Job Purpose
CGC Digital builds and runs SME financing platforms on AWS: customer portals, mobile apps, government-facing programme modules and AI-powered services. The Cybersecurity Specialist owns day-to-day security of these platforms: identity and access governance, AWS security, security monitoring, compliance, and the secure use of AI, including agentic AI and Amazon Bedrock.
AI-assisted tooling are part of how CGC Digital develops and operates its platforms. You must be able to secure what both engineers and AI tools build, and use AI tools yourself to work effectively. This is a hands-on role reporting functionally to the Head of DevOps.
Roles & Responsibilities
1. Cybersecurity Governance & Information Protection
- Apply CGC Digital security policies and standards across all platforms and environments (Dev, SIT, UAT, Staging, Production).
- Implement and verify controls that protect the confidentiality, integrity and availability of business systems and customer data.
- Enforce internal cybersecurity policies and operational security standards.
2. Identity and Access Management (IAM) Governance
- Own the user access lifecycle for AWS, Microsoft Dynamics 365 Business Central, Atlassian Jira and GitHub: provisioning, changes, periodic access reviews and deactivation.
- Enforce least privilege, MFA, segregation of duties, privileged access governance and Zero Trust principles. Keep evidence audit-ready.
3. AWS Cloud Security Management
- Administer IAM users, roles and policies, AWS IAM Identity Center (SSO) and Amazon Cognito across a multi-account AWS organisation.
- Maintain Service Control Policies (SCP) and permission boundaries. Review IAM roles used by CI/CD pipelines and AI agents.
- Monitor AWS CloudTrail, AWS Config, Amazon GuardDuty and Security Hub. Act on findings to closure.
- Govern secrets: enforce AWS Systems Manager Parameter Store and Secrets Manager. No credentials in code, buildspecs or container images.
- Secure containerised (ECS, ECR) and serverless (Lambda, API Gateway, CloudFront, S3) workloads, including image scanning and immutable image tags.
4. AI & Agentic Systems Security
- Secure Amazon Bedrock: model access policies, Bedrock Guardrails, Knowledge Base data access, model invocation logging and private (VPC endpoint) connectivity.
- Govern AI agents (Amazon Bedrock Agents / AgentCore, Claude Code, Amazon Q Developer, GitHub Copilot, MCP servers): scoped IAM roles, least-privilege tool access, human approval gates and audit trails of agent actions.
- Protect LLM applications against prompt injection, data leakage, insecure output handling and excessive agency, in line with the OWASP Top 10 for LLM Applications.
- Control third-party AI API usage (Anthropic Claude, Google Gemini, OpenAI): API key lifecycle, spend limits and data classification of what may be sent to each provider.
- Review AI-generated code and infrastructure changes for security defects before merge.
- Use AI tools to automate access reviews, log analysis, alert triage and policy audits.
5. DevSecOps & Pipeline Security
- Embed security gates in AWS CodePipeline / CodeBuild: SonarQube quality gate, dependency and container scanning, and IaC scanning (Terraform, CloudFormation).
- Review pull requests for security impact. Block merges that fail security gates.
6. Security Monitoring & Incident Response
- Monitor the SIEM, Orca Security (CSPM) and Bitdefender GravityZone (endpoint). Triage and investigate alerts with the SOC.
- Lead first response to security incidents on our platforms. Document root cause and corrective actions.
- Stay composed and decisive under time pressure.
7. Vulnerability & Risk Management
- Review vulnerability assessment and penetration testing findings. Validate exploitability and business risk before remediation.
- Track patching and remediation to closure across application, container and cloud layers.
8. IT Audit, RMiT Compliance & Documentation
- Participate in internal, external and regulatory IT audits: coordinate with auditors, walk through security controls, and collect and present evidence.
- Own the audit findings tracker. Log every finding and compliance item, assign owners, track remediation to closure and report status weekly.
- Keep the platforms and the team fully compliant with CGC IT policies and Bank Negara Malaysia's Risk Management in Technology (RMiT). Map security controls to RMiT requirements and close gaps.
- Maintain evidence for ISO 27001, NIST Cybersecurity Framework, SOC 2 and client or government project audits.
- Maintain operational manuals for access governance, SOC procedures and the AI acceptable-use policy.
- Report security posture, audit status, incident trends and RMiT compliance to the Head of DevOps.
Qualifications:
- Diploma or Bachelor's Degree in Information Systems, Network and Security, Computer Science or a related discipline.
Certifications (Preferred):
- AWS Certified Security – Specialty or AWS Certified Solutions Architect
- AWS Certified AI Practitioner
- CompTIA Security+
- Certified Information Systems Security Professional (CISSP) – for senior candidates
- Certified Identity and Access Manager (CIAM) or equivalent IAM certification
- Microsoft SC-900 (Security, Compliance, and Identity Fundamentals)
Requirements:
- 3–4 years in cloud security or SOC environments, with at least 2 years hands-on on AWS.
- Hands-on with AWS IAM, IAM Identity Center, Cognito, SCPs, CloudTrail and AWS Config.
- Working knowledge of Amazon Bedrock and at least one LLM or agent framework. Able to explain how an AI agent obtains and uses credentials, and how to constrain it.
- Daily use of AI coding assistants (Claude Code, Amazon Q Developer, GitHub Copilot or similar) with the judgement to review their output critically.
- Experience supporting IT audits and tracking findings to closure. Exposure to BNM RMiT or similar regulatory technology requirements preferred.
- Strong analytical and incident investigation skills. Clear written reporting.
Knowledge
- IAM lifecycle: role-based access control, least privilege and segregation of duties.
- Security monitoring, threat detection and incident response using SIEM platforms.
- Cloud Security Posture Management (CSPM) using Orca Security. Endpoint protection using Bitdefender GravityZone.
- Amazon Bedrock security model: IAM for model invocation, Guardrails, Knowledge Bases, invocation logging, PrivateLink / VPC endpoints.
- Agentic AI architecture: agents, tools and function calling, Model Context Protocol (MCP), retrieval-augmented generation (RAG), and where the security boundaries sit.
- OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework and ISO/IEC 42001 awareness.
- Container and serverless security on AWS: ECS / ECR, Lambda, API Gateway, CloudFront, S3.
- Vulnerability management and risk validation.
- User access management for Microsoft Dynamics 365 Business Central and Atlassian Jira.
- Compliance frameworks: ISO 27001, NIST Cybersecurity Framework, SOC 2.
- Bank Negara Malaysia RMiT policy: technology risk management, cybersecurity, access control, cloud and third-party risk, and audit expectations.
Skills/Competencies:
- Security event detection, correlation and investigation through SIEM solutions.
- Operating CSPM (Orca Security) and endpoint protection (Bitdefender GravityZone).
- Scripting and automation (Python, Bash, AWS CLI) for access reviews, log parsing and policy audits, including with AI assistance.
- Security review of Infrastructure as Code (Terraform, AWS CloudFormation).
- Prompt engineering and safe use of AI assistants for security work. Critical review of AI-generated code and configuration.
- Audit coordination and findings tracking: evidence management, remediation follow-up and compliance reporting.
- Stakeholder communication: translate technical findings into business risk language.
- Continuous learning to keep pace with evolving threats, AI tooling and AWS services.
Pay: RM3,400.00 - RM5,600.00 per month
Benefits:
- Dental insurance
- Health insurance
- Maternity leave
- Opportunities for promotion
- Parental leave
- Professional development
- Work from home
Work Location: Hybrid remote in Kelana Jaya