Security Engineer

PROCESS AND INFORMATION OFFICE
Malaysia

Executive


Responsibilities

  1. Manage cybersecurity every day
  2. Keep the company's computers, servers, cloud systems, networks, Microsoft 365, and employee devices secure.
  3. Handle security incidents
  4. When something suspicious happens—such as malware, phishing, a compromised account, or a data breach—you investigate what happened, contain the problem, fix it, and make sure it doesn't happen again.
  5. Find and fix security weaknesses
  6. Regularly look for vulnerabilities in systems and applications, monitor security alerts, and make sure important security risks are addressed.
  7. Manage security policies and compliance
  8. Create and maintain cybersecurity policies, standards, and procedures, and make sure the company follows them.
  9. Work with ISO 27001
  10. Help maintain the company's ISO 27001 Information Security Management System (ISMS), prepare for audits, maintain required documentation, and make sure security controls are working.
  11. Assess security risks
  12. Look at potential threats and weaknesses, decide how serious they are, and recommend ways to reduce the risk.
  13. Work with different teams
  14. You'll communicate with IT, management/business teams, auditors, and outside security vendors or partners.
  15. Improve security systems and processes
  16. Review how the company currently protects its systems and suggest better ways to design, configure, and operate them.
  17. Teach employees about security
  18. Help run cybersecurity awareness programs, such as phishing training, security briefings, and employee education.
  19. Guide junior security staff
  20. Help less-experienced security engineers develop their technical skills and handle security tasks.

Requirements

  1. Someone with at least 4-5 years of cybersecurity experience, preferably someone who has worked inside a company rather than mainly works for a consulting company or system integrator.
  2. Possess hands-on experience with:
  • Microsoft 365 — securing email, Teams, SharePoint, etc.
  • Entra ID — Microsoft's identity and access management system (formerly Azure AD)
  • Endpoint security — protecting laptops, desktops, and other employee devices
  • SIEM — collecting and analyzing security logs and alerts
  • EDR — detecting and responding to threats on computers
  • Security operations — monitoring and responding to security threat
  • ISO 27001 — implementing controls and preparing for auditsCertifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, or Security+ are a plus.
  1. Excellent communication and presentation skills.
  2. Strong problem-solving skills and attention to detail.
  3. Proficient in English and Bahasa (both written and verbal).

APPLY

About the Company

MESINIAGA BERHAD