Partner with engineering teams to review application designs and implementations, identifying security risks and working collaboratively to address them
Contribute to and evolve our Secure SDLC processes, ensuring security is embedded into how we build and deliver software
Perform application security reviews across a range of technologies and services
...
Coordinate and manage application penetration testing activities including scoping, scheduling, evidence collection, vendor coordination, report review, retest tracking, and closure validation to ensure testing outcomes are thorough and actionable.
Conduct or support technical security assessments for web, Application Programming Interface (API), mobile, cloud-hosted, and enterprise applications using manual testing and automated tools, delivering findings that drive meaningful risk reduction.
Own application vulnerability tracking from discovery through to remediation, ensuring findings are categorized by severity, affected application, owner, risk, due date, and closure status to maintain full visibility and accountability.
...
Regional Security Blueprinting: Establish unified security architecture patterns that harmonize Bank Negara Malaysia (BNM) RMiT requirements with MAS (Singapore), NBC (Cambodia), SBV (Vietnam), and HKMA (Hong Kong) regulations.
App-Layer Strategy (Primary): Design the strategic security architecture for Open Banking, API orchestrations, and the HLB digital core. Define standards for end-to-end payload encryption and regional identity federation.
Cross-Border Data Strategy: Design the architectural guardrails for regional data flows, ensuring cross-border privacy compliance and localized data residency requirements.
...
Install, configure, and manage enterprise security platforms such as next generation firewalls, endpoint protection systems, network access controls, and data loss prevention (DLP) solutions.
Maintain the stability and security of system infrastructure through patch management, policy tuning, and system upgrades.
Manage security infrastructure projects from planning to deployment while ensuring compliance with internal policies and risk requirements.
...
Lead discovery, requirements analysis, architecture, and solution-design activities across Microsoft Defender XDR and Microsoft Purview.
Design integrated Microsoft Defender XDR solutions covering Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, and Microsoft Defender for Cloud Apps.
Design Microsoft Purview solutions covering Information Protection, Data Loss Prevention, Insider Risk Management, Communication Compliance, Data Lifecycle Management, Records Management, eDiscovery, and Audit.
...
Regional Security Blueprinting: Establish unified security architecture patterns that harmonize Bank Negara Malaysia (BNM) RMiT requirements with MAS (Singapore), NBC (Cambodia), SBV (Vietnam), and HKMA (Hong Kong) regulations.
App-Layer Strategy (Primary): Design the strategic security architecture for Open Banking, API orchestrations, and the HLB digital core. Define standards for end-to-end payload encryption and regional identity federation.
Cross-Border Data Strategy: Design the architectural guardrails for regional data flows, ensuring cross-border privacy compliance and localized data residency requirements.
...
Lead and execute security transformation initiatives for enterprise clients, focusing on AI security, cloud security, application security, and vulnerability management.
Proficiency in writing code, scripting and automation (e.g., Python, PowerShell, Bash) to streamline investigations.
Serve as a primary client-facing security expert, building strong relationships and effectively communicating complex technical concepts to both technical and non-technical stakeholders.
...