About the role
As a Senior IT Security Officer, you will play a critical role in safeguarding the organisation’s information assets and digital infrastructure. You will be responsible for planning, implementing, and monitoring security measures to protect systems, networks, and data from cyber threats. This role requires a proactive professional who can balance technical expertise with strategic oversight, ensuring compliance with regulatory requirements while supporting business operations.
What you'll be doing
- Oversee daily IT security operations, including system monitoring, incident detection, and response.
- Conduct regular vulnerability assessments, penetration testing, and threat analysis to mitigate risks.
- Develop, review, and enforce IT security policies, standards, and procedures in line with ISO 27001, PDPA, and other regulatory requirements.
- Conduct IT security audits and risk assessments, ensuring findings are addressed and documented.
- Ensure compliance with organisational, legal, and industry security standards.
- Lead investigations of security breaches, root cause analysis, and remediation.
- Coordinate incident response activities with internal teams and external stakeholders.
- Manage user access controls, authentication mechanisms, and privilege management.
- Ensure strict adherence to least-privilege and segregation-of-duties principles.
- Conduct staff security awareness programs and training sessions.
- Promote a strong cybersecurity culture across the organisation.
- Provide expert advice to management and project teams on IT security best practices.
- Collaborate with vendors, regulators, and partners on IT security matters.
What we're looking for
Malaysian citizenship is mandatory.Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field.Minimum 5 years of working experience in IT security, with at least 3 years at the executive / senior executive level.Strong knowledge of cybersecurity frameworks, standards, and tools (ISO 27001, NIST, CIS, PDPA, etc.).Hands-on experience with firewalls, intrusion detection / prevention systems (IDS / IPS), SIEM, endpoint protection, and encryption technologies.Experience in incident response, threat intelligence, and vulnerability management.Relevant professional certifications such as CISSP, CISM, CISA, CEH, CompTIA Security+ or equivalent are highly desirable.Strong analytical, problem-solving, and communication skills.Ability to work independently with minimal supervision while managing multiple priorities.Unlock job insights
Salary match Number of applicants Skills match
Your application will include the following questions :
What\'s your expected monthly basic salary?Which of the following types of qualifications do you have?How many years\' experience do you have as an Information Technology Security Officer?Have you completed a Certified Information Systems Security Professional (CISSP) certification?How much notice are you required to give your current employer?#J-18808-Ljbffr