IT Manager, APAC

Hoffman Agency

Malaysia

On-site

MYR 200,000 - 280,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Four-week sabbatical after four years
Competitive salary and benefits
Career growth opportunities

Job summary

Hoffman Agency is seeking a seasoned IT Security Lead in Malaysia to govern security policy, conduct risk assessments, and manage audits. You will respond to client security questionnaires and RFPs, coordinate with external auditors, and drive remediation while mentoring staff in security best practices.

The role requires 4+ years in IT security, familiarity with ISO 27001/NIST CSF, and strong English communication. A four-week sabbatical after four years is among offered benefits.

Qualifications

  • Bachelor's degree in a relevant field
  • At least 4 years in IT security governance or related role
  • Knowledge of ISO 27001 / NIST CSF / CIS Controls
  • Experience with risk assessments, audits and gap analyses
  • Familiarity with Microsoft 365 security tools
  • Experience responding to client security questionnaires and RFPs
  • Knowledge of endpoint protection and vulnerability management
  • Understanding data protection regulations across regions (GDPR/PDPA/CCPA)
  • Strong English communication; additional language (Chinese) a plus

Responsibilities

  • Own security policy lifecycle and keep documents up to date
  • Lead security certifications with external auditors
  • Respond to client security questionnaires and RFPs
  • Plan and conduct annual information security risk assessments
  • Design and deliver security awareness training for staff
  • Monitor vulnerabilities and coordinate incident response
  • Evaluate and integrate security tools with IT ecosystem
  • Provide backup support for IT operations during peak periods

Skills

Security governance
Risk assessment
Security audits
Client security questionnaires
Endpoint protection
English communication
Additional language (Chinese)
Cloud security (M365)

Education

Bachelor's degree in Information Security / IT
ISO 27001 Lead Implementer/Auditor
CISSP, CISM, CompTIA Security+ or equivalent

Tools

Microsoft Defender for Office 365
Azure AD / Entra ID
Intune

Job description

Your drive to inspire and guide sets you apart. You thrive on taking responsibility, tackling challenges head-on, and turning obstacles into opportunities. Working closely with a diverse, talented team to deliver innovative solutions energizes you, and you find genuine satisfaction in helping clients achieve their goals.

We’re in search of dynamic IT talent who not only excel in a fast-paced, collaborative environment but also bring creativity, strategic insight, and a good sense of humour to every challenge. If you’re ready to empower internal clients, and drive transformative change, we want to hear from you!

If you like where this story is leading, read on.

The Plot Thickens: Job Description
  • Security governance and policy management: You will own the lifecycle of our security documentation—regularly reviewing and updating the IT Security Policy, Security Incident Response Procedures, Business Continuity Plan (BCP), Disaster Recovery Plan (DRP), AI Policy oversight, and related documents. You will ensure these frameworks remain current, aligned with evolving threats, and compliant with industry standards and regional regulations such as PDPA and related privacy laws. You will also be responsible for the maintenance, upkeep, and upgrades of security systems, including Microsoft Defender, Sophos, BitLocker, and Microsoft Intune.
  • Compliance and certifications: You will lead the effort in obtaining and maintaining security-related certifications (e.g., ISO 27001, SOC 2, Cyber Essentials) that strengthen our credibility with clients and partners. This includes coordinating with external auditors, preparing documentation, and driving remediation of any gaps identified during the certification process.
  • Client security questionnaires and RFP responses: You will serve as the go‑to person for responding to client security questionnaires, RFPs, and due diligence requests. By researching and recommending cost‑effective security tools and controls, you will ensure our environment meets the requirements our clients expect—without overengineering solutions.
  • Risk assessment and audit: You will initiate and manage annual information security risk assessments, identifying vulnerabilities across our Microsoft 365 environment, endpoint infrastructure, and third‑party integrations. You will coordinate internal and external audits, track findings, and drive remediation plans through to completion.
  • Security awareness training: You will design, develop, and deliver an annual security awareness training programme for all staff, including on our learning platform—HAcademy. From phishing simulations to policy refreshers, you will foster a security‑conscious culture that empowers every team member to be a line of defence.
  • Vulnerability monitoring and incident response: You will continuously monitor security vulnerability alerts from sources such as vendor advisories, threat intelligence feeds, and our endpoint protection tools. When threats emerge, you will assess their impact, coordinate with the IT team to apply patches or mitigations and escalated per the Incident Response Procedures when necessary.
  • Security tooling, vendor evaluation, and cybersecurity management: You will research, evaluate, and recommend cost‑effective security solutions that address gaps in our environment while meeting client and regulatory requirements. This includes managing cybersecurity vendors and overseeing the integration of security tools into the broader IT ecosystem. You will also contribute to procurement decisions in collaboration with the Regional IT Director and maintain strong vendor relationships to ensure optimal performance and value.
  • IT support and infrastructure backup: While your primary focus is cybersecurity, you will also serve as a backup for IT support and infrastructure functions. This includes assisting with endpoint troubleshooting, user support escalations, Microsoft 365 administration, and infrastructure tasks during peak periods or when colleagues are unavailable.
  • Hosting of company website and related resources: You act as both a trainer and advisor to the wider IT team, providing guidance on cybersecurity best practices and key security considerations. In addition, you provide ad hoc support across end‑user support and infrastructure needs, stepping in as required to ensure smooth and reliable IT operations.
Attributes of the Protagonist (That’s You)
  • Detail-oriented and methodical in approach
  • Team player – your success is my success!
  • Ownership mindset and accountability
  • Proactive and vigilant – you spot risks before they become incidents
  • Passionate about cybersecurity and continuous learning
  • Strong communicator who can translate technical concepts for non-technical audiences
  • Resourceful problem‑solver with a cost‑conscious mindset
  • Adaptable and willing to step outside your core function when the team needs you
The Hero’s Background: Qualifications
  • Bachelor’s degree or above in Information Security, Computer Science, Information Technology, or a related field from a reputable university
  • At least 4 years of experience in IT security, cybersecurity governance, or a related information security role
  • Solid understanding of security frameworks and standards (e.g., ISO 27001, NIST CSF, CIS Controls)
  • Experience conducting risk assessments, security audits, and compliance gap analyses
  • Familiarity with Microsoft 365 security and compliance tools (Microsoft Defender for Office 365, Azure AD / Entra ID, Intune)
  • Experience responding to client security questionnaires and RFPs in a professional services or agency context
  • Knowledge of endpoint protection solutions and vulnerability management practices
  • Understanding of data protection regulations across key operating regions (e.g., GPDR, CCPA, PDPA Singapore, China PIPL, etc.)
  • Strong documentation and communication skills in English; proficiency in another language such as Chinese would be an advantage due to support of users in China
  • Relevant certifications are a plus: CISSP, CISM, CompTIA Security+, ISO 27001 Lead Implementer/Auditor, or equivalent

