Security Engineer - Vulnerability & Exposure Management

🗓️ Posted 2026-08-10 Petaling Jaya, Selangor, Malaysia Full-time Hybrid ICT

Company shared salary

NA

Market rate

RM12,000–RM18,000/mo (RM144,000–RM216,000/yr)

Based on similar roles (title + domain + location).

About the Company

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

Responsibilities

  • Triage, investigate, and respond to critical vulnerabilities impacting Roche systems and applications
  • Evaluate and prioritize vulnerabilities identified through security tools and external programs, including bug bounty initiatives
  • Research emerging threats and assess exploitability against Roche's attack surface
  • Collaborate with infrastructure, cloud, application, and security teams to drive remediation activities
  • Assess company systems and web applications using automated and manual testing approaches
  • Engineer and enhance vulnerability scanning, detection, automation, and monitoring capabilities
  • Contribute to security monitoring and incident response activities within a global environment
  • Develop scripts, detection logic, templates, and automation workflows to improve operational efficiency
  • Support continuous improvement initiatives across vulnerability and exposure management processes

Requirements

  • Strong cybersecurity foundation combined with analytical thinking, technical curiosity, and a proactive approach to solving complex security challenges
  • Associate Degree in a relevant field or 5+ years of professional experience in information security, with demonstrated experience triaging, analyzing, and escalating security vulnerabilities
  • Strong understanding of web application, network, endpoint, and cloud security concepts, including vulnerability management or attack surface management within complex enterprise environments
  • Hands-on scripting or programming experience using languages such as Python, JavaScript, or Node.js, with familiarity in security tooling, detection logic, automation, or custom scripting
  • Experience validating vulnerabilities, assessing exploitability, and supporting security monitoring or incident response activities
  • Ability to communicate technical risks effectively to both technical and non-technical stakeholders, while balancing operational priorities and research initiatives
  • Passion for cybersecurity, continuous learning, and emerging security trends, with exposure to open-source security projects or modern AI-assisted engineering workflows considered advantageous
  • Professional fluency in English, with industry certifications related to offensive or application security