jobs in PayNet (Payments Network Malaysia)

全职 Security Engineer (Blue Team) 工作, 薪水, PayNet (Payments Network Malaysia) Federal Territory 公司招聘中 - Ricebowl

Security Engineer (Blue Team)

PayNet (Payments Network Malaysia)

KL City, Federal Territory

分享
保存

工作地点

  • Jalan Sultan Mizan Zainal Abidin, Kompleks Kerajaan Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

Why PayNet / Why Now

  • PayNet operates at a scale where technology, reliability, and trust are fundamental to the services we provide.
  • As our platforms, partnerships, and capabilities continue to evolve, so does the complexity of the environment we operate in.
  • You'll join a team that values curiosity, autonomy, and the ability to turn challenges into lasting improvements.
  • We are investing in people who can navigate ambiguity, make sound decisions, and help build sustainable capabilities for the future.
  • This is an opportunity to shape meaningful outcomes in an organisation where ownership, accountability, and continuous improvement are highly valued.

TL; DR

  • Own the detection, investigation, and response to cyber threats across PayNet's technology environment.
  • Build and improve security detections, automation, and response capabilities that reduce risk and improve resilience.
  • Drive proactive threat hunting and use intelligence to identify threats before they become incidents.
  • Influence how security is embedded across cloud, infrastructure, and technology platforms.
  • Play a key role during cyber incidents, making evidence-based decisions when speed and accuracy matter most.

Why This Role Matters

  • The quality of our detection and response capabilities determines how quickly threats are identified and contained.
  • Effective automation creates faster more consistent outcomes while allowing human expertise to focus on higher-value investigations.
  • Strong detection engineering reduces noise, improves visibility, and helps security teams focus on genuine threats.
  • Turning security testing, incident lessons, and threat intelligence into meaningful improvements strengthens PayNet's overall security posture.
  • This role requires judgment over process, particularly when balancing security risk, operational impact, and response urgency

What You Will Actually Do

  • Own end-to-end incident investigations, from initial triage through containment, eradication, and recovery.
  • Build, tune, and continuously improve detection logic across security monitoring platforms to increase threat visibility and reduce false positives.
  • Shape and expand security automation through response playbooks and workflow orchestration.
  • Drive threat-hunting initiatives using threat intelligence, adversary techniques, and behavioural analysis.
  • Influence DevSecOps practices by integrating security controls into technology delivery pipelines.
  • Translate findings from security assessments, purple-team exercises, and vulnerabilities into stronger controls, detections, and defensive capabilities.

Examples of This Role in Practice

  • A high-severity alert triggers during an on-call shift, and you quickly determine whether it is a real threat, contain the impact, and guide the response effort.
  • A recurring alert generates excessive noise, and you redesign the detection to improve accuracy without weakening coverage.
  • A threat-hunting exercise uncovers suspicious activity that existing controls missed, leading you to develop new detection logic and response procedures.
  • A cloud workload exhibits unusual behaviour, requiring you to combine evidence from multiple sources to determine risk and next actions.
  • A red-team exercise reveals a defensive gap, and you convert the findings into measurable improvements across monitoring and response capabilities.

Required

What Will Help You Succeed

  • Strong analytical thinking and the ability to investigate complex security events using incomplete or rapidly changing information.
  • Practical experience with security monitoring, threat detection, incident response, and security operations.
  • Working knowledge of cloud security principles and modern detection and response technologies.
  • Ability to automate tasks and workflows using Python, PowerShell, Bash, or similar scripting languages.
  • Clear communication skills and the confidence to work independently while collaborating with technical and business stakeholders.

Good to Have

  • Familiarity with SIEM, SOAR, NDR, IDS/IPS, and detection engineering practices.
  • of frameworks such as MITRE ATT&CK, NIST, ISO 27001, SOC 2, PCI DSS, and Bank Negara Malaysia RMiT.
  • Exposure to Infrastructure as Code, DevSecOps, and cloud-native security technologies.
  • Experience with vulnerability assessments, penetration testing, adversary emulation, or purple-team activities.
  • Relevant cybersecurity certifications that demonstrate technical capability and continuous learning.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多