Experience: 8+ years in cybersecurity, technical risk, or IT audit, with 2+ years of direct team leadership, supervisory, or line management experience in a complex enterprise environment.
If you are looking to excel and make a difference, take a closer look at us…
Experience: 8+ years in cybersecurity, technical risk, or IT audit, with 2+ years of direct team leadership, supervisory, or line management experience in a complex enterprise environment.
...
Consulting on current trends in the methodological and technical assessment of IT security requirements
Regular analysis of the threat landscape in the IT security environment and review of regulatory requirements and methodologies with regard to information security (e.g., KRITIS, ISO 27001, ISO 27005)
Responsibility for continuous monitoring of the IT security level, assessment of threat potentials and residual risks, and development of corresponding recommendations for action
...
Act as level 1 & level 2 Analyst for all security-related events, alerts, and incidents
Be responsible to monitor, analyse, triage, and escalate security incidents as part of 24x7x365 security operations
Provide first and second line response to security incidents (malware infections, unauthorized access, malicious codes/emails, Distributed Denial of Service (DDoS) attacks)
...
Perform vulnerability assessments and penetration tests (mostly web applications and networks), source code reviews, configuration reviews, and other information security consulting services.
Work in a hybrid arrangement — some projects require onsite work (mostly within KL/Selangor), while others allow remote work.
Produce reports documenting security vulnerabilities and recommendations to fix them, written in a clear and actionable manner.
...
Architecture & Design Reviews: Evaluate application architectures and cloud/on-premise deployment patterns against enterprise security standards to ensure alignment with Security & Privacy by Design principles.
Threat Gap Identification: Conduct threat modeling and risk assessments to identify technical vulnerabilities, architectural flaws, and control gaps early in the application lifecycle.
Risk Assessment & Impact Analysis: Quantify and document technical, operational, and business risks associated with system changes, third-party integrations, and new technology deployments.
...
Define methodology, conduct security assessments, and address any findings by supporting solution implementation to develop segmented infrastructure that includes various IoT/OT technologies and models best practices.
Identify and effectively communicate IoT/OT architectural vulnerabilities with supporting risk statements and realistic mitigation options to stakeholders.
Support and manage the Group OT Security programme deployment within the APAC region
...
A Global IT Support Organization, delivering enterprise services that comprise of end-to-end lifecycle of IT identity and access provisioning and a single request process that enables end-users to utilize roles aligned to their job on the day the access is required for use, recertified as required, fully auditable and revoked if access is no longer required
Functionally accountable to Team Lead, Global Access Administration or Regional Manager, Global Access Administration (AMER, APAC, EMEA)
Responsible for providing support to all clients which includes employees, contractors and business partners which requires working with Abbott personnel at all levels.
The Global Access Administration organization has a global charter that is principally responsible for ensuring proper control of access to Abbott IT and data assets for enterprise computer platforms and applications on a global, regional, divisional and local basis.
...
Functionally accountable to Team Lead, Global Access Administration or Regional Manager, Global Access Administration (AMER, APAC, EMEA)
Responsible for providing support to all clients which includes employees, contractors and business partners which requires working with Abbott personnel at all levels.
The Global Access Administration organization has a global charter that is principally responsible for ensuring proper control of access to Abbott IT and data assets for enterprise computer platforms and applications on a global, regional, divisional and local basis.
...
Establish and maintain appropriate relationships with customers, enabling the company to be active & leading, speedy response time, highly profitable, excellent payment collection position at all time.
External communication with customers, consultants, general contractor, supervision, design institute and other construction units, manage site activities to ensure compliance to quality standards.
Internal communicate and work closely with sales, engineering, project engineer, procurement and other departments to ensuring the overall company objectives/performance is achieved.
...
Hold the board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.
Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.
Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
...
The Active Defense Center is responsible for the early and effective detection and prevention of attacks on the bank's data integrity and information security in the exciting environment of Cyber Security. We achieve this together with our 3 existing ADC locations in Singapore, Frankfurt and New York together with our new 24/7 first level SOC in KL. We are responsible for the detection and proactive defense against cyber-attack scenarios and actively define and manage the implementation and configuration of appropriate security measures.
In the first level SOC you will be responsible for monitoring our core SIEM tool Google Chronicle as well as MS-Defender and VectraAI. Based on pre-defined playbooks you will initiate response measures as well as document and track incidents in ServiceNowSecOps. In addition, you will provide comprehensive reports on Cyber incidents. Further you will monitor external information sources on upcoming vulnerabilities and available patches and create internal patch advisories for distribution into the Bank. You are characterized by a high level of flexibility and commitment and a basic understanding of Cyber security topics.The role also includes the participation in task forces to respond to cyber threats.
Studies or equivalent training with a focus on information and Cyber security
...
Monitor, review and respond to alerts generated from the various security detection tools and case management systems in accordance with established service level agreements and objectives (SLA & SLO) .
Recommend triage actions and maintenance of runbooks and playbooks.
Investigate and escalate security incidents based on the severity level for each event/incident within SLA & SLO.
...
Establish, maintain, and enforce cloud security policies, standards, and governance frameworks to ensure secure cloud adoption across the organization.
You will manage one of the EIS sub-services workstreams: Endpoint Security, Internet Security, Corporate Data Loss Prevention, and Enterprise Application Security.
You will lead and collaborate on cross-functional projects including vulnerability management, shadow IT, data leakage prevention etc.
You will enforce security policy and controls to protect our corporate environment, yet enabling business by triaging exceptions via balancing the benefit and trade-offs between security and operations.
...
As a Network Security Engineer (Firewall) you will work in a team focused on network-security related services. The primary focus of a network-security engineer is technical.
You would be responsible for implementing and operating network-security related services together with other members of your team. These tasks include security policy implementation on firewall devices, lifecycle-management, participation in firewall upgrades and changes related to the infrastructure.
Administration of Firewall, Site to Site VPN and SSL Interception environment
...
Implement security solutions and manage security operations center to keep client’s business and assets secure. Deploy digital identity, platform security, data & AI protection, cloud security solutions to achieve continuous protection involving onshore, nearshore and offshore capabilities.