
Cloud Security Engineer
- Kuala Lumpur
- Permanent
- Full-time
We are seeking an experienced Cloud Security Engineer to lead our cloud infrastructure security initiatives as part of our Infrastructure Vulnerability Management program. This role focuses on securing our cloud infrastructure and ensuring robust security posture across multi-cloud environments, with specific emphasis on identifying, assessing, and managing security vulnerabilities and misconfigurations across Azure (primary), AWS, and Google Cloud Platform environments.As a Cloud Security Engineer, you will serve as the primary technical expert for cloud security vulnerability management, working closely with DevOps, cloud architects, and development teams to secure our cloud-native infrastructure, reduce cloud-specific attack surfaces, and integrate security throughout the cloud development lifecycle.Key Responsibilities:Cloud Security Architecture & Posture Management
- Design and implement security controls for cloud infrastructure across Azure, AWS, and GCP environments
- Implement, configure, and manage Cloud Security Posture Management (CSPM) tools across all cloud platforms
- Deploy and maintain cloud vulnerability scanning solutions including Prisma Cloud, and native cloud security services
- Continuously monitor cloud infrastructure for security misconfigurations, and compliance violations
- Develop and maintain cloud security baselines and configuration standards
- Assess cloud-native services, serverless functions, and container environments for security vulnerabilities
- Manage comprehensive vulnerability scanning and remediation for cloud infrastructure, ensuring asset coverage and timely patching
- Conduct comprehensive security assessments across multi-cloud environments and hybrid infrastructure
- Perform vulnerability scanning of cloud workloads, virtual machines, containers, and cloud-native applications
- Analyze cloud security findings and validate vulnerabilities specific to cloud environments
- Monitor and assess Infrastructure as Code (IaC) templates for security misconfigurations before deployment
- Track and prioritize cloud infrastructure vulnerabilities based on risk and business impact
- Integrate cloud security tools into CI/CD pipelines and support container security initiatives
- Implement security scanning integration into CI/CD pipelines and DevOps workflows
- Develop and maintain Infrastructure as Code (IaC) security templates and automated security policy enforcement
- Develop automation scripts for cloud security monitoring, alerting, and remediation workflows
- Collaborate with DevOps teams to implement "shift-left" security practices in cloud deployments
- Create and maintain cloud security automation using tools like Terraform, CloudFormation, ARM templates
- Implement cloud security orchestration and automated response capabilities
- Ensure compliance with cloud security frameworks including CIS Benchmarks, AWS Well-Architected Framework, Azure Security Benchmark, and GCP Security Command Center recommendations
- Conduct cloud security assessments for regulatory compliance in cloud environments
- Create and maintain risk documentation for cloud security exceptions and accepted risks
- Create and maintain cloud security policies, standards, and procedures aligned with NIST CSF 2.0
- Partner with cloud engineering, DevOps, and development teams to coordinate cloud security remediation
- Provide technical guidance on cloud security best practices and remediation approaches
- Track cloud security remediation progress and ensure issues are addressed within established SLAs
- Participate in cloud security incident response and forensic investigations
- Support incident response for cloud security events and breaches
- Maintain cloud security remediation tracking and reporting dashboards
- Bachelor's degree in Cybersecurity, Cloud Computing, Information Technology, or related field
- 2-3 years of hands-on experience in cloud security, cloud infrastructure, or related cybersecurity roles
- 1 year of experience with cloud vulnerability management and CSPM tools
- Strong experience with Azure
- Experience managing security across major cloud platforms in enterprise environments
- Proficiency with Cloud Security Posture Management (CSPM) platform: Prisma Cloud or similar solutions
- Strong experience with native cloud security services: AWS Security Hub/Config, Azure Security Center/Defender, GCP Security Command Center
- Proficiency with cloud vulnerability scanning and cloud workload protection platforms
- Working knowledge of container security tools and Kubernetes security scanning
- Understanding of cloud compliance frameworks and automated compliance monitoring
- Advanced knowledge of major cloud platforms: AWS, Microsoft Azure, Google Cloud Platform
- Infrastructure as Code expertise: Terraform, CloudFormation, ARM templates
- Container and orchestration experience: Docker, Kubernetes, or similar
- Scripting and automation: Python, PowerShell, Bash, YAML for cloud security automation
- CI/CD integration: Jenkins, GitLab CI, Azure DevOps, GitHub Actions for security pipeline integration
- Cloud networking: VPCs, security groups, network ACLs, cloud firewalls, and micro-segmentation
- Understanding of network security in cloud environments and container technologies
- Experience with DevSecOps practices and security integration in cloud-native development
- Knowledge of secure coding practices for cloud applications and microservices
- Understanding of API security and cloud service authentication mechanisms
- Familiarity with cloud-native application architectures and serverless security considerations
- Knowledge of cloud security frameworks: CIS Cloud Benchmarks, NIST Cloud Computing Framework, Cloud Controls Matrix
- Understanding of shared responsibility models across different cloud providers
- Familiarity with cloud compliance programs: SOC 2, ISO 27001, PCI-DSS, FedRAMP
- Familiarity with data protection regulations in cloud environments: GDPR, CCPA, HIPAA
- Achieve 99%+ asset coverage and scanning coverage across all cloud environments
- Successfully integrate security scanning into >90% of cloud deployment pipelines
- Minimize critical cloud vulnerability exposure time to •Track cloud security remediation progress and ensure SLA compliance
- Respond to cloud security incidents within 30 minutes of detection
- Automate 80%+ of routine security configuration and compliance checks
- Reduce cloud security incidents through proactive vulnerability management
- Successfully integrate security controls into development workflows
- Achieve high adoption rates of cloud security tools and practices across teams