Talent.com
Tawaran kerja ini tidak tersedia di negara anda.
Information Security, Senior Executive (1 year contract)

Information Security, Senior Executive (1 year contract)

WhiteCoatMalaysia, 14, MY
21 hari lalu
Penerangan pekerjaan

About WhiteCoat

WhiteCoat is a Singapore-headquartered omnichannel provider of integrated health and wellness services that serves as the first and single touchpoint for all care needs in Southeast Asia.

Since launching in 2018, WhiteCoat’s digital platform powers a wide range of services including tele- and in-person consultations, as well as medication fulfilment and diagnostic testing, across primary, specialist and allied care. With a focus on the B2B space, WhiteCoat has forged strategic partnerships with the region’s leading insurers, corporates and care providers, to provide accessible and affordable high-quality care to its users.

The Group currently has offices in Singapore, Indonesia, Malaysia and Vietnam. For more information on WhiteCoat, please visit https : / / whitecoat.global .

What you will be doing

The Information Security Senior Executive is responsible for embedding security into the entire software development lifecycle (SDLC). This role owns the application and product security roadmap, from initial design to deployment and operation.

You will safeguard our information systems by proactively identifying, assessing, and mitigating security risks in our software. This position acts as a critical bridge between development, operations, and security teams, ensuring our products are built on a foundation of security and trust.

Your accountability spans secure development practices, automated security testing (SAST / DAST), penetration testing, and vulnerability management, with a clear mandate to drive down risk without impeding engineering velocity.

Key Responsibilities :

1. Security Governance & Operations

Develop, implement, and enforce security policies, standards, and guidelines aligned with industry best practices (e.g., ISO 27001, NIST, OWASP).

Own and manage the regulator reporting workflow for security incidents and data breaches (e.g., PDPC, MAS, MOH), ensuring timely and accurate submissions.

Prepare and present a quarterly board-level metrics pack detailing our security posture, vulnerability status, testing outcomes, and risk landscape.

Monitor, assess, and respond to security threats and incidents in close coordination with the Security Operations Center (SOC) and IT teams.

2. Secure Development & Testing (DevSecOps)

Integrate and automate security tooling into the CI / CD pipeline at key gates :

Static Application Security Testing (SAST) on every pull request.

Software Composition Analysis (SCA) for dependency scanning on every merge.

Dynamic Application Security Testing (DAST) in pre-production environments.

Lead threat-modeling workshops with engineering teams to proactively identify architectural flaws and teach them to "think like an attacker."

Work directly with development teams to remediate identified vulnerabilities, providing clear guidance and promoting secure coding practices.

3. Penetration Testing & Vulnerability Management

Plan and manage a continuous program of internal and external penetration testing for applications, APIs, networks, and cloud infrastructure.

Oversee the budget for third-party security assessments to ensure specialized testing can be procured without delay.

Enforce risk-stratified Service Level Agreements (SLAs) for remediation (e.g., Critical : 7 days, High : 14 days), tracked transparently in Jira.

Validate remediation efforts post-testing and ensure all identified risks are formally closed or accepted.

4. Incident Response & Threat Management

Lead application-focused incident response activities, including investigation, containment, eradication, and recovery.

Conduct blameless post-mortems and root cause analysis for security incidents, ensuring preventative measures are implemented.

Run regular table-top exercises and purple-team drills to test and improve our response capabilities.

Track emerging threats, vulnerabilities, and exploits relevant to the organization’s technology stack and software supply chain.

5. Awareness & Training

Establish and lead a Security Champions Guild, embedding a security-focused engineer in each squad to act as a first-line AppSec advocate.

Provide technical guidance and hands-on training to development, QA, and operations teams on security best practices and tooling.

Promote a security-first culture across the organization, making security a shared responsibility.

Our Benefits

Make a Real Impact : Opportunity to contribute to a leading digital health company's rapid growth.

Fast-paced Start-up Environment : Experience an environment where you get to own and make tangible impact without bureaucracy getting in the way of rapid decision-making.

