Cloud Security Manager

StarHub

Petaling Jaya

Hybrid

MYR 240,000 - 360,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance

Job summary

StarHub is seeking a Cloud Security Manager to lead the organization’s cloud security posture across architectures, governance, and operations. You will work with Cloud Engineering, DevOps, and Cybersecurity to embed security-by-design in cloud deployments.

The role covers governance, architecture, operations, and regulatory compliance, with leadership across security tools and services to drive continuous improvement.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related field; Master’s degree is a plus.
  • 5-10 years of cybersecurity experience, with at least 3+ years focused on AWS cloud security and cloud security architecture.
  • Strong expertise in AWS security services and cloud-native security design.
  • Hands-on experience in cloud security architecture, DevSecOps, and IaC (Terraform, CloudFormation).
  • Proven ability to implement IAM governance, encryption, network security, and secure cloud design principles.
  • Experience with cloud compliance frameworks and audits (ISO 27001, SOC 2, CIS, MAS TRM, NIST).
  • Strong leadership and communication skills; capable of coordinating security initiatives with multi-disciplinary teams.

Responsibilities

  • Cloud Security Governance & Strategy: develop and maintain AWS security policies and frameworks; enforce Well-Architected, CIS, and Zero Trust.
  • Cloud Security Architecture & Engineering: design secure AWS architectures; govern IAM (RBAC, least privilege, automated remediation); oversee network security controls.
  • Cloud Security Operations, Monitoring & Incident Response: manage monitoring, vulnerability remediation, and incident response; automate guardrails.
  • Compliance & Risk Management: ensure SOC 2, GDPR, MAS TRM, PDPA compliance; conduct risk assessments and audits; prepare evidence for audits.
  • Data Protection & Cloud Security Controls: protect sensitive data via encryption, access governance, classification, and DLP.

Skills

Cloud security governance
IAM governance
Security-by-design
Threat modeling
Leadership & stakeholder engagement
Incident response
Regulatory/compliance awareness

Education

Bachelor’s degree in Computer Science/Info Security or related
Master’s degree (a plus)

Tools

Terraform
CloudFormation
AWS Security Services (IAM, Security Hub, GuardDuty, CloudTrail, Config, Macie, KMS)
WAF / Shield

Job description

The Cloud Security Manager is responsible for leading and managing the security posture of the organization’s cloud environments. This role oversees cloud security architecture, governance, compliance, incident response, and cloud security operations to ensure secure design, implementation, and ongoing management of cloud workloads. The manager will work closely with cloud engineering, DevOps, cybersecurity, infrastructure, and application teams to embed security-by-design across all cloud deployments.

Accountabilities:

Cloud Security Governance & Policy

Establish, maintain, and enforce cloud security policies, standards, and governance frameworks to ensure secure cloud adoption across the organization.

Review and approve cloud solution designs, ensuring secure-by-design principles, threat modeling, and compliance with best practices and reference architectures.

Identity & Access Management (IAM) Control

Own and govern cloud IAM strategy, enforcing least privilege, strong authentication, privileged access control, and periodic access reviews.

Cloud Security Operations & Monitoring

Oversee continuous monitoring of cloud environments, ensuring timely detection and remediation of misconfigurations, vulnerabilities, and security threats.

Ensure cloud environments meet regulatory, legal, and internal compliance requirements; manage risk assessments, audits, and cloud security reporting.

Lead cloud security incident response, including investigation, containment, recovery, and root cause analysis for cloud-related security events.

Leadership, Stakeholder Engagement & Continuous Improvement

Provide cloud security expertise to stakeholders, lead security teams, manage security tools/vendors, and drive cloud security capability enhancements.

Responsibilities:

Cloud Security Governance & Strategy

Develop and maintain AWS cloud security policies, standards, and frameworks; lead security strategy aligned with business and regulatory requirements; enforce AWS Well-Architected, CIS, and Zero Trust principles.

Cloud Security Architecture & Engineering

Design, review, and approve secure AWS architectures; guide secure cloud-native implementations; govern IAM (RBAC, least privilege, automated remediation); oversee network security controls including WAF, Shield, and service mesh.

