Search by job, company or skills

Specialist, IT CyberSecurity

  • Posted 16 hours ago
  • Be among the first 10 applicants

Job Description

Position Summary

The Specialist, IT CyberSecurity is the Group's senior technical expert for information and cyber security, supporting the protection of the Group's IT and operational technology environments across all sites.

Reporting to the Group IDT Director, the role provides the technical expertise behind the Group's security operations capability — threat monitoring, incident response, vulnerability management, endpoint and network security, and identity and access controls — and the governance framework that sits above it, covering security policy, standards, risk assessment, audit response, and regulatory compliance. The role combines hands-on technical delivery with policy development: it designs and operates security controls directly, and drafts the standards that, once approved by the Group IDT Director, site IT teams, application owners, and third-party providers are required to follow. It is an individual-contributor role without technical authority: its influence is exercised through the development of Group security strategy and operating plans, with ownership of those strategies and of the Group's security operations capability remaining with the Group IDT Director. The role works through site IT teams and functional stakeholders rather than direct reports, and managing security tooling and managed-service vendors at the operational level.

Responsibilities

Security Governance, Policy and Risk

  • Develop and maintain, for the Group IDT Director's approval, the Group information security policy set, standards, and procedures, and keep them aligned to recognised frameworks such as ISO 27001 and the NIST Cybersecurity Framework.
  • Conduct cyber risk assessments across Group and site systems, maintain the security risk register, and track remediation of identified risks to closure.
  • Recommend security requirements and standards for the Group IDT Director's endorsement, which site IT teams, application owners, and project teams are then required to apply, and support them in meeting these consistently.
  • Report the Group's security posture, incident trends, risk exposure, and improvement progress to the Group IDT Director and senior management.
  • Manage security tooling and managed-security-service vendors at the operational level, including service quality, licence utilisation, and cost.

Security Operations, Monitoring and Incident Response

  • Operate and continuously improve Group security monitoring, covering SIEM use cases, log sources, detection rules, and alert triage across endpoints, servers, network, and cloud services.
  • Lead investigation and response for security incidents end to end, including containment, eradication, recovery, root-cause analysis, and post-incident reporting.
  • Maintain and test the cyber incident response plan and playbooks, and coordinate escalation with site IT teams, business stakeholders, external responders, and authorities where required.
  • Oversee email, web, and endpoint protection controls — anti-malware, EDR, phishing defence, and content filtering — and tune them to reduce both risk and false positives.
  • Monitor threat intelligence relevant to the manufacturing and industrial sector, and translate it into detection, hardening, and awareness actions.

Vulnerability and Threat Management

  • Run the Group vulnerability management cycle — scanning, prioritization by risk and exploitability, remediation tracking, and verification — across servers, endpoints, network devices, and applications.
  • Define and monitor patching and hardening standards and baseline configurations, and report compliance against them by site and system.
  • Plan and coordinate penetration tests and security assessments, and drive remediation of findings to agreed timelines.
  • Assess the security of new systems, integrations, and cloud services before deployment, and recommend the controls required for approval.
  • Support security assurance for operational technology and manufacturing systems, including network segmentation between IT and OT environments.

Identity, Access and Data Protection

  • Develop and maintain identity and access management standards, including least-privilege, privileged-access controls, multi-factor authentication, and periodic access reviews and recertification.
  • Define and oversee data protection controls — classification, encryption, backup integrity, and data-loss prevention — for information held on premise and in cloud services.
  • Secure network and infrastructure architecture in conjunction with infrastructure teams, covering segmentation, firewall and remote-access policy, and secure configuration of cloud tenancies.
  • Assess and monitor the security of third parties and service providers, including due diligence, contractual security requirements, and periodic review.

Compliance, Audit and Security Awareness

  • Maintain readiness for internal and external audits, customer security assessments, and certification requirements, and coordinate responses and corrective actions.
  • Ensure Group practices meet applicable data-protection and regulatory obligations across the jurisdictions in which the Group operates, working with Legal and HR as required.
  • Design and run the Group security awareness programme, including training, phishing simulations, and targeted guidance for higher-risk roles.
  • Maintain security documentation, control evidence, and metrics to support governance reporting and audit enquiries.

