

Search by job, company or skills

This job is no longer accepting applications
Job Role: Lead System Security Architect
Employer: International multi-utility owner and operator that functions as an investment holding company providing essential infrastructure and services.
Location: Kuala Lumpur, Malaysia
Job Type: Full Time – On Site
Experience: At least 5 years work experience as a System Security Architect.
JOB DESCRIPTION
• Directly support the company's CISO.
• Lead and manage GRC personnel as required.
• Develop, review and implement security architectures and frameworks for IT systems, networks, applications and OT systems.
• Develop and maintain reference security architectures and models.
• Develop and maintain system security architecture patterns, design standards, templates and models.
• Define and enforce security policies, procedures, and best practices.
• Define governance and risk management procedures and methodologies.
• Guide security roadmap development based on business and enterprise priorities.
• Evaluate or prepare security requirements for projects or tender submissions.
• Evaluate and recommend security tools and technologies.
• Develop security assessment surveys and maturity measurement methods.
• Identify vulnerability and perform or guide security risk assessments.
• Coordinate and communicate GRC activities across the Group's subsidiaries.
• Define and manage data gathering and reporting across the Group's subsidiaries.
• Work with company's audit and risk specialists to maintain and present a consistently accurate assessment of enterprise security risk.
• Work with the company's Cyber Security Architect to ensure all aspects of Cyber Security Operational capability are developing appropriately and to communicate threat intel across company's subsidiaries as required.
• Work with the company's Security Compliance Lead to ensure all aspects of the Security GRC function are planned, implemented and applied effectively.
JOB REQUIREMENTS
• In-depth knowledge of Mitre ATT&CK Tactics and Techniques and OWASP Top Ten .
• Practical experience in NIST CSF and CIS Controls assessment and implementation .
• Demonstrable experience delivering detailed system security design and threat modelling.
• In-depth work experience in hybrid and cloud architecture / system design and implementation.
• In-depth knowledge of zero trust principles, network security, cloud security, cryptography, and secure software development.
• Project and/or programme management and support experience.
• Excellent documentation and writing skills.
• Excellent communications skills.
• At least 5 years work experience as a System Security Architect.
• Previous work experience in IT architecture and infrastructure.
• BSc in Computer Science, Computer Engineering or equivalent.
Additional Requirements
Certification: CISSP / OSCP / CEH
Job ID: 153361223