Certification: Active OSCP certification is mandatory. Candidates without a valid OSCP or an equivalent hands-on certification (e.g., OSEP, CPTS) will not be considered.
Experience: 5+ years in offensive security, penetration testing, or vulnerability management.
Autonomy: Proven track record of building security processes from scratch in environments where they were the sole security expert.
...
The Network Security Department is responsible for protecting the organisation’s network infrastructure from cyber threats while ensuring availability, performance, and compliance. The department works at the intersection of network engineering and cybersecurity, implementing security controls across on premises, cloud, and hybrid environments.
The team designs, deploys, and operates network security technologies such as firewalls, intrusion prevention systems, secure access solutions, and network monitoring tools. In close partnership with the Network Engineering and Cybersecurity teams, the department proactively identifies vulnerabilities, remediates security findings, and continuously improves the organisation’s overall security posture.
...
Assess security practices across the Software Development Lifecycle.
Participate in application design, architecture, and data flow reviews for new and existing systems.
Perform secure code reviews to identify vulnerabilities such as injection flaws, authentication weaknesses, insecure data handling, exposed secrets, and insecure API usage.
...
Plan, execute, and manage risk-based audit assignments as outlined in the Audit Plan, ensuring adherence to approved objectives, scope, and Audit Methodology standards
Monitor audit progress to ensure completion within budgeted timelines, manpower resources, and cost allocation
Review draft audit findings, root causes, and recommendations to ensure relevance and accuracy before discussion with line management
...
P&L Ownership : Own the profitability of Digital Safety and Protection services by tracking performance metrics, managing budgets, and achieving financial targets
Customer Engagement : Promote activation and consistent usage of safety products, ensuring seamless integration into customers’ lives
Issue Resolution : Oversee customer escalations, improving resolution times and reducing complaint volumes
...
Maintaining of security solution including Splunk, Imperva and etc. (Task including compliance to patch and obsolescence framework requirement, UAMR etc.)
Ensure events / logs from all relavant devices are sending to SIEM solution in a complete and accurate manner
To produce monthly SIEM system health report (completeness and accurate)
...
Assess security practices across the Software Development Lifecycle.
Participate in application design, architecture, and data flow reviews for new and existing systems.
Perform secure code reviews to identify vulnerabilities such as injection flaws, authentication weaknesses, insecure data handling, exposed secrets, and insecure API usage.
...
Set the overall direction by formulating and executing a comprehensive Group IT Security strategy for RHB Banking Group (including regional offices), ensuring a secure, resilient, and risk‑minimised IT environment that supports business objectives and complies with all applicable regulatory, legal and industry requirements.
The role is accountable for Group‑wide cyber security governance, technology controls, incident readiness, and security culture, while providing strategic advisory to the Board, senior management and regulators.
Define, own and continuously evolve the Group IT Security strategy, roadmap, and target maturity model, aligned with business priorities and regulatory expectations
...
Access Governance: Establish and govern a comprehensive access control baseline by reviewing and granting access authorities based on approved User Access Matrices (UAM). Ensure strict adherence to the Principle of Least Privilege across all environments and critical systems.
Privileged Access: Enforce strict governance over super-user and privileged accounts by ensuring IDs are split, lodged securely, and that all usage is properly documented, controlled, and reviewed to prevent abuse of administrative powers.
Compliance: Act as the primary coordinator for the periodic review of User Access Matrix (UAM)and User ID listings with Business Owners/Departments to ensure ongoing compliance. Execute annual Security Risk and Control Self-Assessments (RCSA) to identify gaps and enforce control effectiveness.
...
Conduct security patrols: Monitor interior and exterior hotel premises to identify and address safety and security risks, security threats, and undesirable conditions
Support emergency responses: Coordinate responses to incidents such as fires, medical emergencies, and security threats
Supervise and develop the team: Train, schedule, and supervise Security Guards/Officers, providing guidance and support to ensure high performance
...
Manage nationwide physical security operations for technology buildings, covering perimeter security, assets, guards, equipment, vendors, and related services.
Monitor and ensure consistency of security operations in compliance with Ministry of Home Affairs regulations and internal policies.
Manage, control, and review security vendors to ensure service delivery meets SLA requirements and CelcomDigi policies, while maintaining zero downtime of security systems that may impact business operations.
...
Validate and support deployment of Microsoft Defender for Endpoint (MDE), ensuring protection, EDR, and hardening requirements are met.
Assist in planning, deploying, and maintaining Microsoft Intune policies for secure device management, compliance enforcement, and configuration baselines.
Support integration and continuous improvement of Intrusion Prevention Systems (IPS) across on‑premises and cloud network environments.
...
Lead the delivery of ICT and security workstreams throughout the data centre construction lifecycle, from design and procurement through installation, testing, and commissioning.
Manage the implementation of physical security technologies, including Access Control Systems (ACS), CCTV, Perimeter Intrusion Detection Systems (PIDS), Visitor Management Systems (VMS), and Security Operations Centre (SOC) integrations.
Coordinate closely with clients, consultants, general contractors, M&E teams, vendors, and commissioning teams to ensure timely project delivery.
...
Strategic and Big-Picture Thinker : Able to see long-term partnership value beyond short-term gains and connect partnerships to overall business strategy and identify scalable growth opportunities
Strong Business Acumen: With strong commercial mind and understands different revenue models, cost, margin, pricing and ROI and able to negotiate for a win-win mindset
Execution-Driven and Operationally Strong : Translates strategy into clear, actionable plans, including driving partnerships from engagement, negotiation to contract signing and product delivery to the market
...
Lead the delivery of ICT and security workstreams throughout the data centre construction lifecycle, from design and procurement through installation, testing, and commissioning.
Manage the implementation of physical security technologies, including Access Control Systems (ACS), CCTV, Perimeter Intrusion Detection Systems (PIDS), Visitor Management Systems (VMS), and Security Operations Centre (SOC) integrations.
Coordinate closely with clients, consultants, general contractors, M&E teams, vendors, and commissioning teams to ensure timely project delivery.
...
Lead or assist in Information Security audits and Risk Management initiatives using frameworks such as PCI DSS, ISO 27001, NIST, COBIT, and others, including scoping, evaluation, testing, reporting, and issue follow-up.
Conduct audits and risk assessments across various processes, technologies, and platforms, including UNIX, Windows, DBMS (SQL, Oracle, DB2), Active Directory, AS/400, and network infrastructures.
Identify technology risks and recommend appropriate controls based on risk level, business requirements, and implementation feasibility.
...
Work closely with our sales team to understand clients' network security needs and recommend appropriate solutions
Provide technical expertise and support during the pre-sales process, including product demonstrations, proof of concepts, and responding to technical inquiries
Stay up-to-date with the latest advancements in network security and apply this knowledge to the pre-sales process
...
Work closely with our sales team to understand clients' network security needs and recommend appropriate solutions
Provide technical expertise and support during the pre-sales process, including product demonstrations, proof of concepts, and responding to technical inquiries
Stay up-to-date with the latest advancements in network security and apply this knowledge to the pre-sales process
...