Experience

  • Minimum 6 years of experience in IT, of which at least 3 years in a dedicated information security or cyber security role covering both operational security and governance.
  • Hands-on experience operating security monitoring and detection tooling (e.g. Microsoft Sentinel, Defender XDR, Splunk, or equivalent SIEM/EDR platforms), including alert triage and detection tuning.
  • Demonstrable experience leading security incident investigation and response end to end, including containment, root-cause analysis, and reporting to management.
  • Experience running a vulnerability management programme, including scanning tooling, risk-based prioritisation, patching standards, and remediation tracking across a distributed estate.
  • Experience implementing and operating identity and access management controls, including privileged access, multi-factor authentication, and access reviews.
  • Practical experience applying recognised security frameworks and standards (e.g. ISO 27001, NIST CSF, CIS Controls) and drafting security policy and standards.
  • Experience supporting internal and external audits, customer security assessments, or certification exercises, including evidence preparation and corrective action.
  • Experience securing cloud environments (Azure, AWS) and hybrid infrastructure, including network security, firewalls, and secure configuration baselines.
  • Experience working with a regional or global headquarters IT function within a multinational group, influencing security standards across sites without direct authority, is an advantage.
  • Experience in a manufacturing or industrial environment, including operational technology or ICS/SCADA security and IT/OT segmentation, is an advantage.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline.
  • Professional security certification is strongly preferred, e.g. CISSP, CISM, or CISA.
  • Cloud security certification is an advantage, e.g. Microsoft SC-200 or SC-100, AZ-500, or AWS Certified Security – Specialty.
  • ITIL Foundation or an equivalent service-management certification is an advantage.
  • Fluency in written and spoken English; additional Mandarin ability is an advantage given Group operations in China.

Competencies

Technical

  • Strong grounding in security operations — threat detection, SIEM/EDR tooling, log analysis, and incident response.
  • Proficient in vulnerability management, secure configuration and hardening, patch management, and penetration-test remediation.
  • Sound knowledge of network, cloud, and endpoint security architecture, including segmentation, firewalls, encryption, and identity and access management.
  • Working knowledge of security frameworks, standards, and regulatory requirements (e.g. ISO 27001, NIST CSF, CIS Controls, data-protection legislation), and the ability to translate them into practical controls.
  • Competent with scripting and automation for security tasks and reporting (e.g. PowerShell, Python), and with security dashboards and metrics.
  • Informed view of emerging threats and of the security implications of AI tools and services adopted by the business.

Influence and Enablement

  • Develops Group security standards and drives their adoption by site IT teams, project teams, and vendors through advice, evidence, and escalation to the Group IDT Director, rather than direct authority.
  • Able to build credibility with technical teams and business stakeholders, and to influence adoption of security practices through advice and evidence.
  • Coordinates infrastructure, application, HR, Legal, and vendor parties to deliver consistent security outcomes across the Group.

Non-Technical

  • Strong analytical, investigative, problem-solving, and decision-making skills, with sound judgement under pressure.
  • Effective communication and stakeholder-management skills, able to explain security risk and trade-offs to non-technical stakeholders and senior management.
  • Ability to manage competing priorities across incidents, projects, and audit commitments, and to remain composed during security events.
  • Diligent and continuous-improvement mindset, with attention to detail, discretion in handling sensitive information, and a bias for documentation and automation.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152117847

Similar Jobs

Petaling Jaya, Malaysia, Selangor

Skills:

PowerbiBwKnimeHanaPythonSqlSap EccAI ToolsSACBI and Visualization

Shah Alam, Malaysia, Selangor

Skills:

MetasploitEthical HackingLinux System AdministrationIt Information SecurityNetwork ProtocolsCybersecurityBurp SuiteIamOwasp Top 10SplunkautomationPenetration TestingWeb Application SecurityQualysAWS security controlsNessusthreat detection methodologiesSIEM platformsAI-assisted security analysis

Malaysia, Cyberjaya, Selangor

Skills:

Cloud security architectureDevSecOps and secure engineeringArchitecture leadership and governance capabilityThreat modelling and architecture risk assessmentZero Trust ArchitectureContainer Kubernetes and platform securityStakeholder alignment across engineering teamsAbility to translate policy into technical implementation

Petaling Jaya, Malaysia, Selangor

Skills:

Oracle databaseJavascriptCSSPhpPythonHTMLGit version control systems

Petaling Jaya, Malaysia, Selangor

Skills:

Azure Data FactoryPower BiEtl ToolsDatabricksInformaticaTalendPythonSql

Beware of Scammers

We don’t charge money for job offers