Cybersecurity & Compliance Analyst

MixWork Pte. Ltd.

Jakarta Selatan

On-site

IDR 360,000,000 - 600,000,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible Medical Benefit
Daily Allowances
Workstation Provisioning
Regional Ecosystem

Job summary

MixWork Pte. Ltd. seeks a Cybersecurity & Compliance Analyst to own internal security across Singapore and offshore IT environments.

You will manage the SOC partner, own security policy and awareness programs, and support the DPO function for PDPA and UU PDP obligations. The role involves guiding SOC partner outputs, reviewing reports, and ensuring security posture improvements land across all client systems and environments, with a focus on Azure, Purview, and M365 controls.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.
  • Minimum 4 years of IT security experience with policy, compliance, or security operations oversight.
  • Hands-on experience liaising with a third-party SOC or MSSP, including reviewing escalations.
  • Knowledge of Microsoft Azure and Microsoft 365 security controls (Entra ID, Purview, Defender for Endpoint, CA).
  • Familiarity with ISO 27001 framework: gap assessment, risk register, and control documentation.
  • Strong written English for incident reports and policy docs.

Responsibilities

  • Manage third-party SOC partner relationship: set monitoring requirements, review alerts, challenge findings, ensure SLA compliance.
  • Lead security policy ownership: review/update IT security policies and obtain sign-off.
  • Conduct ISO 27001 gap assessments and track remediation actions.
  • Support SaaS and vendor security assessments and provide go/no-go recommendations.
  • Design and deliver annual security awareness training and phishing simulations.
  • Manage Azure RBAC and PIM: quarterly access reviews, just-in-time activation, remediate over-privileged accounts.
  • Configure Conditional Access policies and maintain PDPA data handling requirements.
  • Produce monthly security posture reports across Microsoft 365.

Skills

Security policy oversight
Vendor management
Threat awareness

Education

Bachelor's degree in Cybersecurity, CS, or IT

Tools

Azure Entra ID
Microsoft Purview
Defender for Endpoint
Microsoft 365 security
SIEM concepts
CrowdStrike Falcon Spotlight
MDM integration

Job description

Role Summary

This role is client’s internal security owner for all cybersecurity and compliance matters across the group's Singapore and offshore IT environments. The Cybersecurity & Compliance Analyst manages the client's relationship with the third-party SOC partner, owns security policy and awareness programmes, and supports the Head of IT in his capacity as Data Protection Officer (DPO) under Singapore PDPA and Indonesia UU PDP obligations.

This is not a SOC analyst role. The candidate may not operate a SIEM console directly. Instead, they set security requirements for the SOC partner, review and challenge what the partner reports, and ensure that security posture improvements land across all client’s systems and environments.

Key Responsibilities
SOC Partner Management and Incident Response

Manage client’s third-party SOC partner relationship: set monitoring requirements, review escalated alerts, challenge the partner's findings where necessary, and ensure SLA compliance.

Receive and act on escalated security incidents from the SOC partner: direct containment actions, coordinate with affected teams, and produce incident reports for the Head of IT.

Conduct periodic reviews of the SOC partner's detection coverage and reporting quality; recommend adjustments to monitoring scope and escalation thresholds.

Security Policy Ownership

Own client’s IT security policy library: review policies at least annually, update them when systems or regulatory obligations change, and obtain sign-off from the Head of IT.

Conduct ISO 27001 gap assessments against client’s current security controls; track findings, assign remediation owners, and monitor closure.

Support SaaS and vendor security assessments: review new tools for data handling risks and provide a structured go / no-go recommendation to the Head of IT before onboarding.

Security Awareness and Phishing Programme

Design, schedule, and deliver client’s annual security awareness training programme for all staff; maintain training records.

Plan and execute biannual phishing simulation exercises; measure click-through and submission rates, report outcomes, and run follow‑up coaching for high-risk users.

Produce targeted awareness materials for specific risk areas (e.g. ransomware, social engineering, AI tool misuse) as new threats emerge.

Identity Governance and Data Protection Compliance

Manage Azure RBAC and Privileged Identity Management (PIM): conduct quarterly access reviews, enforce just‑in‑time admin activation, and remediate over‑privileged accounts.

Configure and maintain Conditional Access policies in Azure Entra ID: MFA enforcement, device compliance requirements, and location‑based access controls.

Manage Microsoft Purview: DLP policies, sensitivity labels, information barriers, and compliance reports relevant to PDPA and UU PDP data handling requirements.

Support the Head of IT (DPO) with PDPA compliance: maintain the Data Processing Agreement register, assist with DPIAs for new SaaS systems, and support data breach investigation and notification procedures.

Vulnerability Management and Reporting

Review vulnerability findings surfaced by CrowdStrike Falcon Spotlight across client’s endpoints; prioritise remediation based on risk, and track closure with asset owners.

Assess client’s current endpoint device estate and produce a recommendation to the Head of IT on Mobile Device Management (MDM) strategy, covering risk exposure, scope of enforcement, and implementation approach for both Singapore and offshore users.

Produce monthly security posture reports: open vulnerabilities and ageing, incident summary, access review outcomes, and Secure Score trends across Microsoft 365.

Required Qualifications & Experience

Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.

Minimum 4 years of IT security experience with demonstrated responsibility for security policy, compliance, or security operations oversight.

Hands‑on experience managing or liaising with a third‑party SOC or MSSP, including reviewing escalations and challenging vendor output.

