Information Security Analyst

Air Liquide

Petaling Jaya

On-site

MYR 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Air Liquide IT is undergoing an overhaul of its security operations, consolidating global IT services under GIO and BIS structures to improve security, competitiveness and agility. The role focuses on application security, architecture review, risk analysis, vulnerability management, and governance across IT and OT environments.

You will drive threat modeling, risk mapping, and exception handling, partnering with engineering and operations to implement compensating controls and robust policy

Qualifications

  • 5+ years in information security, risk management, or vulnerability management across IT/OT environments.
  • Experience coordinating vulnerability and penetration testing programs.
  • Strong knowledge of secure architecture and cloud-first patterns.

Responsibilities

  • Conduct architecture reviews and risk assessments for applications.
  • Lead vulnerability management and remediation across IT/OT.
  • Coordinate IAM access reviews and security governance reporting.
  • Produce risk reports and executive dashboards.

Skills

Architecture Review
Threat Modeling
Risk Assessment
Exception Management
Compensating Controls
Risk Registry Maintenance

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field

Tools

Qualys
PRISMA Cloud

Job description

Air Liquide IT: The Group launched an overhaul of its IT services, to simultaneously improve and world security, competitiveness and agility. This results in a changing IT organizations with infrastructure services and IT production which will now be managed globally by a central department called GIO (Global Infrastructure Operations) and business applications that will be supported by dedicated departments, called BIS (Business Information Systems) for each business line and relevant geographies.

How will you CONTRIBUTE and GROW?

1. Application Security, Architecture Review & Risk Analysis

  • Architecture & Design Reviews: Evaluate application architectures and cloud/on-premise deployment patterns against enterprise security standards to ensure alignment with Security & Privacy by Design principles.
  • Threat Gap Identification: Conduct threat modeling and risk assessments to identify technical vulnerabilities, architectural flaws, and control gaps early in the application lifecycle.
  • Risk Assessment & Impact Analysis: Quantify and document technical, operational, and business risks associated with system changes, third‑party integrations, and new technology deployments.
  • Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
  • Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
  • Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re‑evaluation.

3. Vulnerability & Compliance Management (Cyber Ops)

  • Vulnerability Scanning & Remediation: Execute continuous vulnerability assessments across IT/OT networks and applications using enterprise tools (e.g., Qualys, PRISMA Cloud).
  • Penetration Test Follow‑Up: Track remediation of findings from IT/OT penetration tests, perform re‑testing validation, and support ad‑hoc testing requirements.
  • Operational Security Requests: Manage and triage incoming requests from the centralized security mailbox, along with ad‑hoc tickets (e.g., firewall rule changes, proxy whitelisting, YourWay requests).

4. Security Operations & Governance Support

  • Threat Intelligence Execution: Process and execute follow‑up actions on cyber threat intelligence reports issued by the CSIRT.
  • IAM & Access Control Reviews: Coordinate annual Identity and Access Management (IAM) access reviews for both standard users and High Privilege Accounts (HPA).
  • Metrics & Reporting: Maintain security dashboards, track CMDB asset governance, and produce security reporting for leadership.

Qualifications & Candidate Requirements:

Education & Experience

  • Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field (or equivalent practical experience).
  • Experience: 5+ years of hands‑on experience in information security, risk management, vulnerability management, or security incident handling across both IT and OT (Operational Technology) environments.

Vulnerability Management & Penetration Testing Coordination

  • Vulnerability Assessment & Governance: Demonstrated expertise in running enterprise‑wide vulnerability management programs (using tools such as Qualys, PRISMA Cloud, etc.), including scanning, prioritization, triage, and SLA enforcement across IT/OT infrastructure.
  • Penetration Test Follow‑up & Remediation: Proven experience coordinating third‑party and internal penetration testing engagements. This includes analyzing findings, leading remediation workflows with infrastructure/application teams, facilitating re‑testing, and conducting ad‑hoc security validations.

Security Architecture & Risk Management

  • Application Architecture & Threat Modeling: Deep understanding of secure application architecture, cloud‑first patterns, threat modeling, and identifying structural threat gaps during design reviews.
  • Access Control & Identity Architecture: Strong technical command of identity and access governance, including Role‑Based Access Control (RBAC), Tiered Access Models, and Privileged Access Management (PAM/HPA).
  • Risk Assessment & Exception Handling: Hands‑on experience performing technical risk analyses, evaluating compensating controls, and managing formal digital security policy exception workflows (DTAP/waivers).
  • Communication & Certifications
  • Communication: Exceptional written and verbal communication skills, with a track record of producing clear technical risk reports, executive dashboards, and policy documentation.
  • Certifications (preferably ): Professional certifications such as CISSP, CISA, CRISC or CISM

Other Information:

  • Office Location: Level 17, 1Powerhouse
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst - Threat & Risk Leader
Senior Information Security Analyst - Threat & Risk Leader

Air Liquide • Petaling Jaya

On-site
MYR 120,000 - 180,000
IT Security Operation Lead_3266
IT Security Operation Lead_3266

Allianz Technology • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Technology Security Analyst
Information Technology Security Analyst

Lotus's Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Security Engineer
Security Engineer

Mission Consultancy Services • Kuala Lumpur

On-site
MYR 80,000 - 120,000
IT Security Operation Lead_3266
IT Security Operation Lead_3266

Allianz • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Senior Security Business Partner – Product Security
Senior Security Business Partner – Product Security

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA • Sepang

On-site
MYR 80,000 - 120,000
Staff IT, Cybersecurity & OT Security Engineer
Staff IT, Cybersecurity & OT Security Engineer

ENOVIX Corporation • Seberang Perai

On-site
MYR 240,000 - 420,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 90,000 - 150,000
Senior Security Analyst
Senior Security Analyst

Logicalis Asia Pacific • Kuala Lumpur

On-site
MYR 80,000 - 100,000