Cyber Defense Lead

Hong Leong Bank Berhad

Selangor

On-site

MYR 120,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading financial institution in Malaysia is seeking a highly experienced Defense Management Lead to supervise and enhance comprehensive security operations. Responsibilities include managing VAPT teams, overseeing security governance frameworks, and serving as a security advisor across business units. The ideal candidate will possess extensive experience in information security, relevant certifications, and strong leadership skills. This role demands a commitment to optimizing security practices and ensuring alignment with regulatory requirements.

Qualifications

  • 8+ years of progressive experience in information security.
  • In-depth knowledge of security governance frameworks.
  • Relevant industry certifications such as CISSP, CISM, OSCP, CEH.

Responsibilities

  • Lead and manage a team of VAPT specialists.
  • Oversee security governance frameworks and audit assessments.
  • Act as a primary security advisor to business units.

Skills

Information security experience
Security governance frameworks knowledge
Strong communication skills
Analytical abilities

Education

Bachelor's degree in Computer Science or related field
Master's degree preferred

Tools

ISO 27001
NIST
CISSP
CISM
OSCP
CEH

Job description

Overview

We are seeking a highly experienced and strategic Defense Management Lead to spearhead our comprehensive security operations. This pivotal role will be responsible for overseeing and optimizing our vulnerability management, security governance, system security, and security advisory functions. The ideal candidate will be a proven leader with deep technical expertise across various security domains, exceptional organizational skills, and a strong commitment to enhancing our overall security posture.



Responsibilities

VAPT (Vulnerability Assessment & Penetration Testing) Team Management


  • Lead, mentor, and manage a team of VAPT specialists, fostering a culture of continuous improvement and technical excellence.

  • Develop, implement, and mature the VAPT program, including scope definition, methodology, tool selection, and reporting.

  • Oversee the execution of regular vulnerability assessments and penetration tests across applications, infrastructure, and networks.

  • Prioritize and track remediation efforts for identified vulnerabilities, collaborating with relevant teams to ensure timely resolution.

  • Stay abreast of emerging threats, vulnerabilities, and attack techniques to enhance VAPT strategies.


Security Governance


  • Establish and maintain robust security governance frameworks, policies, standards, and procedures in alignment with industry best practices (e.g., ISO 27001, NIST, internal compliance requirements).

  • Lead and facilitate security audit assessments (internal and external), ensuring compliance with regulatory and organizational requirements.

  • Manage and conduct OSP (Outsourced Service Provider) security reviews, including due diligence and ongoing monitoring of third-party security posture.

  • Oversee the vendor security management program, assessing security risks posed by third-party vendors and ensuring appropriate controls are in place.

  • Provide governance and oversight over the security posture of all security components and solutions deployed within the organization.


System Security


  • Manage and optimize endpoint security solutions (e.g., EDR, antivirus), ensuring comprehensive protection across all devices.

  • Oversee the lifecycle management of SSL/TLS certificates, ensuring timely renewals and proper implementation.

  • Develop and implement strategies for data encryption across various systems and data at rest/in transit.

  • Define and enforce hardening standards for operating systems, applications, and network devices.

  • Manage and secure file sharing mechanisms, ensuring data integrity, confidentiality, and access control.


Security Advisory, Architecture & Project Office


  • Act as a primary security advisor to business units and technology teams, providing expert guidance on security best practices, risk mitigation, and architectural design.

  • Contribute to the development and evolution of the overall security architecture, ensuring alignment with business objectives and threat landscape.

  • Lead the security project office function, managing the lifecycle of security-related projects from initiation to closure.

  • Define project scopes, objectives, resource requirements, timelines, and budgets for security initiatives.

  • Monitor project progress, identify and mitigate risks, and ensure successful delivery of security projects.


Skills And Experience We Are Looking For


  • Bachelor's degree in Computer Science, Information Security, or a related field. Master's degree preferred.

  • 8+ years of progressive experience in information security

  • In-depth knowledge of security governance frameworks (ISO 27001, NIST, etc.) and experience with audit management.

  • Strong understanding of system security principles, including endpoint security, encryption, hardening, and data protection.

  • Experience in security architecture and providing security advisory services.

  • Demonstrated success in managing security projects and programs.

  • Relevant industry certifications such as CISSP, CISM, OSCP, CEH, or equivalent are highly desirable.

  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex security concepts to technical and non-technical audiences.

  • Strong analytical and problem-solving abilities, with a keen eye for detail.

  • Ability to work effectively in a fast-paced and dynamic environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Manager, Cyber Security Operations (Vulnerability Management)
Associate Manager, Cyber Security Operations (Vulnerability Management)

Permodalan Nasional Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Vulnerability Response Specialist
Vulnerability Response Specialist

Two95 International Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Technology Security Analyst
Information Technology Security Analyst

Lotus's Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 60,000 - 120,000
Senior VAPT Practice Head
Senior VAPT Practice Head

EC-Council • Kuala Lumpur

On-site
MYR 240,000 - 360,000
IT & Cyber Risk Manager
IT & Cyber Risk Manager

ADI Resourcing • Petaling Jaya

On-site
MYR 180,000 - 240,000
Associate, Cyber Security Governance, Risk & Compliance
Associate, Cyber Security Governance, Risk & Compliance

LGMS Berhad • Subang Jaya

On-site
MYR 70,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

Randstad Malaysia • Kuala Lumpur

On-site
MYR 70,000 - 90,000
Associate - Cybersecurity
Associate - Cybersecurity

PwC South Africa • Kuala Lumpur

On-site
Confidential
IT Security Operation Lead
IT Security Operation Lead

Jobtailor • Kuala Lumpur

On-site
MYR 60,000 - 90,000