Security Specialist
Indexed description
Job Responsibilities
We are seeking an experienced and highly analytical Senior Information Security Specialist to strengthen our cybersecurity posture and lead critical security initiatives. In this senior role, you will drive the identification and remediation of complex vulnerabilities, lead incident response efforts, and provide expert guidance to technical and business stakeholders.
You will play a key role in shaping security strategies, enhancing our defensive capabilities, and ensuring the resilience of our systems against evolving threats. This position requires strong technical depth, proactive leadership, and the ability to influence security practices across the organization.
- Lead vulnerability assessments across networks, applications, and infrastructure, delivering clear, actionable remediation guidance to technical and non‑technical stakeholders.
- Plan and conduct advanced penetration testing (network, application, cloud, and infrastructure), producing high‑quality reports with prioritized risk-based recommendations.
- Review, refine, and optimize security controls, including firewall rulesets, network segmentation, and endpoint configurations to ensure continuous hardening of the environment.
- Monitor, analyze, and respond to complex security alerts and incidents, ensuring timely triage, containment, eradication, and detailed root cause analysis.
- Act as an escalation point for incident investigations, coordinating cross-functional response efforts and ensuring lessons learned are captured and implemented.
- Review, validate, and prioritize bug bounty submissions, working collaboratively with security researchers and internal engineering teams to remediate identified vulnerabilities.
- Collaborate with IT, DevOps, Cloud, Risk and Compliance teams to embed security best practices throughout the system development lifecycle and operational processes.
- Engage with business units as a trusted security advisor, providing expert guidance, risk assessments, and recommendations to support secure business decisions.
- Champion and drive security awareness initiatives, fostering strong security culture and improving organization-wide security maturity.
- Contribute to security strategy, standards, and continuous improvement, leveraging threat intelligence, emerging trends, and lessons learned.
- Perform additional duties as assigned by the Team Lead or Manager to support departmental goals.
- Bachelor’s Degree, Postgraduate Diploma, or Professional Qualification in Computer Science, Information Security, IT, or a related field. Equivalent practical experience will be considered.
- Minimum 5 years hands-on experience in cybersecurity, ethical hacking, penetration testing, or information security.
- Industry certifications such as Security+, CEH, OSCP, eJPT, eWPT, GIAC or similar are highly advantageous.
- For senior or lead roles: demonstrated leadership capability—team guidance, project ownership, and cross-functional influence.
- Proficiency with offensive and defensive security tools such as Burp Suite, Metasploit, Nessus, Qualys, Splunk, SIEM platforms, and other industry-standard toolsets.
- Strong technical understanding of network protocols, web application security (OWASP Top 10), vulnerability analysis, and threat detection methodologies.
- Hands‑on experience with AWS Cloud services (security controls, IAM, networking) and Linux system administration is essential.
- Strong analytical and problem solving skills, with the ability to operate independently and collaboratively in a fast-paced environment.
- Strong communication and reporting skills, with the ability to articulate complex technical risks to non‑technical stakeholders.
- Willingness to work on-site in i-City Shah Alam.
Are you game?
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search