Working knowledge of Microsoft Azure and Microsoft 365 security controls (Entra ID, Purview, Defender for Endpoint, Conditional Access).

Familiarity with ISO 27001 framework: gap assessment, risk register, and control documentation.

Good English for written incident reports, policy documentation, and regular communication with the Singapore Head of IT.

Technical Proficiency
Core (must be able to operate on day one)

Azure Entra ID: Conditional Access policies, PIM, Identity Protection, RBAC access reviews.

Microsoft Purview: DLP policy configuration, sensitivity labels, compliance manager.

Microsoft Defender for Endpoint: alert triage and endpoint security concepts; familiarity with MDM integration is an advantage.

Microsoft 365 security posture: Secure Score interpretation, tenant‑level security settings.

Security policy drafting and review: structured policy documents aligned to ISO 27001 or NIST CSF.

Working Knowledge (enough to review and challenge partner output)

SIEM concepts: understanding alert logic, detection rules, and escalation thresholds sufficient to hold a SOC partner accountable.

CrowdStrike Falcon Spotlight: vulnerability prioritisation and remediation tracking.

Endpoint security concepts: EDR, device compliance baselines, patch management.

Nice to Have

SC-200 (Microsoft Security Operations Analyst Associate), AZ-500, CISSP, or CISM certification.

Singapore PDPA compliance experience or equivalent data protection regulatory exposure.

Experience running phishing simulations with measurable outcomes.

SaaS or retail environment security assessment experience.

Statutory Provisions & Compliance

Full Legal Compliance: Official employment contract managed under MixWork Indonesia, ensuring complete adherence to local labor laws and employment standards.

Healthcare & Social Security: Full registration and contributions for both BPJS Kesehatan and BPJS Ketenagakerjaan to ensure comprehensive coverage.

Religious Holiday Allowance: Guaranteed annual mandatory Religious Holiday Allowance (THR) paid in accordance with statutory government regulations.

What We Offer
  • Flexible Medical Benefit: Comprehensive healthcare coverage fully inclusive of dental, optical, outpatient care, and wellness treatments to support your overall well-being.
  • Daily Allowances: Competitive transportation and meal allowances to support your operational needs.
  • Workstation Provisioning: High-performance corporate laptop and necessary technical equipment provided.
  • Regional Ecosystem: Access to ongoing global corporate alignment, dedicated HR support, and a stable, creative career trajectory with a premier international brand.

Language Requirement: As this is an international role, please note that all screenings and interviews will be conducted exclusively in English.

Equal Opportunity Employer: MixWork is committed to creating an inclusive, diverse, and fair workplace culture. We value talent and capability above all else, completely free from discrimination or bias.

Your application will include the following questions:

  • Which of the following statements best describes your right to work in Indonesia?
  • Do you have experience using Microsoft Azure?
  • How many years' experience do you have as a Microsoft 365 Administrator?
  • Do you have experience using Microsoft Defender?
  • Have you worked in a role which requires a sound understanding of ISO 27001?
  • How many years' experience do you have as an Endpoint Security Engineer?
  • Have you worked in a role which requires a sound understanding of PDPA?
  • What's your expected monthly basic salary?
  • How much notice are you required to give your current employer?
  • Have you completed an English language proficiency certification?
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud & Network Infrastructure
Cloud & Network Infrastructure

MixWork Pte. Ltd. • Jakarta Utara

On-site
IDR 350,000,000 - 550,000,000
Flexible Medical Benefit
Daily Allowances
Workstation Provisioning
+1
Infrastructure Analyst (MS365 & Azure Cloud)
Infrastructure Analyst (MS365 & Azure Cloud)

Glints • Batam

On-site
IDR 180,000,000 - 320,000,000
Regional Protective Services Manager ASEAN
Regional Protective Services Manager ASEAN

Accenture Southeast Asia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Regional Protective Services Manager ASEAN
Regional Protective Services Manager ASEAN

Accenture • Jakarta Pusat

On-site
IDR 800,000,000 - 1,200,000,000
Cybersecurity & Compliance Program Lead (PDPA/DPO)
Cybersecurity & Compliance Program Lead (PDPA/DPO)

MixWork Pte. Ltd. • Jakarta Selatan

On-site
IDR 360,000,000 - 600,000,000
Flexible Medical Benefit
Daily Allowances
Workstation Provisioning
+1
AI / Agent Engineer
AI / Agent Engineer

MixWork Pte. Ltd. • Jakarta Pusat

Hybrid
IDR 4,800,000,000 - 7,000,000,000
Flexible Medical Benefit
Daily Allowances
Workstation Provisioning
+1
Microsoft Security Consultant - Jakarta - Global IT Solutions Company
Microsoft Security Consultant - Jakarta - Global IT Solutions Company

PT Adecco Personnel Indonesia • Jakarta Utara

On-site
IDR 180,000,000 - 480,000,000
Associate - Risk Assurance - IT Cybersecurity (Talent Pool)
Associate - Risk Assurance - IT Cybersecurity (Talent Pool)

PwC • Daerah Khusus Ibukota Jakarta

On-site
IDR 120,000,000 - 180,000,000
ICT Security Supervisor
ICT Security Supervisor

PT Maybank Indonesia Finance • Jakarta Pusat

On-site
IDR 360,000,000 - 480,000,000
Associate, Cybersecurity / Information Security
Associate, Cybersecurity / Information Security

PT TRS Forensics Indonesia • Jakarta Pusat

On-site
IDR 18,000,000 - 30,000,000