Malaysia Airports Holdings Berhad manages a sprawling attack surface that most security teams never have to consider: 40 airports, spanning five international hubs, 17 domestic terminals, 17 short take-off and landing ports across Malaysia, and one international airport in Turkey. The threat model here is physical-digital convergence at scale - operational technology controlling baggage systems, air traffic support, and building management layered on top of IT networks that handle passenger data, payment processing, and airline integrations. A breach doesn't just mean data loss; it means grounded flights and disrupted national infrastructure.
Founded in 1992, the company's core business is the management, operation, maintenance, and development of airports. That means the security team works across aviation-specific operational domains - not just corporate IT but the industrial control systems and OT environments that keep terminals running. The geographic spread across Malaysia and Turkey adds jurisdictional complexity: different regulatory regimes, different national CERT relationships, different baseline threat actors.
This is critical infrastructure work where uptime is non-negotiable and the consequences of failure are measured in passenger safety, not just SLA penalties. If you're looking for a role where the threat landscape includes nation-state actors, ransomware targeting OT, and the reality that your network perimeter includes runway lighting systems and jet bridges, this is the kind of environment where that work happens.





