Greetings from Velesto Energy Berhad!
We are pleased to offer an opportunity for a seasoned professional to join our Digital, Technology and Information (DTI) Team.
ABOUT THE ROLE
The Consultant – Cybersecurity & Infra is responsible for managing and executing daily business-as-usual activities to ensure the enterprise technology environment remains highly available, secure, stable, and performing effectively. This role drives end-to-end operational excellence across infrastructure, managed services, cybersecurity implementation, and end-user services, ensuring all platforms and services are delivered within defined SLA and KPI targets. The Consultant serves as a hands-on operational lead responsible as a hands-on operational lead responsible for ensuring cybersecurity posture and technology services are proactively managed, incidents are resolved in a timely manner, and security controls are effectively implemented and enforced in line with business, governance, and regulatory requirements. The Consultant may also be assigned to support multi-disciplinary tasks across other domains within DTI, based on business and operational requirements.
KEY ACCOUNTABILITIES
Digital Infrastructure & Service Operations Ownership
- Accountable for day-to-day technology service stability, availability, security, and performance.
SLA / KPI Delivery
- Ensure service performance metrics, including uptime, response, resolution, and security remediation targets, are consistently achieved.
Cybersecurity Implementation
- Support operational deployment, monitoring, and enforcement of security controls across enterprise infrastructure and end-user environments.
Incident & Recovery Effectiveness
- Minimize service disruption through timely incident response, recovery coordination, root cause analysis, and corrective actions.
Vendor & Managed Services Performance
- Ensure vendors and managed service providers deliver agreed outcomes, service quality, and proactive support.
Continuous Service Improvement
- Reduce recurring incidents, improve operational resilience, enhance user experience, and strengthen cybersecurity maturity.
KEY RESPONSIBILITIES
Digital Infrastructure & Service Operations
- Own day-to-day technology service operations across infrastructure, including servers, network, storage, cloud, virtualization, and related platforms.
- Ensure high system availability, performance monitoring, capacity planning, and operational resilience.
- Enforce 24x7 monitoring, proactive alerting, and timely incident response to prevent or minimize service disruption.
- Drive service stability through standardization, automation, preventive maintenance, and continuous improvement.
- Oversee data centre, cloud, and platform operations to ensure secure, continuous, and reliable service delivery.
Cybersecurity Implementation & Operational Enforcement
- Implement and operate security controls, including firewall, endpoint protection, IDS/IPS, vulnerability management, identity controls, and secure configuration baselines.
- Perform continuous security monitoring, alert triaging, incident containment, and escalation in coordination with internal teams and service providers.
- Execute vulnerability remediation, patch management, system hardening, and security configuration reviews on an ongoing basis.
- Lead or support security incident response, root cause analysis, evidence gathering, corrective actions, and post-incident improvement.
- Ensure compliance with cybersecurity policies, regulatory requirements, audit controls, and applicable standards such as ISO and PDPA.
Incident, Problem & Service Operations Management
- Manage end-to-end incident lifecycle, including logging, triage, escalation, resolution, closure, and service restoration in line with SLA targets.
- Drive major incident management and real-time response coordination for critical technology or cybersecurity disruptions.
- Improve mean time to resolve, first-contact resolution, service responsiveness, and escalation effectiveness.
- Conduct root cause analysis and implement preventive or corrective actions to reduce recurrence.
- Strengthen problem management practices through trend analysis, recurring issue elimination, and lessons learned.
End-User Computing & BAU Service Delivery
- Manage end-user technology services, including workplace devices, endpoint support, access services, and lifecycle management.
- Ensure timely onboarding, offboarding, account provisioning, access reviews, and access control management.
- Maintain service responsiveness and user productivity through efficient support delivery and effective issue resolution.
- Ensure asset tracking, licensing compliance, device health, endpoint protection, and performance optimization.
Vendor & Managed Services (Operations Control)
- Provide operational oversight of vendors delivering infrastructure, cybersecurity, end-user, and managed services.
- Monitor SLA/KPI performance, service quality, operational responsiveness, security performance, and compliance obligations.
- Drive issue resolution, escalation management, service reviews, and performance improvement actions.
- Ensure vendors deliver proactive service operations and continuous improvement, not only reactive support.
Backup, Disaster Recovery & Operational Resilience
- Execute and validate backup, recovery, and data protection processes for critical systems and information assets.
- Perform or coordinate disaster recovery testing, restoration validation, failover exercises, and recovery readiness reviews.
- Ensure critical services can be restored within agreed recovery objectives with minimal business impact.
- Support operational resilience planning through documented procedures, recovery evidence, and continuous improvement actions.
Change, Patch & Release (Operational Execution)
- Execute controlled infrastructure, platform, and security changes to minimize operational and cybersecurity risks.
- Ensure regular patching, upgrades, vulnerability remediation, testing, and rollback planning.
- Maintain system stability and service continuity while implementing required updates and releases.
- Coordinate change communication, approvals, implementation evidence, and post-change validation.
Service Governance, Reporting & Documentation
- Maintain service dashboards covering uptime, incidents, SLA performance, security remediation, risks, and improvement actions.
- Ensure complete and current documentation of SOPs, runbooks, technical configurations, access records, and operational evidence.
- Support audit, compliance reporting, governance requirements, risk reviews, and management updates.
- Provide management visibility on technology service health, cybersecurity posture, operational risks, and mitigation actions.
KEY SERVICE PERFORMANCE METRICS
- System Availability / Uptime (%)
- SLA Compliance (%)
- Mean Time to Resolve (MTTR)
- First Contact Resolution (FCR)
- Incident Volume, Severity, and Recurrence Rate
- Patch Compliance Rat
- Vulnerability Closure Rate
- Security Alert Response and Containment Timeliness
- Backup Success and Recovery Validation Rate
- User Satisfaction (CSAT)
EDUCATION
- Bachelor's Degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related discipline.
EXPERIENCE
- 5–8 years of hands-on experience in technology service operations, infrastructure support, cybersecurity operations, or managed services environments.
- Proven experience managing or supporting enterprise infrastructure, cloud platforms, networks, endpoints, and security technologies.
- Hands-on exposure to cybersecurity implementation, vulnerability management, incident response, access controls, and security monitoring.
- Familiarity with ITIL practices, SLA/KPI management, change management, problem management, and service reporting.
- ITIL certification is preferred.
- Security or infrastructure certifications such as Security+, CISSP, CISM, Microsoft, Cisco, or cloud certifications are advantageous.
CONTRACT PERIOD
Six (6)-month consultancy contract, renewable subject to business and project requirements.