Doctevo Sdn Bhd is seeking a Cybersecurity Engineer to design and implement a secure, compliant, and cost‑optimized framework for our SaaS platform on .NET Core 8 and Azure. The role ensures alignment with CIS Benchmarks, GDPR, and PDPA, covering cloud infrastructure, credential handling, API security, and compliance oversight.
Responsibilities
- Credential & Access Design: Implement Azure Key Vault with Managed Identities, rotation policies, and outbound API credential handling.
- Cloud & Identity Security: Harden Azure resources, configure NSGs/Firewall/WAF, architect Entra ID, MFA, and RBAC.
- Integration & Data Protection: Guardrails for AI API flows, PII filtering, secure SendGrid/DNS protocols.
- Database & Application Security: MSSQL encryption/auditing, secure .NET middleware, CSP for frontend.
- Compliance Oversight: Map controls to GDPR/PDPA, review pentest results, provide remediation.
Skills Required
- Azure Mastery: Expert knowledge of Azure Security, Entra ID, and Azure Key Vault.
- Stack Expertise: Deep understanding of .NET Core 8, C#, MSSQL, and JQuery/Bootstrap security.
- Credential Management: Experience with Managed Identities and secure outbound API integration.
- Regulatory Knowledge: Practical experience implementing GDPR and PDPA.
- Cost Management: Ability to utilize native tools to minimize monthly spend.
Deliverables
- Design Submission: The Cloud Engineer submits the blueprint for your approval.
- Technical Handover: Provides the Cloud Engineer with specific security instructions for the build.
- Verification Audit: Performs a final audit to ensure the implementation matches the CIS standards and compliance design.