Information Security Analyst

Media.Monks

Kuala Lumpur

On-site

MYR 90,000 - 150,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Media.Monks Malaysia is seeking an Information Security Analyst to safeguard customer and company data, uphold the company’s security posture, and support risk-based decision making. The role covers security assessments, technical controls, risk assessments, vendor risk, and ISMS alignment with ISO/IEC 27001:2022; you will collaborate with global teams and various departments.

The ideal candidate has a 4+ year security background, strong CIA understanding, network security, cloud security,

Qualifications

  • Bachelor's degree or higher in Computer Science, Cybersecurity, Computer or Systems Engineering or equivalent.
  • Minimum of 4 years of experience in information security.
  • Strong understanding of CIA, confidentiality, integrity, and availability.
  • Solid knowledge of network architecture and segmentation, firewalls/IDS/IPS, encryption/PKI, EDR/DLP, OS security, databases, SSO/SAML/OIDC, RBAC, cloud security (AWS/Azure/GCP), S-SDLC, patching, logging, and API security.
  • Excellent problem-solving and analytical abilities and strong English communication.

Responsibilities

  • Assess and track security posture across platforms and systems, following up on remediation tasks.
  • Collaborate with stakeholders to integrate security requirements into projects, services, and vendor relations.
  • Conduct regular assessments to ensure compliance with internal policies and external standards.
  • Identify risks with third-party vendors, cloud infrastructure, access management, and system configurations.
  • Evaluate and recommend security technologies to improve the posture (DLP, EDR, network segmentation, cloud tools).
  • Align with ISMS based on ISO/IEC 27001:2022 and best practices (NIST).
  • Maintain documentation of security processes, audits, compliance controls, and risk assessments.
  • Automate compliance checks and reporting using tools and platforms.
  • Stay current with industry trends and regulatory changes; suggest enhancements.
  • Contribute to security awareness programs and training; mentor colleagues.
  • Foster collaboration across global Infosec Team and departments to ensure collective success.

Skills

CIA Triad
Network security
Firewall/IDS/IPS
PKI
EDR/DLP
OS hardening
Cloud security
S-SDLC
Patch management
Logging/Monitoring
API security
RBAC/least privilege
SAML/OIDC
Security risk assessment
English communication
Analytical thinking

Education

Bachelor's degree in Computer Science / Cybersecurity / Systems Engineering

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

As an Information Security Analyst, your core responsibility will be safeguarding customer and company data, protecting the company's reputation, and making vital decisions that are integral to shaping the state-of-the-art security posture for the business's future success.

This person should detect new threats, understand the risk assessment process, contribute in the action plan development and promote the progress of mitigation implementation and evolution. The position will cover security assessment activities, technical controls evaluation, risk assessments, management of clients requirements and internal awareness.

As a valuable member of our global Infosec Team, you will have the opportunity to collaborate with colleagues across the globe, fostering a dynamic and diverse work environment. Your role will involve working closely with stakeholders from various departments, forging strong partnerships to ensure the collective success of our information security initiatives.

As an Information Security Analyst, your core responsibility will be safeguarding customer and company data, protecting the company's reputation, and making vital decisions that are integral to shaping the state-of-the-art security posture for the business's future success.

This person should detect new threats, understand the risk assessment process, contribute in the action plan development and promote the progress of mitigation implementation and evolution. The position will cover security assessment activities, technical controls evaluation, risk assessments, management of clients requirements and internal awareness.

As a valuable member of our global Infosec Team, you will have the opportunity to collaborate with colleagues across the globe, fostering a dynamic and diverse work environment. Your role will involve working closely with stakeholders from various departments, forging strong partnerships to ensure the collective success of our information security initiatives.

Responsibilities:

  • Assess and track security posture across platforms and systems, following up on remediation tasks to close gaps efficiently.

  • Collaborate with stakeholders across technology, legal, and business units to integrate security requirements into projects, services, and vendor relationships.

