Search Jobs

Search by job, company or skills

Information Security Analyst

Information Security Analyst

Air Liquide
  • Posted 12 hours ago
  • Be among the first 10 applicants

Job Description

Entity and activity description

Air Liquide IT: The Group launched an overhaul of its IT services, to simultaneously improve and world security, competitiveness and agility. This results in a changing IT organizations with infrastructure services and IT production which will now be managed globally by a central department called GIO (Global Infrastructure Operations) and business applications that will be supported by dedicated departments, called BIS (Business Information Systems) for each business line and relevant geographies.

How will you CONTRIBUTE and GROW

1. Application Security, Architecture Review & Risk Analysis

  • Architecture & Design Reviews: Evaluate application architectures and cloud/on-premise deployment patterns against enterprise security standards to ensure alignment with Security & Privacy by Design principles.
  • Threat Gap Identification: Conduct threat modeling and risk assessments to identify technical vulnerabilities, architectural flaws, and control gaps early in the application lifecycle.
  • Risk Assessment & Impact Analysis: Quantify and document technical, operational, and business risks associated with system changes, third-party integrations, and new technology deployments.

2. Risk Exception Management & Policy Governance

  • Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
  • Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
  • Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re-evaluation.

3. Vulnerability & Compliance Management (Cyber Ops)

  • Vulnerability Scanning & Remediation: Execute continuous vulnerability assessments across IT/OT networks and applications using enterprise tools (e.g., Qualys, PRISMA Cloud).
  • Penetration Test Follow-Up: Track remediation of findings from IT/OT penetration tests, perform re-testing validation, and support ad-hoc testing requirements.
  • Operational Security Requests: Manage and triage incoming requests from the centralized security mailbox, along with ad-hoc tickets (e.g., firewall rule changes, proxy whitelisting, YourWay requests).

4. Security Operations & Governance Support

  • Threat Intelligence Execution: Process and execute follow-up actions on cyber threat intelligence reports issued by the CSIRT.
  • IAM & Access Control Reviews: Coordinate annual Identity and Access Management (IAM) access reviews for both standard users and High Privilege Accounts (HPA).
  • Metrics & Reporting: Maintain security dashboards, track CMDB asset governance, and produce security reporting for leadership.

Qualifications & Candidate Requirements:

Education & Experience

  • Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field (or equivalent practical experience).
  • Experience: 5+ years of hands-on experience in information security, risk management, vulnerability management, or security incident handling across both IT and OT (Operational Technology) environments.

Vulnerability Management & Penetration Testing Coordination

  • Vulnerability Assessment & Governance: Demonstrated expertise in running enterprise-wide vulnerability management programs (using tools such as Qualys, PRISMA Cloud, etc.), including scanning, prioritization, triage, and SLA enforcement across IT/OT infrastructure.
  • Penetration Test Follow-up & Remediation: Proven experience coordinating third-party and internal penetration testing engagements. This includes analyzing findings, leading remediation workflows with infrastructure/application teams, facilitating re-testing, and conducting ad-hoc security validations.

Security Architecture & Risk Management

  • Application Architecture & Threat Modeling: Deep understanding of secure application architecture, cloud-first patterns, threat modeling, and identifying structural threat gaps during design reviews.
  • Access Control & Identity Architecture: Strong technical command of identity and access governance, including Role-Based Access Control (RBAC), Tiered Access Models, and Privileged Access Management (PAM/HPA).
  • Risk Assessment & Exception Handling: Hands-on experience performing technical risk analyses, evaluating compensating controls, and managing formal digital security policy exception workflows (DTAP/waivers).
  • Communication & Certifications
  • Communication: Exceptional written and verbal communication skills, with a track record of producing clear technical risk reports, executive dashboards, and policy documentation.
  • Certifications (preferably ): Professional certifications such as CISSP, CISA, CRISC or CISM

Other Information:

  • Office Location: Level 17, 1Powerhouse
  • Accessible via MRT & LRT 3 (Bandar Utama station)

More Info

Job Type:
Industry:
Employment Type:

About Company