Job Description
We value our people and encourage everyone to grow professionally. If you think this opportunity is right for you, we encourage you to apply!
Cybersecurity Architecture & Strategy
- Define and maintain enterprise cybersecurity architecture across IT, OT, and cloud environments.
- Establish security design standards, principles, and reference architectures.
- Act as the technical authority for security architecture designs, control implementations & cybersecurity technology selection
- Ensure all systems and initiatives are secure-by-design and aligned with business and risk requirements.
- Lead cybersecurity transformation initiatives from strategy through delivery.
Security Engineering & Technology Management
- Own the full lifecycle of cybersecurity technologies starting from technology evaluation, procurement, deployment, optimization, and retirement.
- Manage key security platforms including:
- SIEM / SOC
- Endpoint Security (AV, EDR, XDR)
- PAM (implementation and operations)
- DLP and data security
- Network and cloud security solutions
- Zero Trust and secure access technologies
- Ensure solutions are scalable, integrated, and optimized for operational effectiveness.
- Define engineering standards, implementation patterns, and system integrations.
Application & Cloud Security
- Integrate security into SDLC and DevSecOps practices.
- Oversee application security testing (SAST, DAST, penetration testing).
- Manage cloud security posture, including identity, access control, encryption, and configuration management.
Security Operations & Incident Response
- Lead and manage Security Operations Center (SOC), whether internal or MSSP-based.
- Oversee threat monitoring and detection, incident response and containment and cyber investigation and root cause analysis
- Establish and maintain incident response plans, playbooks, and escalation procedures.
- Ensure timely remediation and recovery to minimize business impact.
Cyber Analytics & Investigation Execution
- Operate and optimize SIEM, threat intelligence, and security analytics platforms.
- Conduct detailed cyber investigations in accordance with forensic and evidentiary requirements.
- Produce incident reports, lessons learned, and corrective improvement actions.
Delivery & Vendor Management
- Deliver cybersecurity initiatives and projects within scope, timeline, and budget.
- Manage MSSPs and security vendors from an operational and service delivery perspective.
- Monitor SLA/KPI performance and ensure service effectiveness and value realization.
Strategic Planning & Continuous Improvement
- Define and maintain the cybersecurity technology roadmap aligned with business strategy.
- Monitor emerging threats, vulnerabilities, and technology trends.
- Drive continuous improvement in detection and response capabilities, automation and operational efficiency and cyber resilience and maturity
- Support long-term planning, investment prioritization, and capability development.
Education / Professional Qualification
- Bachelor’s or master’s degree in Cybersecurity, Information Technology, Computer Science, or related field.
- Cybersecurity certifications CISM, CRISC, CISSP, CCSK.
Professional Experience
- Minimum 10–12 years of experience in cybersecurity, including leadership, governance, and project delivery roles.
- Knowledge of cybersecurity frameworks, standards, and regulatory requirements relevant to Malaysia (PDPA, Bank Negara, ISO 27001) and the plantation/industrial sector.
- Proven experience in executive-level risk assessment, governance, and successful project delivery.
- Strong coordination, stakeholder management, and decision-making skills.
- Excellent analytical, problem-solving, and strategic thinking abilities.
To apply, please submit your resume and cover letter outlining your interest for this role.