DevOps Security Engineer
HFM Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia
About HFM : HFM is an internationally acclaimed multi-asset broker, delivering cutting‑edge trading tools, platforms, and conditions to traders worldwide. We are committed to innovation, transparency, and excellence in the financial markets.
Your role at HFM :
- Collaborate with development, DevOps, and IT operations teams to embed security principles and ensure compliance with industry standards across the software development lifecycle (SDLC).
- Establish and manage security controls, including firewalls, access controls, encryption, and automated security testing frameworks.
- Conduct comprehensive security assessments, participate in penetration testing efforts, and ensure rapid remediation of vulnerabilities.
- Oversee the monitoring of security systems and lead the response to security incidents, ensuring timely detection and resolution of issues.
- Drive incident response processes, including root cause analysis and applying corrective actions across teams.
- Stay ahead of security threats by continuously researching the latest trends, vulnerabilities, and technologies, and integrating them into security practices.
- Mentor and provide guidance to junior engineers, ensuring they follow best practices and keep security at the forefront of their work.
- Act as a subject matter expert (SME) on security across teams, ensuring alignment with organizational security goals and standards.
Requirements
4–7 years of experience in DevOps security, cybersecurity, or related fields, with a strong focus on cloud or infrastructure security.Deep knowledge of security technologies (firewalls, access controls, SSL / TLS, SSH, IPSec) and encryption protocols.Strong understanding of security standards and frameworks, including OWASP Top 10, PCI DSS, NIST, and ISO 27001.Extensive experience with vulnerability management, penetration testing, and remediation techniques.Advanced understanding of DevOps practices, including CI / CD pipelines, containerization, and automation with security tooling.Solid grasp of secure coding practices and experience guiding development teams on applying them.Proficiency in security tools, such as IDS / IPS, vulnerability scanners, and SIEM platforms.Experience with cloud security, especially in AWS, Azure, or GCP environments.Strong communication skills, with the ability to influence stakeholders and integrate security best practices into workflows.All Resumes must be submitted in English
Applicants must be eligible or have legal authorization to work in the country where the position is based.
Benefits
Hybrid Work Model (2 days working from home).22 days of Annual Leave.Comprehensive Health Insurance (from day one!).Friday afternoons off in Summer (December & January).Birthday Leave.Referral Bonus.Kick off an exceptional career with HFM and follow the path to success!
Sounds like you? Come and write the next chapter with us!
All applications will be treated as confidential.
#J-18808-Ljbffr