A complete application in a minute — tailored resume and cover letter, ready to send.
CLOUD MILE SDN. BHD. is seeking a Security Compliance Specialist to lead ISMS-related activities and coordinate audits. The role focuses on enforcing information security policies across the organization and promoting security awareness.
The candidate will assess risks, document control issues, and work with auditors to ensure compliance with ISO/IEC 27001 standards. Strong communication and cloud experience are essential.
As a CloudMiler, we thrive to be the leading Enterprise-grade Artificial Intelligence, cloud and security solutions providers in Asia. We are the First Google Premier Partner to acquire Infrastructure and machine learning Specializations in North Asia with strong investment in R&D and technologies.
If you also believe in artificial intelligence and cloud technologies can enable our customers to achieve their goals. If you’re looking to help customers, we should meet up and discuss how we can make the business successful together.
Responsible in conducting the ISMS Committee meeting on ISMS related activities and acceptance of ISMS changes
Coordinate with ISMS auditors on ISMS compliance audit exercise in ensuring company compliance to the ISMS standards
Ensure company sections and staffs are comply with ISMS policies, procedures and standards
Coordinate ISMS yearly policy and management review
Responsible in providing regular ISMS awareness training to company employees
The job encompasses leading and participating in the assessment of security, risks, and control effectiveness for applications, infrastructure, and technology projects.
The Specialist will identify, classify, and document control issues in a company's computing environment by documenting assessment results, recommending corrective action, tracking remediation, evaluating policy and control standard exceptions, and regularly reporting to top management.
To treat customers’ information and material as private & confidential and shall not at any time during or after the services, for any reason whatsoever disclose or permit to disclose to any person, or otherwise make use of or permit to be made use of any information and material relating to the customers’ technology, technical process, business affairs or finances.
Troubleshoot network issues such as outages, security vulnerabilities, and other system-level concerns.
Manage information system accounts and permissions across various platforms, ensuring proper access control and security protocols are followed.
Any other duties assigned from time to time.
Bachelor's degree in computer technology, information systems, or a related field
Possess at least 1-3 years of working experience related to information security practices
MUST possess good understanding on ISO/IEC 27001:2013 minimum
MUST be certified with ISO/IEC 27001 Foundation, IA or LA
Good knowledge of IT and network architecture
Access control management skills
Strong communication and interpersonal skills
Ability to educate technical and non-technical staff on computer security
Knowledge on cybersecurity standards/frameworks
Strong analytical and problem-solving skills
Familiarity with network L1 to L3 concepts and equipment operations (including Palo Alto, Cisco Meraki), as well as managing access control systems (including AD, RADIUS, and VPN)
Certified in ISO/IEC 27001 Foundation or IE or LA.
Experience with public cloud services usage or architecture planning.
Experience in automation scripting or software development.