Security Engineer
HFM Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia
About HFM
HFM is an internationally acclaimed multi‑asset broker, delivering cutting‑edge trading tools, platforms, and conditions to traders worldwide. We are committed to innovation, transparency, and excellence in the financial markets.
Role Overview
We are searching for an enthusiastic and committed Security Engineer to join our dynamic team at HFM. As a Security Engineer, you will play a key role in defending our global financial infrastructure by designing, implementing, and managing advanced security controls across cloud and on‑premise environments. Working within a cross‑functional security team, you’ll actively monitor threats, respond to incidents, and continuously improve our detection and prevention capabilities. This is a hands‑on role that blends technical depth, strategic impact, and regulatory awareness in a fast‑paced, regulated environment.
- Security Monitoring and Maintenance : Continuously monitor and maintain security solutions to detect and respond to unauthorized activities across the corporate environment.
- Security Tool Evaluation and Implementation : Assess and deploy new security tools to address specific use cases, enhance visibility, and improve existing security processes.
- Incident Response Enhancement : Participate in, analyze, and refine incident response processes to ensure swift and effective handling of security incidents.
- Threat Intelligence and Research : Stay up‑to‑date with current and emerging technology issues, including security trends, vulnerabilities, and threats, and conduct proactive research to identify security weaknesses and recommend appropriate strategies.
- Information Security Strategy Development : Contribute to the planning, development, and implementation of the company’s information security strategy, aligning with established security best practices.
- Security Issue Resolution : Assist in troubleshooting and resolving various security issues, ensuring minimal impact on business operations.
- Security Projects : Contribute to security initiatives such as network segmentation, zero‑trust implementation, endpoint hardening, and vulnerability management.
- Collaboration : Work with DevOps, Cloud, and IT teams to ensure secure architecture and operations. Support compliance and audit requirements (e.g., ISO 27001, DORA, GDPR, CySEC, etc.).
Requirements
Bachelor’s degree in Computer Science, Information Security, or a related field.4+ years of hands‑on experience in security engineering or a similar cybersecurity role.Passion for Cybersecurity : Demonstrated enthusiasm for staying updated on the latest security threats and solutions, with a proactive approach to continuous learning.Scripting : Familiarity with scripting (Python, Bash, PowerShell) for automation.Knowledge of Security Frameworks : Familiarity with best‑practice configurations and security frameworks such as CIS Controls.System Administration Skills : Proficiency in Active Directory and general Linux administration.Penetration Testing Tools : Experience with phishing simulations, password audits, and basic penetration testing.Security Solution Implementation : Experience with a variety of security products, including firewalls, URL filtering, information security, and virus protection. Adept with implementing and managing security solutions such as Endpoint Detection and Response (EDR), Antivirus / HIPS, Security Information and Event Management (SIEM), Data Loss Prevention (DLP), and mail filtering systems.Custom Rule Development : Ability to develop custom rules to prevent unauthorized behaviors.Malware Analysis : Experience in malware investigation, troubleshooting, and sample analysis.Understanding of Attack Frameworks : Knowledge of the MITRE ATT&CK framework and common attack vectors, including Living off the Land Binaries (LoLBins), ransomware, brute force attacks, and password spraying events.Incident Response Experience : Hands‑on experience with incident response processes and related tools.Hands‑on certifications : OSCP, OSCP+, SANS GIAC (GCIH, GCIA, GCFA), CEH, Security+.Cloud security knowledge (AWS, Azure, GCP) and certifications (e.g., AWS Security Specialty, CCSP).Familiarity with SOAR platforms and automation of response playbooks.Resumes submitted must be in English.
Benefits
Hybrid Work Model (2 days working from home).22 days of Annual Leave.Comprehensive Health Insurance (from day one!).Friday afternoons off in Summer (December & January).Birthday Leave.Referral Bonus.Kick off an exceptional career with HFM and follow the path to success! Sounds like you? Come and write the next chapter with us!
All applications will be treated as confidential.
Seniority level
Mid‑Senior level
Employment type
Full‑time
Job function
Information Technology
Industries
IT Services and IT Consulting
#J-18808-Ljbffr