Lead Engineer – Cloud & Endpoint
Dyson is hiring a Lead Engineer – Cloud & Endpoint in Kuala Lumpur, Malaysia. Level rates it ; you can apply on Level.
AI in this role
Lead Cloud and Endpoint Security Engineer responsible for managing Microsoft Defender security stacks and vulnerability management.
Role Purpose
As the Cloud & Endpoint Security Engineer, you are accountable for engineering integrated cloud-connected and endpoint security capabilities to maintain a high security posture across all workspace platforms.
Operating as a cross-domain engineering lead, you will bridge the gap between cloud security services and endpoint telemetry. By managing Defender Vulnerability Management, maintaining Defender for Cloud Apps integrations, and implementing automated security posture controls, you will provide visibility and technical remediation across the workplace ecosystem.
In this role, you will lead and manage the following domains:
Defender for Endpoint & Cloud Integration: Owning the architecture and operational health of MDE cloud capabilities.
Vulnerability & Exposure Management: Implementing and optimizing Defender Vulnerability Management to continuously identify exposure.
Cloud App Security (CASB): Engineering and governing Defender for Cloud Apps to secure SaaS usage and shadow IT.
Security Posture Management: Building posture monitoring tools, compliance reporting frameworks, and automated posture remediation.
Telemetry & Engineering Projects: Leading workplace security engineering projects and providing telemetry integration into central monitoring solutions.
Key Skills & Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related technical discipline (or equivalent practical experience).
- A minimum of 5–7 years' cybersecurity experience with focus on cloud-delivered endpoint protection, CASB, and exposure management platforms.
- Proven hands-on experience deploying and running unified Microsoft Defender security stacks across cloud and hybrid client estates.
- Relevant industry certifications such as Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400), SC-200, CISSP, or CCSP are highly desirable.
Security Expertise & Architecture
Deep technical expertise in cloud-delivered security solutions, exposure management, CASB architecture, API integrations, and threat vector analysis across hybrid workspaces.
Tooling & Technical Proficiency
Expertise with Microsoft Defender for Endpoint (MDE), Defender Vulnerability Management, Defender for Cloud Apps (MDA), Microsoft Sentinel integration, and Security Posture Management tools.
Risk Management & Prioritisation
Ability to leverage vulnerability scoring models (CVSS, EPSS) and asset business context to prioritize exposure remediation across cloud and endpoint boundaries.
Governance, Process & Control Design
Experience designing cloud access policies, sanctioning SaaS applications, and establishing vulnerability management exception tracking mechanisms.
Service Delivery & Operational Management
Track record of managing enterprise-scale security tooling platforms, maintaining seamless API connections, and delivering against operational SLAs.
Data Analysis, Reporting & Insight
Strong data-analysis skills using KQL and API data feeds to create executive dashboards demonstrating security posture improvements and risk trends.
Stakeholder Management & Influence
Effective communicator capable of collaborating with cloud operations, networking, and IT operations teams to implement security posture changes.
Threat Intelligence Integration
Ability to utilize threat intelligence indicators to identify malicious SaaS application usage, unusual tenant activities, and high-risk endpoint vulnerabilities.
Leadership & Execution
Proven execution capability to lead complex engineering projects, translate security outcomes into practical steps, and guide operational teams.
Continuous Improvement & Automation
A drive to automate security checks, vulnerability ticketing workflows (e.g., via ITSM integrations), and cloud app policy adjustments.
Key Accountabilities & Success Measures
Vulnerability & Posture Management Engineering
Accountability: Deploy, operate, and optimize Defender Vulnerability Management to identify, prioritize, and drive technical exposure reduction.
Success Measures: Maintain >95% accurate scan and telemetry coverage across all active cloud-managed devices; Measurable structural reduction in organizational Exposure Score within Defender Vulnerability Management.
Cloud App Security & Shadow IT Governance
Accountability: Architect and manage Defender for Cloud Apps integrations to enforce SaaS governance, detect anomalous cloud behavior, and control unsanctioned applications.
Success Measures: 100% of cloud app traffic monitored and evaluated against security risk policies; Automated block controls enforced for high-risk, unsanctioned cloud platforms.
Security Telemetry & Platform Automation
Accountability: Drive end-to-end security telemetry pipelines between MDE, Cloud Apps, and centralized monitoring tools (e.g., Sentinel/ServiceNow).
Success Measures: 100% platform uptime and event ingestion reliability across security tool integrations; Significant reduction in manual tracking through automated posture and vulnerability ticketing workflows.
Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.
How we rate this
Lead Engineer – Cloud & Endpoint at Dyson rates 10 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- What's a project where you used Microsoft Defender hands-on?
- Walk me through how you've used Microsoft Sentinel in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Microsoft Defender and Microsoft Sentinel. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new software engineering jobs by email
One email a week with the new software engineering jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step