Great Team : Collaborate with intelligent, friendly, and supportive professionals from diverse backgrounds.

Hands-on Learning & Growth : Gain hands-on experience in strategy, partnerships, operations, and product innovation within a growing industry.

Competitive Compensation & Benefits : Competitive compensation and performance-based bonus.

How to apply

If you believe you have what it takes for this role, click ‘Apply’ and join us on our journey to make a positive impact on the lives of people through innovative healthcare solutions!

What we are looking for

Education & Certification :

Bachelor’s degree in Computer Science, Information Security, or a related field.

Relevant certifications strongly preferred (e.g., OSCP, GWAPT, GPEN, CSSLP, CISSP).

Technical Skills :

Deep expertise in application security concepts and frameworks (OWASP Top 10, SANS CWE 25).

Hands-on experience with SAST (e.g., SonarQube, Checkmarx), DAST (e.g., OWASP ZAP, Burp Suite), and SCA / SBOM tools (e.g., Syft, Grype, Snyk).

Practical experience conducting, managing, and interpreting penetration test results.

Proven ability to integrate security tools into CI / CD pipelines (e.g., Jenkins, GitLab CI, GitHub Actions).

Strong understanding of secure coding practices in languages like Java, Python, and JavaScript.

Proficiency in cloud security, with a priority on AWS (CIS Benchmarks, IAM), and familiarity with Azure / GCP.

Experience with Infrastructure as Code (IaC) security scanning (e.g., Terraform, CloudFormation).

Soft Skills :

Exceptional communication skills, with a proven ability to translate technical CVEs into business and product impact for executive stakeholders.

Strong analytical and problem-solving skills, with a proactive, detail-oriented mindset.

Demonstrated ability to influence roadmap trade-offs and collaborate effectively with Product, Legal, and Audit teams.

Buat amaran kerja untuk carian ini

Executive Executive • Malaysia, 14, MY

Pekerjaan yang berkaitan
  • Dinaikkan pangkat
  • Baharu!
Client Onboarding Analyst 1 (Mandarin proficiency)

Client Onboarding Analyst 1 (Mandarin proficiency)

Citigroup Inc.PahangMalaysia, Pahang, Malaysia
At Citi, we connect millions of people across hundreds of cities and countries every day.We provide a broad range of financial services and products to our clients – whether they be consumers, corp...Tunjukkan lagiKemas kini terakhir: 18 jam yang lalu
  • Dinaikkan pangkat
Senior Associate (Audit)

Senior Associate (Audit)

Jobstreet MalaysiaPahangMalaysia, Pahang, Malaysia
We are an established audit firm seeking an experienced Audit Senior Associate to join our team.This role provides strong career prospects and opportunities to work with top auditors, supporting ca...Tunjukkan lagiKemas kini terakhir: 2 hari yang lalu
  • Dinaikkan pangkat
  • Baharu!
Senior Executive

Senior Executive

Sunway PropertyMalaysia
Sunway Property is the property arm of Sunway Group which was established in 1974, and is now one of Malaysia's top multinational property-construction. Our unique business model 'Build, Own, Operat...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Manager, Group Information Security

Manager, Group Information Security

FWD InsuranceMalaysia
HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD's customer-led and tech-enabled approach ...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Manager, IT Security Operation

Manager, IT Security Operation

FGV HoldingsMalaysia, Malaysia
Manager , IT Security Operation page is loaded## Manager , IT Security Operationlocations : Wisma FGVtime type : Full timeposted on : Posted 2 Days Agojob requisition id : JR2268 • •FGV Holdings ...Tunjukkan lagiKemas kini terakhir: 18 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
05 - Security Support 5

05 - Security Support 5

Celestica Inc.Malaysia, Malaysia
Press Tab to Move to Skip to Content Link.Select how often (in days) to receive an alert : .Incumbents may determine best methods and procedures to follow to complete assignments.Tasks are very compl...Tunjukkan lagiKemas kini terakhir: 18 jam yang lalu
  • Dinaikkan pangkat
Site Safety Supervisor

Site Safety Supervisor

ERAWORKS ENERGY (MALAYSIA) SDN. BHD.PahangMalaysia, Pahang, Malaysia
Reporting to the Safety Officer and Project Manager, this full-time Site Safety Supervisor role is responsible for ensuring the highest standards of health, safety and environmental practices are m...Tunjukkan lagiKemas kini terakhir: 2 hari yang lalu
  • Dinaikkan pangkat
  • Baharu!
Executive / Senior Executive, Roadshow Management

Executive / Senior Executive, Roadshow Management

Samsung Malaysia Electronics (SME) Sdn BhdMalaysia
Plan and manage retail roadshows, expos, and events, ensuring optimal locations, layouts, and shopper engagement.Develop roadshow layouts, planograms, and design segmentation based on shopper insig...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
ADMIN OFFICER (MALAYSIA)

ADMIN OFFICER (MALAYSIA)

Dxn2uKuala Atok, Pahang, Malaysia
Record Keeping - Maintain and organize office record, document, and databases.Communication - Handle incoming and outgoing correspondence, email, and phone calls, acting as a point contact for quer...Tunjukkan lagiKemas kini terakhir: 2 hari yang lalu
  • Dinaikkan pangkat
  • Baharu!
Senior Executive

Senior Executive

Public Mutual BerhadMalaysia
Assist in the development, enhancement and implementation of operational risk management policies / guidelines.Prepare risk reports by analysing operational loss event data and key risk indicator tr...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Digital & E-Commerce, Senior Executive

Digital & E-Commerce, Senior Executive

UNIVERSAL TRAVELLER SHOP SDN BHDMalaysia
At Universal Traveller, we equip travellers with reliable luggage and stylish winter apparel, designed to inspire confident journeys. As we continue to expand across digital channels and marketplace...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Senior Executive, ITBP Corporate Services

Senior Executive, ITBP Corporate Services

Malaysia AirlinesMalaysia
Senior Executive, ITBP Corporate Services ‎.Lead, ITBP Airlines Operation (Ground).Execute assigned business units (IT Corporate Services) on technology requirements, IT Support (incidents and prob...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Senior Admin Executive

Senior Admin Executive

Agensi Pekerjaan Find Talent Sdn BhdPacific Remote Islands Marine National Monument, Howland Island, Malaysia
You will be facilitating immigration work, mainly on Singapore Permanent Resident and Singapore Citizenship applications. You will be responsible to develop and maintain the most up-to-date knowledg...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Chief Information Security Officer

Chief Information Security Officer

AmbitionMalaysia
Main Duties & Responsibilities : .Define and execute the information security strategy aligned with group policies and regulatory requirements. Lead the development of security architecture, framework...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
senior executive, ict

senior executive, ict

TRIplc BerhadMalaysia
Responsible for leading the analysis, support, and optimization of Electronic Medical Records (EMR) systems across the healthcare network. This role acts as the key liaison between clinical, operati...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Operation Executive

Operation Executive

Chan Chee Kheong & Brothers Travel Sdn. Bhd.Malaysia
Develop creative and marketable tour packages and itineraries for different travel markets.Conduct product reserach and destination studies, identifying new attractions, accommodation and unique ex...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Operational Training Executive

Operational Training Executive

Giga Maritime GroupMalaysia
The Operational Training Executive is responsible for planning, delivering, and monitoring training programs for drivers and operational staff to ensure compliance with company standards, regulator...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Executive, Infrastructure Planning

Executive, Infrastructure Planning

Malaysian Communications and Multimedia CommissionMalaysia
Responsible to facilitate and coordinate the operation of Infrastructure Planning & Implementation Unit (IPIU) to ensure all infrastructure development projects meet the target, well managed and co...Tunjukkan lagiKemas kini terakhir: 6 jam yang lalu