving orientation
- Proactive approach to security improvement
What We Offer
- Opportunity to work on enterprise‑grade endpoint security platforms
- Collaboration with experienced security and infrastructure professionals
- Competitive compensation and benefits
- Training and certification support
- Career growth in endpoint and enterprise security engineering