Technical Security Lead

  • Kuala Lumpur
  • Permanent
  • Full-time
  • 17 days ago
We are looking for a highly skilled, hands-on cybersecurity leader to serve as the technical deputy to the Head of Cybersecurity. This role will take full ownership of technical security execution - including architecture, implementation, integration, and advanced troubleshooting - across IT, OT, and cloud environments. You will be the go-to person for deep technical problem-solving, ensuring the security team delivers measurable results Preferred candidates from South East Asian countries, visa will be provided Key Responsibilities: Security Engineering & Architecture Design, implement, and maintain security solutions across cloud (Azure, AWS), network, endpoints, OT/ICS, and applications. Develop security architecture patterns for Zero Trust, cloud, and OT environments. Integrate and fine-tune SIEM, SOAR, EDR, vulnerability management, and OT monitoring tools. Security Operations & Detection Lead threat detection engineering - create custom detection rules, parsers, playbooks, and response workflows. Oversee vulnerability scanning, prioritization Conduct advanced incident response and digital forensics across IT and OT networks. Manage threat hunting activities and red/blue/purple team exercises. Penetration Testing / VAPT/ Red Teaming Plan, scope, and execute penetration tests across network, web applications, APIs, mobile, cloud Lead red team exercises simulating advanced persistent threats (APTs) against IT and OT environments. Develop and maintain attack playbooks using frameworks like MITRE ATT&CK, ICS ATT&CK. Conduct purple team engagements with SOC teams to validate and tune detections. Use tools such as Cobalt Strike, Caldera, Sliver, Metasploit, Bloodhound, Empire to emulate adversary TTPs. Develop custom payloads, scripts, and evasion techniques. Technical Leadership Act as the final technical escalation point for complex security issues. Mentor and coach, the security operations and engineering team members. Evaluate, test, and approve new security tools and technologies. Qualifications & Experience 10+ years in cybersecurity with hands-on offensive security and vulnerability management experience. Strong track record in planning and executing VAPT engagements and leading red team exercises. Expertise in tools: Tenable.sc, Tenable OT, Qualys, Rapid7, Cobalt Strike, Sliver, Metasploit, Burp Suite Pro, Nessus, Nmap, BloodHound. Deep knowledge of Active Directory exploitation, cloud attack paths (Azure, AWS) Experience mapping vulnerabilities to NIST CSF, CIS Controls, ISO 27001, IEC 62443. Strong scripting/programming skills (Python, PowerShell, Bash). Familiar with exploit frameworks, payload development, and post-exploitation techniques. Relevant certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRT About us: Skill Quotient Technologies ( https://skillquotientgroup.com/ ) is a leading IT company specializing in Cyber Security Services, Application Testing Services, Application Solutions, Data Engineering, Process Automation, and Cloud Computing. We are ISO 27001 certified, CMMI Level 3 and working towards achieving CREST certifications. With a reputation for excellence, professionalism, and commitment, we deliver tangible results to our clients, ensuring fast-paced project execution and maximum return on investment. Note: To get further updates on the latest job openings, please follow our LinkedIn official page: https://www.linkedin.com/company/skill-quotient-group/mycompany

foundit