Talent.com
This job offer is not available in your country.
Information Security, Senior Executive (1 year contract)

Information Security, Senior Executive (1 year contract)

WhiteCoatMalaysia, 14, MY
19 days ago
Job description

About WhiteCoat

WhiteCoat ( www.whitecoat.global ) is a regional digital healthcare provider founded and headquartered in Singapore which has established itself as a trusted partner and leading provider in the digital healthcare space across Southeast Asia. WhiteCoat offers on-demand telemedicine services and other services through innovation and data-driven technology.

WhiteCoat’s core services include primary care tele-consultations, chronic disease management, health screening services and home-based medical services. As a digital healthcare leader, WhiteCoat partners insurance providers, conglomerates, and other private, government, and financial organisations to spearhead the way for wider access to affordable healthcare across the region.

What you will be doing

The Information Security Senior Executive is responsible for embedding security into the entire software development lifecycle (SDLC). This role owns the application and product security roadmap, from initial design to deployment and operation.

You will safeguard our information systems by proactively identifying, assessing, and mitigating security risks in our software. This position acts as a critical bridge between development, operations, and security teams, ensuring our products are built on a foundation of security and trust.

Your accountability spans secure development practices, automated security testing (SAST / DAST), penetration testing, and vulnerability management, with a clear mandate to drive down risk without impeding engineering velocity.

Key Responsibilities

Security Governance & Operations

Develop, implement, and enforce security policies, standards, and guidelines aligned with industry best practices (e.g., ISO 27001, NIST, OWASP).

Own and manage the regulator reporting workflow for security incidents and data breaches (e.g., PDPC, MAS, MOH), ensuring timely and accurate submissions.

Prepare and present a quarterly board-level metrics pack detailing our security posture, vulnerability status, testing outcomes, and risk landscape.

Monitor, assess, and respond to security threats and incidents in close coordination with the Security Operations Center (SOC) and IT teams.

2. Secure Development & Testing (DevSecOps)

Integrate and automate security tooling into the CI / CD pipeline at key gates :

Static Application Security Testing (SAST) on every pull request.

Software Composition Analysis (SCA) for dependency scanning on every merge.

Dynamic Application Security Testing (DAST) in pre-production environments.

Lead threat-modeling workshops with engineering teams to proactively identify architectural flaws and teach them to "think like an attacker."

Work directly with development teams to remediate identified vulnerabilities, providing clear guidance and promoting secure coding practices.

3. Penetration Testing & Vulnerability Management

Plan and manage a continuous program of internal and external penetration testing for applications, APIs, networks, and cloud infrastructure.

Oversee the budget for third-party security assessments to ensure specialized testing can be procured without delay.

Enforce risk-stratified Service Level Agreements (SLAs) for remediation (e.g., Critical : 7 days, High : 14 days), tracked transparently in Jira.

Validate remediation efforts post-testing and ensure all identified risks are formally closed or accepted.

4. Incident Response & Threat Management

Lead application-focused incident response activities, including investigation, containment, eradication, and recovery.

Conduct blameless post-mortems and root cause analysis for security incidents, ensuring preventative measures are implemented.

Run regular table-top exercises and purple-team drills to test and improve our response capabilities.

Track emerging threats, vulnerabilities, and exploits relevant to the organization’s technology stack and software supply chain.

5. Awareness & Training

Establish and lead a Security Champions Guild, embedding a security-focused engineer in each squad to act as a first-line AppSec advocate.

Provide technical guidance and hands-on training to development, QA, and operations teams on security best practices and tooling.

Promote a security-first culture across the organization, making security a shared responsibility.

Our Benefits

Make a Real Impact : Opportunity to contribute to a leading digital health company's rapid growth.

Fast-paced Start-up Environment : Experience an environment where you get to own and make tangible impact without bureaucracy getting in the way of rapid decision-making.

Great Team : Collaborate with intelligent, friendly, and supportive professionals from diverse backgrounds.

Hands-on Learning & Growth : Gain hands-on experience in strategy, partnerships, operations, and product innovation within a growing industry.

Competitive Compensation & Benefits : Competitive compensation and performance-based bonus.

How to apply

If you believe you have what it takes for this role, click ‘Apply’ and join us on our journey to make a positive impact on the lives of people through innovative healthcare solutions!

What we are looking for

Education & Certification :

Bachelor’s degree in Computer Science, Information Security, or a related field.

Relevant certifications strongly preferred (e.g., OSCP, GWAPT, GPEN, CSSLP, CISSP).

Technical Skills :

Deep expertise in application security concepts and frameworks (OWASP Top 10, SANS CWE 25).