  • Perform regular assessments of technical environments to ensure compliance with internal policies and external standards.

  • Identify and document risks associated with third-party vendors, cloud infrastructure, access management, and system configurations.

  • Evaluate and recommend technologies that enhance our security and compliance posture (e.g., DLP, EDR, network segmentation, cloud security tools).

  • Collaborate with the alignment to the global Information Security Management System (ISMS), based on ISO/IEC 27001:2022 and best practices from well known frameworks such as NIST.

  • Maintain comprehensive documentation of security processes, audit reports, compliance controls, and risk assessments.

  • Utilize tools and platforms to automate compliance checks and reporting across the environment.

  • Stay current with industry trends, technologies, and regulatory changes, proactively suggesting enhancements to the security baseline.

  • Contribute to security awareness programs and training efforts within the organization.

  • Mentor and support colleagues to encourage growth and a strong security culture across teams.

Required Qualifications

  • Bachelor's degree/advanced education in Computer Science, Cybersecurity, Computer or Systems Engineering or equivalent.

  • Minimum of 4 years of experience in security.

  • Solid understanding of core information security concepts, including confidentiality, integrity, and availability (CIA Triad).

  • Solid understanding of technical concepts and security hardening practices in the following areas:

    • Network architecture and segmentation

    • Firewalls, IDS/IPS (Intrusion Detection/Prevention Systems)

    • Encryption and Public Key Infrastructure (PKI)

    • Endpoint protection and hardening (EDR, DLP)

    • Operating system security (Windows, Linux, macOS)

    • Databases

    • Single Sign-On (SSO), SAML, and OIDC

    • Role-Based Access Control (RBAC) and least privilege principles

    • Cloud security hardening (AWS, Azure, GCP)

    • Secure Software Development Lifecycle (S-SDLC)

    • Patch management strategy and tooling

    • Logging and monitoring

    • API security and secure integrations

  • Strong analytical and problem-solving skills, capable of diagnosing issues and implementing effective solutions.

  • Strong English communication.

Preferred Qualifications:

  • Certifications such as CISSP, CISM, CCSK, Security+, AWS Security Specialty, or similar.

  • Experience designing or optimizing a compliance program across multiple business units or geographies.

  • Familiarity with security automation platforms and compliance monitoring tools.

  • Exposure to scripting or automation for reporting and process efficiency.

  • Experience collaborating with third-party auditors, client security teams, or legal/compliance units.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst (Contract)
Cyber Security Analyst (Contract)

Experian • Kuala Selangor

On-site
MYR 100,000 - 160,000
Information Security Analyst
Information Security Analyst

Ricoh • Shah Alam

Hybrid
MYR 60,000 - 120,000
Work from home
Vision insurance
Cyber Security Analyst (Contract)
Cyber Security Analyst (Contract)

Experian • Sepang

On-site
MYR 90,000 - 170,000
Cybersecurity Analyst
Cybersecurity Analyst

techstreet • Selangor

On-site
MYR 60,000 - 110,000
L1 - SOC Analyst
L1 - SOC Analyst

Dwell Technologies Sdn. Bhd. • Kuala Lumpur

On-site
MYR 54,000 - 90,000
Cyber Security Analyst/Support (SOC)
Cyber Security Analyst/Support (SOC)

MSP Systems • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior CyberSecurity Analyst
Senior CyberSecurity Analyst

SF International • Selangor

On-site
MYR 60,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services Malaysia • Kuala Lumpur

On-site
MYR 89,000 - 167,000
Salary 8k-15k MYR
Certifications support
Career development
L2 - Security Analyst
L2 - Security Analyst

Ensign Infosecurity • Kuala Lumpur

On-site
MYR 60,000 - 100,000
System Engineer (Cybersecurity)
System Engineer (Cybersecurity)

Blue Fortress Sdn. Bhd. • Alor Setar

On-site
MYR 36,000 - 60,000