Join us and be at the forefront ofmarketing and communications innovation, partnering withindustry-leading technology brandsacross the world. We valuediverse perspectives,inclusive decision-making, and ideas thatpush boundariesto shape what’s next.

We offer acompetitive salary,comprehensive benefits, andcareer growth opportunities— plus a uniquefour-week paid sabbatical after four years of service, because we believe in rewarding dedication and balance.

About Us

We are anintegrated communications consultancy built to solve tough challenges — the more complex, the better — for technology companies shaping the future. Headquartered in Silicon Valley, our network spans across global innovation hubs including Bangkok, Boston, Beijing, Hong Kong, Jakarta, Kuala Lumpur, London, Munich, Paris, Portland, San Jose, Seoul, Shanghai, Singapore, Taipei, and Tokyo.

At Hoffman, we combine deep tech understanding with bold storytelling to help brands stand out, influence conversations, and drive meaningful impact.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

APAC IT Manager (Cybersecurity)
APAC IT Manager (Cybersecurity)

The Hoffman Agency • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Senior IT Support Specialist
Senior IT Support Specialist

MoneyHero Group • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Annual leave
Birthday leave
Remote work leave
+4
Senior IT Support Specialist
Senior IT Support Specialist

MoneyHero Group (Nasdaq: MNY) • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Annual leave
Professional trainings
Insurance & wellness
Cybersecurity Consultant
Cybersecurity Consultant

Group-IB • Malaysia

On-site
MYR 120,000 - 180,000
Cloud Security Consultant
Cloud Security Consultant

7801 Accenture Solutions Sdn B Company • Kuala Lumpur

On-site
MYR 180,000 - 260,000
IT Manager
IT Manager

Private Advertiser • Kuala Lumpur

On-site
MYR 180,000 - 320,000
—
Information Security Compliance Analyst
Information Security Compliance Analyst

MEDIAMONKS MALAYSIA SDN. BHD. • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Cybersecurity Consultant
Cybersecurity Consultant

Group-IB • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Kuala Lumpur IT SUPPORT ENGINEER / JUNIOR TECHNOLOGIST
Kuala Lumpur IT SUPPORT ENGINEER / JUNIOR TECHNOLOGIST

1000heads Group • Kuala Lumpur

Hybrid
MYR 60,000 - 90,000
Security Solution Sales Lead
Security Solution Sales Lead

Noventiq India, Ltd. • Kuala Lumpur

On-site
MYR 120,000 - 240,000
Bonus & allowances
Premium healthcare for employees and a
Training opportunities