Routiqo

Senior Cloud Vulnerability Management & DevSecOps I IT Security

Maybank

  • WP. Kuala Lumpur
  • Full-time

Background

  • The Senior Cloud Vulnerability & DevSecOps supports the Threat & Vulnerability Management operations. This role ensures that the organization’s cloud architecture, services, and workloads are secure from evolving threats by proactively identifying vulnerabilities via CI/CD pipelines and cloud security operations and driving remediation strategies.
  • The incumbent will define vulnerability management methodologies, mentor junior team members, and serve as a technical advisor to cross-functional teams, contributing directly to the enterprise’s overall cloud security posture.

Key Responsibilities

  • Manage end-to-end vulnerability management for Azure and AWS environments.
  • Perform risk-based prioritization and coordinate remediation with Cloud, DevOps, and application teams.
  • Define, track, and report on remediation SLAs, exceptions, and risk treatment plans.
  • Integrate security controls into CI/CD pipelines (SAST, DAST, SCA, secrets scanning, container and IaC scanning).
  • Support software supply chain security (SBOMs, provenance, code signing, open-source governance).
  • Ensure alignment with internal policies, standards, and regulatory requirements.
  • Produce dashboards and metrics on cloud vulnerability risk and DevSecOps maturity.
  • Collaborate with Security Operations, Risk, and Engineering teams to drive continuous improvement in cloud security posture and DevSecOps practices.
  • Support secure IAM configuration processes and identity automation workflows.
  • Continue learning and staying updated on cloud technologies and best practices.

Key Requirements

  • Bachelor Degree in Business, Computer Science, Information Security, Cybersecurity, or related technical field, or equivalent.
  • Minimum 5 years of experience in penetration testing, with at least 2–3 years focused on cloud platforms (AWS, Azure, GCP).
  • Proven experience performing Penetration Testing in a cloud infrastructure, cloud misconfiguration exploitation, and offensive tool development.
  • Experience in regulated environments (e.g., banking, finance, or telecommunications) is highly advantageous.
  • Hands-on experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, CircleCI).
  • In-depth knowledge of public cloud environments: AWS, Azure, and GCP.
  • Strong understanding of IAM, cloud networking, compute, serverless, containers (Kubernetes), storage, and logging.
  • Skilled in offensive security tools such as Pacu, ScoutSuite, Prowler, Burp Suite, Nmap, custom scripting (Python, Bash, PowerShell).
  • Familiar with IaC and CI/CD tooling: Terraform, CloudFormation, Jenkins, GitLab CI, etc.
  • Strong understanding of MITRE ATT&CK for Cloud, adversary simulation, and attacker TTPs.
  • Strong analytical and problem-solving mindset.
  • Effective communication skills — capable of presenting to both technical and senior leadership audiences.
  • Leadership and mentoring abilities, with experience guiding junior security professionals.
  • Self-driven, highly motivated, and able to work independently in a fast-paced environment.
  • Collaborative and adaptable — capable of working across departments and business units.

Skills

  • Adaptability
  • Analytical
  • AWS
  • Azure
  • Bash
  • Cloudformation
  • Communication
  • Cybersecurity
  • Gcp
  • Github
  • Github actions
  • Gitlab
  • Gitlab ci
  • Iam
  • Jenkins
  • Kubernetes
  • Leadership
  • Networking
  • Presentation
  • Problem solving
  • Python
  • Terraform