Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).
Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.
...
Audio Visual Systems
AI Security
Technical Sales
Client Relationship
Product Demonstration
System Design
Troubleshooting
Proposal Writing
Negotiation Skills
Communication Skills
Problem Solving
Project Management
Collaborate with the sales team to understand client needs and provide tailored solutions.
Conduct product demonstrations and technical presentations to prospective clients, showcasing the security solutions’ features, functionality, and business benefits.
Assist in creating sales proposals, RFP (Request for Proposal) responses, and technical documentation.
...
Collaborate with the sales team to understand client needs and provide tailored solutions.
Conduct product demonstrations and technical presentations to prospective clients, showcasing the security solutions’ features, functionality, and business benefits.
Assist in creating sales proposals, RFP (Request for Proposal) responses, and technical documentation.
...
Develop and implement cybersecurity strategies, governance frameworks, risk management approaches, standards, and best practices across the organisation.
Lead the organisation’s ISMS (ISO/IEC 27001) implementation programme, including risk assessment, gap analysis, documentation, internal audit coordination, and readiness for certification and recertification.
Lead and coordinate cybersecurity operations activities, including security monitoring, vulnerability management, threat intelligence, and incident response escalation to ensure the organisation is equipped with proactive and updated security operations that can detect, prevent, and respond to cyber threats effectively.
...
Monitor the aspects of the network, security, patch management, and end-point protection technology trend and stay on the top of the latest technological progress to make the best for business recommendations.
Strategizes network and security refreshment exercise taking into consideration business needs, user productivity, and device performance matters for the preparation of AOP.
Collaborates with internal stakeholders to gather IT requirements and to ensure that post-live operations, maintenance and support are incorporated.
...
Cloud & Infrastructure Strategy: Architect and implement cloud-based solutions aligned with business goals, ensuring consistency and cost-efficiency. Collaborate across teams to drive a standardized, modernized cloud infrastructure roadmap with a unified operating model
Solution Delivery & Support: Develop and support IT infrastructure solutions with high availability, scalability, and performance as well as act as a Level 3/4 subject matter expert for server and cloud-related issues
Infrastructure Protection (hybrid): Maintain IT security architecture standards, monitor risks, and implement security measures to ensure adherence to security control requirements, manage change processes, and enforce policies to mitigate cyber threats. Define and enforce server/cloud standards and processes aligned with best practices
...
Working as liaison between vendors and the Company
Providing specialized consultative service and implementing, driving and maintaining vendor programs, marketing, and training; review and negotiate terms of vendor contracts and communicate with vendors regarding day-to-day matters
Building and maintaining positive relationships with vendors
...
Validate and support deployment of Microsoft Defender for Endpoint (MDE), ensuring protection, EDR, and hardening requirements are met.
Assist in planning, deploying, and maintaining Microsoft Intune policies for secure device management, compliance enforcement, and configuration baselines.
Support integration and continuous improvement of Intrusion Prevention Systems (IPS) across on‑premises and cloud network environments.
...
Monitor, review and respond to alerts generated from the various security detection tools and case management systems in accordance with established service level agreements and objectives (SLA & SLO) .
Recommend triage actions and maintenance of runbooks and playbooks.
Investigate and escalate security incidents based on the severity level for each event/incident within SLA & SLO.
...
Monitor and report on all security related alerts, incidents and breaches and provide assistance in the investigation and resolution of security incidents, when required
Investigate phishing/spam emails reported by users.
Produce monthly security reports for the clients.
...
Validate and support deployment of Microsoft Defender for Endpoint (MDE), ensuring protection, EDR, and hardening requirements are met.
Assist in planning, deploying, and maintaining Microsoft Intune policies for secure device management, compliance enforcement, and configuration baselines.
Support integration and continuous improvement of Intrusion Prevention Systems (IPS) across on‑premises and cloud network environments.
...
Validate and support deployment of Microsoft Defender for Endpoint (MDE), ensuring protection, EDR, and hardening requirements are met.
Assist in planning, deploying, and maintaining Microsoft Intune policies for secure device management, compliance enforcement, and configuration baselines.
Support integration and continuous improvement of Intrusion Prevention Systems (IPS) across on‑premises and cloud network environments.
...
Consulting on current trends in the methodological and technical assessment of IT security requirements
Regular analysis of the threat landscape in the IT security environment and review of regulatory requirements and methodologies with regard to information security (e.g., KRITIS, ISO 27001, ISO 27005)
Responsibility for continuous monitoring of the IT security level, assessment of threat potentials and residual risks, and development of corresponding recommendations for action
...
Monitor and report on all security related alerts, incidents and breaches and provide assistance in the investigation and resolution of security incidents, when required
Investigate phishing/spam emails reported by users.
Produce monthly security reports for the clients.
...
Perform vulnerability assessments, penetration testing and red teaming on a wide range of technologies including but not limited to Network, Web, Mobile, Thick Client Applications, Cloud, and Operations Technology.
Develop internal VAPT and red team capabilities through scripting, automation, and hands-on research into the latest exploitation tactics, techniques, and procedures (TTPs) of various threat actors.
Participate in providing training and consultancy to client.
...
Senior Security Engineer (Data Loss Prevention) will be responsible to manage, tune and expand the global Data Loss Prevention service that protects ZEISS information assets across cloud, endpoint, email, and collaboration platforms using Microsoft Purview. The engineer will also provide escalation support and resolution for complex incidents that cannot be resolved at the L2 level to ensure reliable and compliant service delivery in collaboration with internal stakeholders and external providers.
Primary duties and responsibilities :-
DLP Lifecycle Management: Manage the end-to-end lifecycle of DLP policies across Endpoint, Exchange, SharePoint, OneDrive, and Teams using Microsoft Purview.
...
Working as liaison between vendors and the Company
Providing specialized consultative service and implementing, driving and maintaining vendor programs, marketing, and training; review and negotiate terms of vendor contracts and communicate with vendors regarding day-to-day matters
Building and maintaining positive relationships with vendors
...
Lead impactful engagements that help organizations strengthen governance, manage technology risks, and enhance regulatory compliance.
Work with diverse clients across industries on emerging technology risk areas, including AI, Cloud Computing, Blockchain, IoT, cybersecurity, and resilience.
Partner directly with Directors and senior stakeholders, gaining exposure to strategic decision-making and executive-level advisory work.
...
Develop, maintain, and operationalise the GRC framework, including policies, standards, and procedures across IT, information security, and broader operational risk domains.
Ensure governance documentation is current, version-controlled, and aligned with relevant regulatory and industry standards (e.g., Securities Commission's GTRM, ISO 27001, NIST CSF, PDPA).
Drive adoption of policies through training, communication, and stakeholder engagement.
...
Develop, maintain, and operationalise the GRC framework, including policies, standards, and procedures across IT, information security, and broader operational risk domains.
Ensure governance documentation is current, version-controlled, and aligned with relevant regulatory and industry standards (e.g., Securities Commission's GTRM, ISO 27001, NIST CSF, PDPA).
Drive adoption of policies through training, communication, and stakeholder engagement.
...
Preparing Situational Security Awareness materials. Assist to develop targeted security awareness content to educate employees on emerging cyber threats, security risks and best practices.
Supporting in validating evidence from BU for GPRA, TPRM, ITRA, and other assessments.
Assist with any Group/local project or initiatives by providing support in the implementation and coordination aspects.
...