Search by job, company or skills

Head of Cyber Defence

Air Asia


    Job Description

    More Info

    Recruiter Info

10-12 Years
23 days ago
63 Viewed
0 Applied

Job Description

Job Description


  • Department: Information Security

  • Entity: Capital A Group, KL, Malaysia

  • Status: Full-time


Key leader in the Information security team leading the Cyber Defence function for the group of companies, this role is accountable for the information and cyber defence in the AirAsia Group and Capital A Group as an independent Assurance Line-of-Defence 2 (LOD2) function.

The Head of Cyber Defence is accountable for leading four areas. 1. Security Operations team, 2. Cyber intelligence and threat hunting team, 3. Vulnerability management 4. Connectivity, Endpoint Security and Identity Management.

Across all the areas they will be responsible for curating actionable insights for identified cyber security threats and incidents and promptly managing the responses to items mentioned above or breaches. They should proactively manage vulnerabilities by leveraging telemetry from data sources, threat intelligence, vulnerability assessments and penetration testing. The role is responsible for continuously enhancing the cyber resilience of the Capital A group and in line with the cyber strategy, responsible for minimising any potential breach impact on the group.

The Head of Cyber Defence works closely in coordination with Business CISOs, the Head of Cyber Architecture & Strategy, the Head of Cyber Risk, Policy & Assurance, Group Risk, Legal, Procurement, and engineering/technical/IT teams across the portfolio of companies.


  • Continuously works to enhance the Group's Cyber Resilience as an authority to protect the group in line with the Cyber Security Governance with a clear mandate.

  • Custodian of the incident response process and continuously enhancing the process according to the ever-changing threat landscape.

  • Perform near real-time and continuous 24.7 monitoring, lead investigations and perform first analysis and triage via a SOC.

  • Ensures continuous monitoring of the Cyber data to detect any anomalies.

  • Leads/Oversees end-to-end incident management cycle, including leading recovery from the incident as rapidly as possible. Conduct the first level of analysis on any highlighted incidents from investigation platforms, referrals and discovery to determine the breach criticality in line with the incident

  • Implementation and execution of adequate response to any incident and cyber-attacks Process.

  • Continuously on alert against Cyber threats and monitoring cyber intelligence feed. Actively action any mitigation towards the cyber threats.

  • Provides actionable insights to Group executive leadership as needed on cyber security threats, incidents, and vulnerabilities to facilitate business decisions across the group for action.

  • Perform forensic investigation of all Cyber incidents and breaches. Report learnings from the forensic report to enhance the Cyber Defence capabilities.

  • Reporting Cyber breaches forensic investigation with H and VH ratings to the Group company Leadership and the VH incidents to the Group company Boards.

  • Leads the development of threat intelligence capability and translation into actionable insights for the Group companies.

  • Champions vulnerability assessments delivery and execution (Vulnerability Scanning, risk-based penetration testing).

  • Drives the discovery of vulnerabilities via structured scanning of the digital platforms/landscapes in an optimised manner. Works closely with the enterprise Risk team to assess and prioritise the vulnerability reports according to high risk and criticality.

  • Partners with enterprise risk team, to ensure cyber security integrity and robustness in the group by prioritising based on the identified risk level and criticality of the vulnerability assessments and ensures closure of the prioritised vulnerabilities with the relevant IT/Digital delivery teams in a focused & coordinated manner to protect the Group companies.

  • Integrate vulnerabilities into the cyber defence data lake to identify potential risks or anomalies.

  • Run Risk based red team and penetration testing capabilities that will be to assess the security posture of the group and digital solutions.

  • Work closely with the Strategy & Portfolio Manager to enhance the Cyber resilience of the IT domains by introducing new technical solutions, concepts and capabilities. Including the drive for automation of analytics capability to enhance the agent's analysis performance and time.

  • Leads the Cybersecurity team to ensure the team is continuously developed, and coached to protect the group companies.

  • Work closely with external sources, partners, national cybersecurity agencies and industry groups.

  • Provide periodic cyber defence reports for various stakeholders.

  • Provide support on any authorised investigation-related discovery cases when requested by Group Audit and Legal teams


  • At least 10 years of experience in Information Security preferably in Security Operations

  • Competent cyber security leader who enhances and sustains required capabilities. Achieves high-performance delivery with the right leadership behaviours executing their roles.

  • Develops & implements distinctive mindset, behaviour and culture to achieve high performance via value interventions, tools, and methodologies to promote commitment, ownership, integrity and loyalty towards team success.

  • Ensures compliance with the Group governance procedures, guidelines and code of conduct requirements

  • Fosters, working relationships and rapport with Business CISOs, key industry players and market providers to keep up with the latest developments to ensure secure Business Growth.


  • Physical Wellbeing: Key medical and insurance benefits, maternity expenses, flexible work arrangement, and health and fitness amenities.
  • Emotional Wellbeing: Paid time off, wellness programmes, and childcare amenities.
  • Financial Wellbeing: Resources relating to financial, personal skills and career growth programmes.
  • Allstars Specials: Free flights, unlimited discounted flights, and exclusive discounts with partners.
  • A unique Allstar culture like no other


  • Application received
  • Candidate screening
  • Interview(s) and assessment(s)
  • Background check and/or other assessments
  • Offer and negotiation

We are all different - one talent to another - that is how we rely on our differences. At AirAsia, you will be treated fairly and given all chances to be your best.We are committed to creating a diverse work environment and are proud to be an equal opportunity employer.

Search Firm Representatives - AirAsia does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place.

Capital A Berhad, operating as AirAsia is a Malaysian multinational low-cost airline headquartered near Kuala Lumpur, Malaysia. It is the largest airline in Malaysia by fleet size and destinations. AirAsia operates scheduled domestic and international flights to more than 165 destinations spanning 25 countries


Similar Jobs

Head of Cyber Risk Policy Assurance

Company Name Confidential

Head of Network Security

Company Name Confidential
Last Updated: 12-07-2024 07:04:55 PM
Home Jobs in Malaysia Head of Cyber Defence
Beware of Scammers

We don’t charge money for job offers