Cloud Security Operations, Monitoring & Incident Response

Manage continuous monitoring with AWS-native tools and SIEM; oversee vulnerability management and misconfiguration remediation; lead incident response including detection, investigation, containment, and recovery; automate security guardrails and remediation workflows.

Ensure compliance with regulatory and internal requirements (SOC 2, GDPR, MAS TRM, PDPA); conduct cloud risk assessments and threat modeling; coordinate penetration testing; prepare documentation and evidence for audits.

Data Protection & Cloud Security Controls

Ensure effective protection of sensitive data through encryption, access governance, classification, and DLP controls; manage cloud data exposure risks and ensure secure storage and handling of information across AWS services.

Leadership, Collaboration & Security Culture

Serve as AWS cloud security SME; collaborate with Cloud, DevOps, Network, and Cybersecurity teams to embed security-by-design; mentor teams and promote a strong security culture through training and stakeholder engagement

Team Scope/ Stakeholders:

Reports to theHead of Cybersecurity:
The candidate will work closely with theHead of Cybersecurityto design, implement, support, andmaintaincybersecurity systems that safeguard the organization’s digital assets. This includes contributing to architecture design, operational readiness, system optimization, and ensuring alignment with security policies and operationalobjectives.

Vendor & Service Provider Management:
The candidate will lead, manage, and coordinate external vendors responsible for supporting cybersecurity systems. This includes ensuring vendors meet contractual obligations, service levels, operational standards, and deliver quality support for security tools, platforms, and related infrastructure.

Cross-Functional Collaboration:
The role will collaborate with internal stakeholders such as IT Infrastructure, Network Engineering, SOC Analysts, Incident Response Teams, Governance/Risk/Compliance (GRC), and Application Teams to ensure the effective operation, integration, and continuous improvement of cybersecurity systems.

Business & Operational Stakeholders:
The candidate will engage with business units to understand operational requirements, communicate potential risks, and ensure security systems support business continuity, performance, and compliance needs.

Requirements:

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field;Master’sdegree is a plus.

5-10years of cybersecurity experience, with at least 3+ years focused on AWS cloud security and cloud security architecture.

Strongexpertisein AWS security services (e.g., IAM, Security Hub,GuardDuty, CloudTrail, Config, Macie, KMS, WAF, Shield).

Hands-on experience in cloud security architecture,DevSecOps, and infrastructure-as-code (Terraform, CloudFormation).

Proven ability to implement IAM governance, least privilege, encryption controls, network security, and secure cloud design principles.

Experience with cloud compliance frameworks and audits (ISO 27001, SOC 2, CIS, MAS TRM, NIST) and conducting cloud risk assessments.

Strong leadership and communication skills, with experience managing cloud security initiatives and collaborating with multi-disciplinary teams.

Relevant professional certifications such as AWS Certified Security - Specialty, AWS Solutions Architect, CISSP, CISM, or CCSP.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Manager
Cloud Security Manager

Starhub Ltd • Petaling Jaya

On-site
MYR 180,000 - 240,000
Cloud Security Manager
Cloud Security Manager

Sourceo Pte Ltd • Selangor

On-site
MYR 180,000 - 320,000
Health insurance
AWS /Cloud Security Manager
AWS /Cloud Security Manager

Flintex Consulting Pte Ltd • Kuala Lumpur

On-site
MYR 179,000 - 223,000
Security Consultant, Global Proserve Security
Security Consultant, Global Proserve Security

Amazon Lab126 • Kuala Lumpur

On-site
MYR 150,000 - 230,000
Cloud Security Architect I IT Security
Cloud Security Architect I IT Security

Maybank • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Cloud Vulnerability Management & DevSecOps I IT Security
Senior Cloud Vulnerability Management & DevSecOps I IT Security

Maybank • Kuala Lumpur

On-site
MYR 180,000 - 320,000
AWS Cloud Engineer
AWS Cloud Engineer

Lavu Tech Solutions Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Security Consultant, Global Proserve Security
Security Consultant, Global Proserve Security

Amazon Web Services (AWS) • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Mentorship programs
Career growth opportunities
Flexible work options
Cloud Security Governance & Compliance Lead
Cloud Security Governance & Compliance Lead

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Cloud Security Consultant
Cloud Security Consultant

Accenture • Kuala Lumpur

On-site
MYR 140,000 - 190,000