Senior Cloud Vulnerability Management & DevSecOps I IT Security
Maybank
Background
- The Senior Cloud Vulnerability & DevSecOps supports the Threat & Vulnerability Management operations. This role ensures that the organization’s cloud architecture, services, and workloads are secure from evolving threats by proactively identifying vulnerabilities via CI/CD pipelines and cloud security operations and driving remediation strategies.
- The incumbent will define vulnerability management methodologies, mentor junior team members, and serve as a technical advisor to cross-functional teams, contributing directly to the enterprise’s overall cloud security posture.
Key Responsibilities
- Manage end-to-end vulnerability management for Azure and AWS environments.
- Perform risk-based prioritization and coordinate remediation with Cloud, DevOps, and application teams.
- Define, track, and report on remediation SLAs, exceptions, and risk treatment plans.
- Integrate security controls into CI/CD pipelines (SAST, DAST, SCA, secrets scanning, container and IaC scanning).
- Support software supply chain security (SBOMs, provenance, code signing, open-source governance).
- Ensure alignment with internal policies, standards, and regulatory requirements.
- Produce dashboards and metrics on cloud vulnerability risk and DevSecOps maturity.
- Collaborate with Security Operations, Risk, and Engineering teams to drive continuous improvement in cloud security posture and DevSecOps practices.
- Support secure IAM configuration processes and identity automation workflows.
- Continue learning and staying updated on cloud technologies and best practices.
Key Requirements
- Bachelor Degree in Business, Computer Science, Information Security, Cybersecurity, or related technical field, or equivalent.
- Minimum 5 years of experience in penetration testing, with at least 2–3 years focused on cloud platforms (AWS, Azure, GCP).
- Proven experience performing Penetration Testing in a cloud infrastructure, cloud misconfiguration exploitation, and offensive tool development.
- Experience in regulated environments (e.g., banking, finance, or telecommunications) is highly advantageous.
- Hands-on experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, CircleCI).
- In-depth knowledge of public cloud environments: AWS, Azure, and GCP.
- Strong understanding of IAM, cloud networking, compute, serverless, containers (Kubernetes), storage, and logging.
- Skilled in offensive security tools such as Pacu, ScoutSuite, Prowler, Burp Suite, Nmap, custom scripting (Python, Bash, PowerShell).
- Familiar with IaC and CI/CD tooling: Terraform, CloudFormation, Jenkins, GitLab CI, etc.
- Strong understanding of MITRE ATT&CK for Cloud, adversary simulation, and attacker TTPs.
- Strong analytical and problem-solving mindset.
- Effective communication skills — capable of presenting to both technical and senior leadership audiences.
- Leadership and mentoring abilities, with experience guiding junior security professionals.
- Self-driven, highly motivated, and able to work independently in a fast-paced environment.
- Collaborative and adaptable — capable of working across departments and business units.
Skills
- Adaptability
- Analytical
- AWS
- Azure
- Bash
- Cloudformation
- Communication
- Cybersecurity
- Gcp
- Github
- Github actions
- Gitlab
- Gitlab ci
- Iam
- Jenkins
- Kubernetes
- Leadership
- Networking
- Presentation
- Problem solving
- Python
- Terraform


