Talent.com
Senior Product Security Engineer

Senior Product Security Engineer

Sitecore Malaysia Sdn. Bhd.Kuala Lumpur, Kuala Lumpur, Malaysia
10 hours ago
Job description

About Us

At Sitecore, our mission is to simplify how brands reach, engage, and serve people by delivering intelligent, personalized digital experiences that connect the world. We empower the world’s most iconic brands to build lifelong relationships with their customers—seamlessly, smartly, and at scale.

As the leading provider of agentic digital experience software, Sitecore brings together content, commerce, and data into one composable platform that enables brands to deliver millions of meaningful, adaptive experiences every day. Trusted by global leaders such as American Express, Porsche, Starbucks, and L’Oréal, Sitecore helps brands transform engagement through experiences that are not only personalized but predictive and dynamic.

Our foundation is our people—a diverse, passionate, and collaborative global team spanning over 25 countries. We believe that every experience matters, and that belief starts with how we work together. We are actively cultivating AI skills across our teams to unlock new levels of creativity, efficiency, and insight. From engineering to customer experience, AI capabilities are becoming integral to how we design, build, and deliver the next generation of digital experiences.

About the Role

As a Senior Product Security Engineer with a focus on Penetration Testing and AI Security, you will play a critical role in identifying, exploiting, and mitigating vulnerabilities across Sitecore’s platforms, infrastructure, and AI-driven features. You will work closely with product engineering teams, cloud operations, and compliance stakeholders to ensure our systems are resilient against evolving threats, including those introduced by AI technologies.

What You’ll Do

Penetration Testing & Vulnerability Assessment

  • Perform advanced penetration tests on Sitecore products, services, and cloud environments.
  • Simulate real‑world attack scenarios to identify weaknesses in applications, APIs, and infrastructure.
  • Develop and maintain automated testing frameworks for continuous security validation.

AI Security Testing

  • Assess AI / ML models and pipelines for adversarial vulnerabilities, data poisoning, and model inversion risks.
  • Evaluate prompt injection, jailbreak attempts, and other LLM‑specific attack vectors.
  • Collaborate with AI engineering teams to implement robust security controls for AI‑driven features.
  • Security Research & Threat Modelling

  • Stay ahead of emerging threats, attack vectors, exploit techniques, including AI‑related risks.
  • Conduct threat modelling for new features and architectures.
  • Collaboration & Remediation

  • Work with engineering teams to prioritize and remediate vulnerabilities.
  • Provide actionable guidance and best practices for secure coding and architecture.
  • Reporting & Compliance

  • Document findings with detailed technical reports and executive summaries.
  • Support compliance initiatives (ISO 27001, SOC 2, GDPR) through security testing and evidence collection.
  • WAF Administration

  • Manage and optimize WAF configurations for security and performance.
  • Implement and maintain WAF (Web Application Firewall) rules, DDoS protection, and bot mitigation.
  • Collaborate with DevOps and infrastructure teams to ensure WAF integration aligns with security architecture.
  • What You Need to Succeed

  • 8+ years in security engineering with a strong focus on penetration testing.
  • Hands‑on experience with AI security testing or adversarial ML techniques is a strong plus.
  • Expertise in tools such as Burp Suite, Metasploit, Nmap, and custom exploit development.
  • Strong knowledge of OWASP Top 10, SANS CWE, and secure coding principles.
  • Familiarity with AI / ML frameworks (TensorFlow, PyTorch) and LLM security considerations.
  • Cloud security (Azure preferred) and containerised environments (Docker / Kubernetes).
  • Comfortable working in a fast‑paced, dynamic environment with shifting priorities.
  • Additional Skills That Could Set You Apart

  • Familiarity with headless CMS architecture, front‑end frameworks, and web technologies.
  • OSCP, CRTO, GPEN or similar advanced penetration testing certifications.
  • AI security certifications or demonstrated research in adversarial ML.
  • CISSP or equivalent for broader security knowledge.
  • Why Sitecore?

    At Sitecore, we offer a vibrant work culture, a collaborative environment, and the opportunity to work on products that shape digital experiences globally. We’re dedicated to fostering growth, innovation, and a commitment to our employees’ professional and personal development. Be part of a visionary, innovation‑driven team shaping the next era of AI‑powered content management in a leading composable DXP.

    Equal Employment Opportunity

    Sitecore is proud to be an equal opportunity workplace. We are committed to equal employment opportunity without unlawful regard to race, color, ancestry, religion, gender, national origin, sexual orientation, age, citizenship, marital status, disability, veteran status or any other local legally protected characteristic.

    #J-18808-Ljbffr

    Create a job alert for this search

    Product Engineer • Kuala Lumpur, Kuala Lumpur, Malaysia

    Related jobs
    Sr Cyber Security Engineer

    Sr Cyber Security Engineer

    Flintex Consulting Pte LtdKuala Lumpur, 14, my
    Quick Apply
    Security Architecture & Engineering.Design and implement enterprise-wide security infrastructure and architecture.Evaluate and recommend security tools and technologies.Ensure security is embed...Show moreLast updated: 30+ days ago
    • Promoted
    Onsite Security Operations Engineer - EDR / XDR & PAM

    Onsite Security Operations Engineer - EDR / XDR & PAM

    Dexian Asia PacificSelangorMalaysia, Selangor, Malaysia
    A leading IT consulting firm in Malaysia seeks a CyberSecurity Resident Engineer to support daily security operations onsite. The role involves managing security tools and monitoring security alerts...Show moreLast updated: 1 day ago
    • Promoted
    Senior Product Security Engineer - AI & Pen Testing

    Senior Product Security Engineer - AI & Pen Testing

    SitecoreKuala Lumpur, Kuala Lumpur, Malaysia
    A leading digital experience platform provider in Kuala Lumpur is seeking a Senior Product Security Engineer.You will conduct advanced penetration testing and assess AI security, collaborating with...Show moreLast updated: 1 day ago
    • Promoted
    (Senior) Security Engineer, Security Engineering & Threat Intelligence

    (Senior) Security Engineer, Security Engineering & Threat Intelligence

    Ring IncKuala Lumpur, Kuala Lumpur, Malaysia
    We are looking for an intermediate level security engineer to join our Global Cybersecurity Services Team.As part of our modern cybersecurity operating model, the role will be engaged in enhancing ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    UndisclosedKuala Lumpur, Kuala Lumpur, Malaysia
    Senior Specialist, Security Engineer.Fintech / Digital Payments / Technology.Lead and manage the Security Operations team (2 members) under the Head of IT Security. Oversee endpoint security across ...Show moreLast updated: 2 days ago
    • Promoted
    Senior Product Security Engineer Kuala Lumpur, Malaysia Senior Product Security Engineer

    Senior Product Security Engineer Kuala Lumpur, Malaysia Senior Product Security Engineer

    SitecoreKuala Lumpur, Kuala Lumpur, Malaysia
    Senior Product Security Engineer – Penetration Testing and AI Security.Engineering & Technology, Kuala Lumpur, Malaysia.At Sitecore, our mission is to simplify how brands reach, engage, and serve p...Show moreLast updated: 2 days ago
    • Promoted
    L2 Security Engineer (SOC)

    L2 Security Engineer (SOC)

    LogicalisKuala Lumpur, Kuala Lumpur, Malaysia
    Location : Logicalis, Federal Territory of Kuala Lumpur, Malaysia.Be among the first 25 applicants.Actively research and stay updated with latest and new cyberattacks, TTPs, threat attackers, vulner...Show moreLast updated: 30+ days ago
    • Promoted
    System Security Engineer

    System Security Engineer

    Public Mutual BerhadKuala Lumpur, Kuala Lumpur, Malaysia
    Empowering the Workforce | Guiding Others to Achieve Their Career Goals.Monitor security alerts and events using Security Information and Event Management (SIEM) tools. Prioritize, analyze, and tria...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    PayNet (Payments Network Malaysia)Kuala Lumpur, Kuala Lumpur, Malaysia
    Lead security solution initiatives, from architecture, design, deployment to operationalizing and other technical security assessment and implementation (at various layers).Ensure sound security pr...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    Senior Product Security Engineer : Pen Testing & AI Security

    Senior Product Security Engineer : Pen Testing & AI Security

    SitecoreKuala Lumpur, Kuala Lumpur, Malaysia
    A leading digital experience platform in Kuala Lumpur is seeking a Senior Product Security Engineer focused on Penetration Testing and AI Security. This role involves identifying and mitigating secu...Show moreLast updated: 10 hours ago
    • Promoted
    Lead Security Operations Engineer - Endpoint & Threat Hunting

    Lead Security Operations Engineer - Endpoint & Threat Hunting

    UndisclosedKuala Lumpur, Kuala Lumpur, Malaysia
    A leading technology firm in Kuala Lumpur is seeking a Senior Specialist, Security Engineer to lead their Security Operations team. The role requires 5–7 years of experience in cybersecurity operati...Show moreLast updated: 2 days ago
    • Promoted
    • New!
    Senior Product Security Engineer

    Senior Product Security Engineer

    SitecoreKuala Lumpur, Kuala Lumpur, Malaysia
    Sitecore Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia.Senior Product Security Engineer – Penetration Testing and AI Security. Engineering & Technology, Kuala Lumpur, Malaysia.At Sitecor...Show moreLast updated: 10 hours ago
    • Promoted
    Senior Security Automation Engineer – Cloud & DevSecOps Leader

    Senior Security Automation Engineer – Cloud & DevSecOps Leader

    BATKuala Lumpur, Kuala Lumpur, Malaysia
    A global multi-category business is seeking a Senior Security Automation Engineer in Kuala Lumpur, Malaysia.This position involves bridging SecOps, policy engineering, and automation to enhance sec...Show moreLast updated: 3 days ago
    • Promoted
    Expression of Interest : Senior Security Automation Engineer

    Expression of Interest : Senior Security Automation Engineer

    BATKuala Lumpur, Kuala Lumpur, Malaysia
    BAT is evolving at pace into a global multi-category business.Our purpose is to create A Better Tomorrow™ by Building a Smokeless World. To achieve our ambition, we are looking for colleagues who ar...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer : Build & Audit Defenses

    Security Engineer : Build & Audit Defenses

    UNAVAILABLEKuala Lumpur, Kuala Lumpur, Malaysia
    A global network and digital integrator is seeking a security expert in Kuala Lumpur.The role involves implementing security measures, responding to alerts, and collaborating on security policies.R...Show moreLast updated: 2 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Ensign InfoSecurityKuala Lumpur, Kuala Lumpur, Malaysia
    Manage the ticketing system and ensure all tickets are up to date with the latest information / updates.Handles customers’ calls / escalation and performs 1st & 2nd level troubleshooting and resolution...Show moreLast updated: 4 days ago
    • Promoted
    • New!
    Senior Product Security Engineer : AI Security & Pen Testing

    Senior Product Security Engineer : AI Security & Pen Testing

    Sitecore Malaysia Sdn. Bhd.Kuala Lumpur, Kuala Lumpur, Malaysia
    A leading digital experience software firm in Kuala Lumpur is seeking a Senior Product Security Engineer to focus on penetration testing and AI security. The ideal candidate will have over 8 years o...Show moreLast updated: 10 hours ago
    Application Security Engineer

    Application Security Engineer

    AvengaKuala Lumpur, Wilayah Persekutuan Kuala Lumpur, .MY
    Quick Apply
    At Avenga, we believe that human creativity empowers technology that matters.Operating globally, our 6000+ specialists provide a full spectrum of services, including business and tech advisory, ent...Show moreLast updated: 30+ days ago