Hands-on experience with SAST (e.g., SonarQube, Checkmarx), DAST (e.g., OWASP ZAP, Burp Suite), and SCA / SBOM tools (e.g., Syft, Grype, Snyk).

Practical experience conducting, managing, and interpreting penetration test results.

Proven ability to integrate security tools into CI / CD pipelines (e.g., Jenkins, GitLab CI, GitHub Actions).

Strong understanding of secure coding practices in languages like Java, Python, and JavaScript.

Proficiency in cloud security, with a priority on AWS (CIS Benchmarks, IAM), and familiarity with Azure / GCP.

Experience with Infrastructure as Code (IaC) security scanning (e.g., Terraform, CloudFormation).

Soft Skills :

Exceptional communication skills, with a proven ability to translate technical CVEs into business and product impact for executive stakeholders.

Strong analytical and problem-solving skills, with a proactive, detail-oriented mindset.

Demonstrated ability to influence roadmap trade-offs and collaborate effectively with Product, Legal, and Audit teams.

Create a job alert for this search

Executive Executive • Malaysia, 14, MY

Related jobs
  • Promoted
  • New!
Senior Associate (Audit)

Senior Associate (Audit)

Jobstreet MalaysiaPahangMalaysia, Pahang, Malaysia
We are an established audit firm seeking an experienced Audit Senior Associate to join our team.This role provides strong career prospects and opportunities to work with top auditors, supporting ca...Show moreLast updated: 8 hours ago
  • Promoted
Hiring Application Security -DevSecops Experience

Hiring Application Security -DevSecops Experience

ConfidentialMalaysia
Regional or global experience is advantageous.Experience with at least one major cloud provider (.CISSP, Security+, CISA, or equivalent. Strong command of written and spoken.Application Security, Ow...Show moreLast updated: 7 days ago
Senior Executive, Support Specialist

Senior Executive, Support Specialist

WhiteCoatMalaysia, 14, MY
If you are not viewing this at our career site, please go to.Singapore, offering on-demand telemedicine services and other services through innovation and data-driven technology.WhiteCoat’s core se...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
Site Safety Supervisor

Site Safety Supervisor

ERAWORKS ENERGY (MALAYSIA) SDN. BHD.PahangMalaysia, Pahang, Malaysia
Reporting to the Safety Officer and Project Manager, this full-time Site Safety Supervisor role is responsible for ensuring the highest standards of health, safety and environmental practices are m...Show moreLast updated: 8 hours ago
Lead Compliance Officer

Lead Compliance Officer

SleekMY
Quick Apply
Through proprietary software and AI, along with a focus on customer delight, Sleek makes the back-office easy for micro SMEs. We give Entrepreneurs time back to focus on what they love doing - growi...Show moreLast updated: 6 days ago
Senior Operations Executive for Teacher Team (Remote MY)

Senior Operations Executive for Teacher Team (Remote MY)

Write EdgeMY
Quick Apply
Write Edge Learning Centre 12 Branches in Singapore, Online arm in Singapore, Malaysia and Indonesia.The Training and Development team is in charge of developing a strong team of teachers and worki...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
ADMIN OFFICER (MALAYSIA)

ADMIN OFFICER (MALAYSIA)

Dxn2uKuala Atok, Pahang, Malaysia
Record Keeping - Maintain and organize office record, document, and databases.Communication - Handle incoming and outgoing correspondence, email, and phone calls, acting as a point contact for quer...Show moreLast updated: 8 hours ago
Lead Consultant (FortiGuard Incident Response) - APAC

Lead Consultant (FortiGuard Incident Response) - APAC

FortinetMY
Join Fortinet, a cybersecurity pioneer with over two decades of excellence, as we continue to shape the future of cybersecurity and redefine the intersection of networking and security.At Fortinet,...Show moreLast updated: 30+ days ago
  • Promoted
Execution Executive, G&O (Palm)

Execution Executive, G&O (Palm)

Louis Dreyfus Company B.V.Malaysia, Malaysia
Louis Dreyfus Company is a leading merchant and processor of agricultural goods.Our activities span the entire value chain from farm to fork, across a broad range of business lines, we leverage our...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
Business Development Executive- Outdoor Sales Consultant (Kuantan)

Business Development Executive- Outdoor Sales Consultant (Kuantan)

Rentokil Initial plcPahangMalaysia, Pahang, Malaysia
We are looking for a motivated, dynamic.Business Development Executive - Outdoor Sales Consultant.Your responsibilities will be to build on solid existing client relationships while also using your...Show moreLast updated: 14 hours ago