jobs in Maybank

Kerja Sepenuh Masa, Senior Cloud Vulnerability Management - DevSecOps I IT Security di Maybank Federal Territory - Maukerja

Senior Cloud Vulnerability Management - DevSecOps I IT Security

KL City, Federal Territory

Kongsi
Simpan

Lokasi Kerja

  • Kuala Lumpur Federal Territory Malaysia

Penerangan Kerja

Tanggungjawab

Background

  • The Senior Cloud Vulnerability & DevSecOps supports the Threat & Vulnerability Management operations. This role ensures that the organization’s cloud architecture, services, and workloads are secure from evolving threats by proactively identifying vulnerabilities via CI/CD pipelines and cloud security operations and driving remediation strategies.
  • The incumbent will define vulnerability management methodologies, mentor junior team members, and serve as a technical advisor to cross-functional teams, contributing directly to the enterprise’s overall cloud security posture.


Key Responsibilities

  • Manage end-to-end vulnerability management for Azure and AWS environments.
  • Perform risk-based prioritization and coordinate remediation with Cloud, DevOps, and application teams.
  • Define, track, and report on remediation SLAs, exceptions, and risk treatment plans.
  • Integrate security controls into CI/CD pipelines (SAST, DAST, SCA, secrets scanning, container and IaC scanning).
  • Support software supply chain security (SBOMs, provenance, code signing, open-source governance).
  • Ensure alignment with internal policies, standards, and regulatory requirements.
  • Produce dashboards and metrics on cloud vulnerability risk and DevSecOps maturity.
  • Collaborate with Security Operations, Risk, and Engineering teams to drive continuous improvement in cloud security posture and DevSecOps practices.
  • Support secure IAM configuration processes and identity automation workflows.
  • Continue learning and staying updated on cloud technologies and best practices.


Key Requirements

  • Bachelor Degree in Business, Computer Science, Information Security, Cybersecurity, or related technical field, or equivalent.
  • Minimum 5 years of experience in penetration testing, with at least 2–3 years focused on cloud platforms (AWS, Azure, GCP).
  • Proven experience performing Penetration Testing in a cloud infrastructure, cloud misconfiguration exploitation, and offensive tool development.
  • Experience in regulated environments (e.g., banking, finance, or telecommunications) is highly advantageous.
  • Hands-on experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, CircleCI).
  • In-depth knowledge of public cloud environments: AWS, Azure, and GCP.
  • Strong understanding of IAM, cloud networking, compute, serverless, containers (Kubernetes), storage, and logging.
  • Skilled in offensive security tools such as Pacu, ScoutSuite, Prowler, Burp Suite, Nmap, custom scripting (Python, Bash, PowerShell).
  • Familiar with IaC and CI/CD tooling: Terraform, CloudFormation, Jenkins, GitLab CI, etc.
  • Strong understanding of MITRE ATT&CK for Cloud, adversary simulation, and attacker TTPs.
  • Strong analytical and problem-solving mindset.
  • Effective communication skills — capable of presenting to both technical and senior leadership audiences.
  • Leadership and mentoring abilities, with experience guiding junior security professionals.
  • Self-driven, highly motivated, and able to work independently in a fast-paced environment.
  • Collaborative and adaptable — capable of working across departments and business units.


Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut