Vulnerability & Security Posture Management Engineer
BAT Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia
BAT Digital Business Solution has an exciting opportunity for a Vulnerability & Security Posture Management Engineer in Subang Jaya.
Key Responsibilities
- Security Posture Management : Develop and implement continuous monitoring and enforcement of security configurations and policies across various platforms, leveraging tools like Microsoft E5 capabilities (Defender External Attack Surface Management, Defender for Identity, Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps).
- Drive the reduction of configuration drift and ensure compliance with BAT security and technical standards, and external regulations.
- Vulnerability Management : Lead the execution and optimization of vulnerability scanning using Qualys and other tools.
- Analyze, prioritize, and report on vulnerabilities based on risk, exploitability, and business impact.
- Proactively monitor threat intelligence feeds and advisories (e.g., CVE, CISA, NCSC, vendor bulletins) to stay current on emerging vulnerabilities and exploits.
- Collaborate with IT and BAT partners to ensure timely and effective remediation efforts are implemented and tracked.
- Attack Surface Management : Continuously discover and inventory all internal and external assets, including cloud resources, to maintain a comprehensive view of the attack surface.
- Monitor for changes in the attack surface and proactively assess new exposures.
- Reporting & Strategy : Generate clear, actionable reports and dashboards for technical teams and leadership detailing vulnerability status, trends, and risk reduction over time; contribute to the strategic planning and selection of security tools and technologies.
- Other responsibilities as required to support security posture and risk reduction initiatives.
What are we looking for?
Minimum 3+ years of experience in information security, with hands-on focus on vulnerability management, threat analysis, or security posture management.Deep hands-on experience with commercial and open-source security tools, including Qualys (or similar platforms like Tenable / Rapid7) and Microsoft E5 Security Stack (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps) and Microsoft Exposure Management; cloud experience (Azure, AWS).Understanding of threat intelligence sources (CVE, CISA, vendor advisories) and how to apply them to remediation efforts.Strong ability to translate raw technical data into business-relevant risk and remediation priorities.Excellent communication, collaboration, and project management skills to drive cross-functional security initiatives.What we offer
Market-leading annual performance bonus (subject to eligibility).Range of benefits varies by country, including diverse health plans, work-life balance initiatives, transportation support, and a flexible holiday plan with additional incentives.Opportunities for internal advancement and career progression within BAT.Access to online learning platforms and personalized growth programs to nurture leadership skills.Commitment to continuous improvement within a transformative environment.Why join BAT?
BAT is recognized as a Global Top Employer and values collaboration, inclusion, and partnership. We welcome applicants from diverse backgrounds and support reasonable accommodations in the recruitment process where needed.
#J-18808-Ljbffr