Why PayNet / Why Now
- PayNet operates at a scale where technology, reliability, and trust are fundamental to the services we provide.
- As our platforms, partnerships, and capabilities continue to evolve, so does the complexity of the environment we operate in.
- You'll join a team that values curiosity, autonomy, and the ability to turn challenges into lasting improvements.
- We are investing in people who can navigate ambiguity, make sound decisions, and help build sustainable capabilities for the future.
- This is an opportunity to shape meaningful outcomes in an organisation where ownership, accountability, and continuous improvement are highly valued.
TL; DR
- Own the detection, investigation, and response to cyber threats across PayNet's technology environment.
- Build and improve security detections, automation, and response capabilities that reduce risk and improve resilience.
- Drive proactive threat hunting and use intelligence to identify threats before they become incidents.
- Influence how security is embedded across cloud, infrastructure, and technology platforms.
- Play a key role during cyber incidents, making evidence-based decisions when speed and accuracy matter most.
Why This Role Matters
- The quality of our detection and response capabilities determines how quickly threats are identified and contained.
- Effective automation creates faster more consistent outcomes while allowing human expertise to focus on higher-value investigations.
- Strong detection engineering reduces noise, improves visibility, and helps security teams focus on genuine threats.
- Turning security testing, incident lessons, and threat intelligence into meaningful improvements strengthens PayNet's overall security posture.
- This role requires judgment over process, particularly when balancing security risk, operational impact, and response urgency
What You Will Actually Do
- Own end-to-end incident investigations, from initial triage through containment, eradication, and recovery.
- Build, tune, and continuously improve detection logic across security monitoring platforms to increase threat visibility and reduce false positives.
- Shape and expand security automation through response playbooks and workflow orchestration.
- Drive threat-hunting initiatives using threat intelligence, adversary techniques, and behavioural analysis.
- Influence DevSecOps practices by integrating security controls into technology delivery pipelines.
- Translate findings from security assessments, purple-team exercises, and vulnerabilities into stronger controls, detections, and defensive capabilities.
Examples of This Role in Practice
- A high-severity alert triggers during an on-call shift, and you quickly determine whether it is a real threat, contain the impact, and guide the response effort.
- A recurring alert generates excessive noise, and you redesign the detection to improve accuracy without weakening coverage.
- A threat-hunting exercise uncovers suspicious activity that existing controls missed, leading you to develop new detection logic and response procedures.
- A cloud workload exhibits unusual behaviour, requiring you to combine evidence from multiple sources to determine risk and next actions.
- A red-team exercise reveals a defensive gap, and you convert the findings into measurable improvements across monitoring and response capabilities.
What Will Help You Succeed
Required
- Strong analytical thinking and the ability to investigate complex security events using incomplete or rapidly changing information.
- Practical experience with security monitoring, threat detection, incident response, and security operations.
- Working knowledge of cloud security principles and modern detection and response technologies.
- Ability to automate tasks and workflows using Python, PowerShell, Bash, or similar scripting languages.
- Clear communication skills and the confidence to work independently while collaborating with technical and business stakeholders.
Good to Have
- Familiarity with SIEM, SOAR, NDR, IDS/IPS, and detection engineering practices.
- of frameworks such as MITRE ATT&CK, NIST, ISO 27001, SOC 2, PCI DSS, and Bank Negara Malaysia RMiT.
- Exposure to Infrastructure as Code, DevSecOps, and cloud-native security technologies.
- Experience with vulnerability assessments, penetration testing, adversary emulation, or purple-team activities.
- Relevant cybersecurity certifications that demonstrate technical capability and continuous learning.
About the Company
Payments Network Malaysia Sdn Bhd
Embark on an exciting career journey with Payments Network Malaysia Sdn Bhd (PayNet), the heartbeat of Malaysia's financial markets!
As the national payments network and a pivotal infrastructure for Malaysia’s dynamic financial markets, PayNet is a linchpin in advancing the nation’s digital economy.
Our comprehensive suite of retail payment solutions - encompassing DuitNow (QR and P2P), JomPAY (Bill Payments), FPX (Online), MyDebit (Domestic Debit), MEPS (ATM), and IBG (Interbank GIRO) - not only offer wide accessibility but are seamlessly integrated into the fabric of daily life in Malaysia. These services have revolutionised the way Malaysians handle financial transactions, marking a significant leap in consumer convenience and efficiency.
At PayNet, our focus is on providing a safe, efficient, and innovative payments system. We are dedicated to improving and managing payment services that meet the evolving needs of consumers and businesses. Our work ensures the stability and reliability of Malaysia’s financial system, supporting the growth of the economy.
Learn more about our work and how we are contributing to Malaysia's financial future at www.paynet.my.
Join us in embracing digital payments and advancing Malaysia's financial landscape.