jobs in PayNet (Payments Network Malaysia)

PayNet (Payments Network Malaysia) Hiring! Full Time Security Engineer (Blue Team) in Federal Territory - Ricebowl

Security Engineer (Blue Team)

PayNet (Payments Network Malaysia)

KL City, Federal Territory

Share
Save

Working Location

  • Jalan Sultan Mizan Zainal Abidin, Kompleks Kerajaan Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

Why PayNet / Why Now

  • PayNet operates at a scale where technology, reliability, and trust are fundamental to the services we provide.
  • As our platforms, partnerships, and capabilities continue to evolve, so does the complexity of the environment we operate in.
  • You'll join a team that values curiosity, autonomy, and the ability to turn challenges into lasting improvements.
  • We are investing in people who can navigate ambiguity, make sound decisions, and help build sustainable capabilities for the future.
  • This is an opportunity to shape meaningful outcomes in an organisation where ownership, accountability, and continuous improvement are highly valued.

TL; DR

  • Own the detection, investigation, and response to cyber threats across PayNet's technology environment.
  • Build and improve security detections, automation, and response capabilities that reduce risk and improve resilience.
  • Drive proactive threat hunting and use intelligence to identify threats before they become incidents.
  • Influence how security is embedded across cloud, infrastructure, and technology platforms.
  • Play a key role during cyber incidents, making evidence-based decisions when speed and accuracy matter most.

Why This Role Matters

  • The quality of our detection and response capabilities determines how quickly threats are identified and contained.
  • Effective automation creates faster more consistent outcomes while allowing human expertise to focus on higher-value investigations.
  • Strong detection engineering reduces noise, improves visibility, and helps security teams focus on genuine threats.
  • Turning security testing, incident lessons, and threat intelligence into meaningful improvements strengthens PayNet's overall security posture.
  • This role requires judgment over process, particularly when balancing security risk, operational impact, and response urgency

What You Will Actually Do

  • Own end-to-end incident investigations, from initial triage through containment, eradication, and recovery.
  • Build, tune, and continuously improve detection logic across security monitoring platforms to increase threat visibility and reduce false positives.
  • Shape and expand security automation through response playbooks and workflow orchestration.
  • Drive threat-hunting initiatives using threat intelligence, adversary techniques, and behavioural analysis.
  • Influence DevSecOps practices by integrating security controls into technology delivery pipelines.
  • Translate findings from security assessments, purple-team exercises, and vulnerabilities into stronger controls, detections, and defensive capabilities.

Examples of This Role in Practice

  • A high-severity alert triggers during an on-call shift, and you quickly determine whether it is a real threat, contain the impact, and guide the response effort.
  • A recurring alert generates excessive noise, and you redesign the detection to improve accuracy without weakening coverage.
  • A threat-hunting exercise uncovers suspicious activity that existing controls missed, leading you to develop new detection logic and response procedures.
  • A cloud workload exhibits unusual behaviour, requiring you to combine evidence from multiple sources to determine risk and next actions.
  • A red-team exercise reveals a defensive gap, and you convert the findings into measurable improvements across monitoring and response capabilities.

Required

What Will Help You Succeed

  • Strong analytical thinking and the ability to investigate complex security events using incomplete or rapidly changing information.
  • Practical experience with security monitoring, threat detection, incident response, and security operations.
  • Working knowledge of cloud security principles and modern detection and response technologies.
  • Ability to automate tasks and workflows using Python, PowerShell, Bash, or similar scripting languages.
  • Clear communication skills and the confidence to work independently while collaborating with technical and business stakeholders.

Good to Have

  • Familiarity with SIEM, SOAR, NDR, IDS/IPS, and detection engineering practices.
  • of frameworks such as MITRE ATT&CK, NIST, ISO 27001, SOC 2, PCI DSS, and Bank Negara Malaysia RMiT.
  • Exposure to Infrastructure as Code, DevSecOps, and cloud-native security technologies.
  • Experience with vulnerability assessments, penetration testing, adversary emulation, or purple-team activities.
  • Relevant cybersecurity certifications that demonstrate technical capability and continuous learning.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More