Descrição
JOB SUMMARY
KEY RESPONSIBILITY AREAS
CYBERSECURITY AND RISK MANAGEMENT
- Network Security: In-depth knowledge of network architecture, protocols (TCP/IP, DNS, HTTP/S), firewalls, VPNs, intrusion detection/prevention systems (IDS/IPS), and network segmentation is essential to identify and mitigate network-based risks.
- Operating Systems: Proficiency in various operating systems, including Windows, Linux, and macOS, to understand their vulnerabilities, perform host hardening, and manage access controls.
- Cloud Security: Expertise in securing cloud platforms like AWS, Azure, and Google Cloud, including identity and access management (IAM), data encryption, and secure configurations for hybrid environments.
- Vulnerability and Penetration Testing: Hands-on experience with vulnerability assessments, penetration testing, and security auditing to identify weaknesses before attackers exploit them. This includes an understanding of ethical hacking to think like an adversary.
- Incident Response and Digital Forensics: Knowledge of incident handling processes, digital forensics techniques (evidence collection, malware analysis, log analysis), and disaster recovery planning to manage and recover from security breaches effectively.
- Security Tools and Platforms: Familiarity with managing and utilizing various security tools, such as Security Information and Event Management (SIEM) systems, endpoint detection and response (EDR) tools, and data encryption protocols.
Risk and Assurance Knowledge.
- Risk Assessment and Management: Ability to conduct comprehensive risk assessments, develop threat models, analyze probability and impact, and design appropriate mitigation strategies.
- Governance, Risk, and Compliance (GRC): Extensive knowledge of common regulatory requirements and industry security frameworks, such as:
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001/2 series
- COBIT
- GDPR, CCPA, HIPAA, PCI DSS data privacy regulations
- Security Architecture and Engineering: The capacity to design and implement enterprise-wide cyber risk governance frameworks and secure infrastructure solutions.
- Threat Intelligence: Staying current with the latest cyber threats, attack vectors, and technological advancements to proactively adjust defenses and develop forward-thinking strategies.
POLICY AND PLANNING
- Assist and support the Director in implementing and ensure compliance with all policies relating to Information Technology and Security.
VENDOR RELATIONSHIP MANAGEMENT
- Specify items required and obtain quotations as necessary. Maintain good relationships with vendors.
JOB REQUIREMENTS
- A Bachelor’s degree in computer science, IT, or a related field from a recognised institution, with minimum of 3 - 5 years of relevant work experience including minimum of one (1) year of supervisory experience.
- At least three (3) to five (5) years of relevant working experience in Cybersecurity operations, Governance, Risk, and Compliance (GRC), or Information Security management in a small to medium size organisation.
- Strong knowledge of IT governance principles, regulatory requirements, risk management, and cybersecurity best practices. Experience with frameworks such as ISO 27001, NIST, and COBIT is a plus.
- Proven experience in conducting IT risk assessments (risk identification, analysis, evaluation, and treatment) and managing risk registers.
- Experience in managing cybersecurity incidents (Incident Response) and conducting root cause analysis.
- Hands-on experience with security technologies including SIEM, Firewalls (Next-Gen), Endpoint Detection & Response (EDR), DLP, and Vulnerability Scanners.
- Strong organizational and documentation skills, ensuring accuracy and consistency in IT policies, reports, and service management records.
- Ability to work in a team environment, mentor junior IT staff, and foster a culture of innovation and compliance within the IT department.
Job Types: Full-time, Contract
Pay: RM6,000.00 - RM8,000.00 per month
Work Location: In person