Cybersecurity Engineer
Job description
Cybersecurity Engineer at Bamboohr.
About the role
Bamboohr is seeking a Cybersecurity Engineer to join their team across Federal Territory Labuan and Kuala Lumpur or Johor, Malaysia. This full-time position involves protecting the organization's digital infrastructure, identifying vulnerabilities, and implementing security measures to safeguard sensitive data and systems from potential threats. The role requires a proactive approach to threat detection and response, ensuring that Bamboohr's operations remain secure against evolving cyber risks and attack methods. The Cybersecurity Engineer will work closely with cross-functional teams to embed security practices into everyday workflows, development processes, and business operations across the company.
Key facts
What you'll do
- Monitor network systems and application environments for signs of unauthorized access or suspicious activity on a daily basis and during off-hours.
- Conduct vulnerability assessments and penetration testing to identify weaknesses in Bamboohr's IT infrastructure, web applications, and software products before they can be exploited.
- Develop and maintain security policies, procedures, and guidelines that align with industry standards and regulatory requirements applicable to the financial services sector.
- Respond to security incidents by investigating breaches, containing active threats, eradicating malicious components, and coordinating recovery efforts across all affected systems and networks.
- Collaborate with software engineering teams to integrate security checks into the application development and deployment pipeline, ensuring code quality and security at every stage.
- Perform security audits of third-party vendors and external service providers to ensure their practices meet Bamboohr's internal security standards and compliance obligations.
- Analyze security logs, alerts, and threat intelligence feeds to detect patterns and potential attack vectors that may target the organization's critical assets.
- Design and implement network segmentation, firewalls, intrusion detection systems, and other defensive controls to reduce the overall attack surface of the infrastructure.
- Provide security awareness training and practical guidance to staff members to help them recognize phishing attempts, social engineering tactics, and other common threats.
- Document security configurations, incident reports, and remediation plans to maintain a clear and accessible record of all protective measures and responses taken.
Requirements
- Bachelor's degree in computer science, information technology, cybersecurity, or a closely related technical field from an accredited institution.
- Proven experience in a cybersecurity engineering or information security role within a corporate or enterprise environment, with a track record of successful projects.
- Strong understanding of network protocols, operating systems, and common application security vulnerabilities and mitigation techniques used to protect modern IT environments.
- Familiarity with incident response methodologies and the ability to handle security breaches in a structured, timely, and well-documented manner under pressure.
- Excellent analytical and problem-solving skills with a high level of attention to detail when reviewing complex system configurations, logs, and network traffic.
- Ability to communicate technical security concepts clearly and effectively to both technical colleagues and non-technical stakeholders across different departments.
- Willingness to work across multiple office locations in Malaysia, including Federal Territory Labuan and Kuala Lumpur or Johor, as project demands require.
- Commitment to staying current with emerging threats, security frameworks, and best practices in the cybersecurity domain through continuous self-education.
Nice to have
- Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP) are highly valued.
- Experience with cloud security platforms and services including AWS, Azure, or Google Cloud security configurations and identity and access management.
- Knowledge of DevSecOps practices and hands-on experience integrating automated security testing tools into continuous integration and continuous deployment workflows.
- Background in regulatory compliance frameworks such as ISO 27001, NIST Cybersecurity Framework, or GDPR and their practical application in a business setting.
Skills & tools
- Proficiency with security information and event management (SIEM) platforms for log aggregation, correlation, alerting, and forensic investigation of security events.
- Experience with endpoint detection and response (EDR) tools and antivirus or anti-malware solutions for comprehensive workstation and server protection across the organization.
- Familiarity with scripting or programming languages such as Python, Bash, or PowerShell for automating repetitive security tasks, data analysis, and reporting.
- Working knowledge of firewalls, virtual private networks (VPNs), and network access control mechanisms and their proper configuration and ongoing management.
- Understanding of web application security concepts including OWASP Top Ten vulnerabilities, secure coding principles, and common injection attack prevention techniques.
- Ability to use packet analysis and network monitoring tools to inspect traffic patterns, diagnose security anomalies, and support incident investigations.
Practical notes
- The role is based in Malaysia with possible assignments across Federal Territory Labuan, Kuala Lumpur, and Johor depending on project needs and team requirements.
- This is a full-time position with standard business hours, though on-call availability may be required for incident response duties during evenings or weekends.
- Candidates should be prepared to undergo a thorough background check and provide professional references as part of the hiring and onboarding process.
- Bamboohr values continuous learning and may support professional development through training budgets, conference attendance, or certification reimbursement programs for eligible employees.