jobs in Air Selangor

Kerja Sepenuh Masa, Associate I (Cybersecurity Testing and Assurance), Cybersecurity, Information Technology (Executive) di Air Selangor Federal Territory - Maukerja

Associate I (Cybersecurity Testing and Assurance), Cybersecurity, Information Technology (Executive)

KL City, Federal Territory

Kongsi
Simpan

Lokasi Kerja

  • Kuala Lumpur Federal Territory Malaysia

Penerangan Kerja

Tanggungjawab

JOB SUMMARY

  • This role supports the organization's cybersecurity assessment and testing activities by evaluating the effectiveness of cybersecurity controls, coordinating security testing initiatives, identifying security weaknesses, and monitoring remediation activities.
  • The role is responsible for supporting vulnerability management, penetration testing, cybersecurity assessments, cyberresilience testing, and assurance reporting activities. It also assists in preparing management reporting, coordinating remediation efforts, and collaborating with stakeholders to strengthen the organization's cybersecurity posture and resilience.


KEY DUTIESAND RESPONSIBILITIES

Main roles and responsibilities

Vulnerability Management & Security Testing

  • Conduct or coordinate vulnerability assessments, penetration testing, and other cybersecurity testing activities, either internally using approved tools or through external service providers where appropriate.
  • Review and assess identified vulnerabilities and security weaknesses, including remediation plans and risk ratings.
  • Monitor remediation progress, validate closure of findings, and escalate overdue corrective actions where necessary.
  • Drives continuous improvement of vulnerability management and security testing processes.

Cybersecurity Assessments & Reviews

  • Conduct cybersecurity assessments and reviews of systems, applications, technologies, and processes.
  • Evaluate cybersecurity controls against organizational requirements, standards, and industry best practices.
  • Identify security gaps, weaknesses, and opportunities for improvement, and provide recommendations to relevant stakeholders.
  • Support security reviews of new technologies, projects, and selected third-party engagements.

Cybersecurity Control Validation

  • Review and validate the implementation and effectiveness of cybersecurity controls through assessments, testing activities, and evidence reviews.
  • Verify remediation actions implemented by control owners to address identified findings.
  • Support the development of cybersecurity metrics, dashboards, and assurance reports.
  • Identify recurring control weaknesses and recommend improvement initiatives.

Cyber Resilience Testing

  • Coordinate cyber drill simulations, tabletop exercises, and cyber resilience testing activities.
  • Document observations, lessons learnt, and improvement actions arising from testingexercises.
  • Monitor implementation and closure of corrective actions resulting from resilience testing activities.

Reporting & Assurance

  • Prepare assessment reports, vulnerability dashboards, testing summaries, and management updates.
  • Maintain accurate records of findings, testing activities, evidence and remediation status.
  • Support audit, regulatory, and governance reporting requirements relating to cybersecurity assessments and testing activities.

Collaboration & Advisory

  • Collaborate with internal and external stakeholders, including Infrastructure, Network, Cloud, Application, Operational Technology, and third-party service providers, to support cybersecurity assessments, testing activities, and remediation efforts.
  • Provide recommendations on remediation priorities and security improvements arising from assessments and testing activities.
  • Work closely with Policy, Compliance, Risk, and business functions to strengthen organisational cybersecurity capabilities and resilience.


Other roles and responsibilities:

(Do not delete, mandatory to carry out these roles and responsibilities)

Compliance with ISO Clause5.3 Organisational roles, responsibilities and authority

  • Always adhere to Air SelangorIntegrated Management System (AIMS) and HSE policy and involvement in implementing the Management System.
  • Ensure the objective/KPI are established in line with the Company's contexts, strategic direction, and purpose.
  • Aware, understand and manage key risks, hazards, and aspects of your work activities.
  • Acknowledge your right not to conduct any work deemed to be harmful to your health and safety
  • Aware and understand your roles and responsibility to provide support during the execution of Emergency Response Plan (ERP) and Business Continuity Plan (BCP) during crisis/emergency, ensuring the continuation of water supply to the consumer at highest quality and providing the best service and customer experience.
  • Aware and understand the asset criticality in the operational activities and ensure all assets are maintained in good working conditions.
  • Aware and understand the confidentiality, availability, and integrity of information assets under your custodian.
  • Aware and understand the whistle-blower policy and carry out daily job activity with full integrity
  • Practice SACRED personality while carrying out daily job activity, which includes:
  • Safety Conscious
  • Agile
  • Creative
  • Reliable
  • Efficient
  • Digitally driven


Minimum Qualifications

  • Bachelor’s degree in Cybersecurity, IT, Information Systems or equivalent technical or professional qualification.
  • 3 to 7 years of relevant cybersecurity experience, preferably covering the majority of the key duties and responsibilities described in this role.
  • Interpersonal skills: open minded, ability to operate within business organizations through social communication and interactions.
  • Problem solving skills: Can get to the root of the problem, objectively identify, analyze and solveproblems that means being solution oriented.
  • Communication skills: Ability to express clear articulate and encourage open communication. Effective interpersonal presentation and interpersonal skills.
  • Listening skills: Patient and attentive.
  • Public Relations skills: Project and market positive proactive image of the team.
  • Collaboration skills: Build close relationships with all levels and a strong team player


Cybersecurity Expertise:

  • Knowledge of vulnerability management, penetration testing, cybersecurity assessments, control validation, and remediation management practices.
  • Familiarity with security assessment methodologies, vulnerability scanning tools, penetration testing approaches, and remediation tracking processes.
  • Understanding of cybersecurity controls across infrastructure, cloud, applications, identity management, and operational technology environments.
  • Exposure to Operational Technology (OT) environments and relevant certifications such as CEH, CPENT, Security+, PenTest+, CISM, CRISC or equivalent are an advantage but not mandatory.
  • Risk & Analytical Skills: Capable of identifying, assessing, and analyzing cybersecurity risks, gaps, and trends; provide actionable recommendations.
  • Regulatory Knowledge: Understanding of cybersecurity and data protection laws, with the ability to support compliance efforts.
  • Personal Attributes: High integrity, detail-oriented, proactive, adaptable, and capable of critical thinking in complex environments.

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut