IT Security Operation Lead_3266

Allianz Technology

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

30 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Allianz Technology in Malaysia is seeking a security operations professional to monitor RDC local security solutions, manage the ticket queue end to end, and coordinate remediation for SOC alerts and vulnerabilities.

You will oversee change management with sign‑offs from the Head of IS and collaborate with IF, ADM, and Group teams while maintaining security documentation and runbooks for the RDC.

Qualifications

  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related field.
  • Proven experience in information security, network security, or a related role.
  • Strong understanding of security principles, practices, and technologies.
  • Hands-on experience with security monitoring, SIEM/SOC alert handling and incident response tools and technologies.
  • Practical experience with vulnerability scanning and remediation tracking, and with access management / user access reviews (IAM, cloud and WAF platforms).
  • Working knowledge of ITIL-based incident, problem and change management, and comfort operating within a defined RACI across local and central/Group teams.
  • Proficiency in scripting or programming languages (e.g., Python, PowerShell) for automation tasks.
  • Familiarity with cloud security and security frameworks (e.g., NIST, ISO 27001).
  • Strong analytical and problem-solving abilities.

Responsibilities

  • Monitor, operate and maintain RDC security solutions and services.
  • Own the security ticket queue end to end and triage issues.
  • Respond to SOC alerts and drive remediation to closure.
  • Execute vulnerability scans across the RDC estate.
  • Track identified vulnerabilities to closure with stakeholders.
  • Prepare, assess and implement security-related changes with signoff.
  • Coordinate incident and problem management with Central ACDC Team.
  • Process access requests and run annual user access reviews.
  • Act as local owner for Group-provided security solutions and services.
  • Deliver evidence and remediation actions for regulatory, compliance and audit requests.

Skills

Security monitoring
Incident response
Access management
Cloud security
Scripting

Education

Bachelor’s degree in computer science, information technology, cybersecurity, or a related field

Tools

Python
PowerShell
SIEM
Cloud WAF
NIST
ISO 27001
ITIL

Job description

  • Local Solutions / Services Monitoring and Management (Responsible): Monitor, operate and maintain the RDC's local security solutions and services, detecting and acting on potential security events and threats. The Head of IS signs off; the Head of IF & IS and the Head of RDC are kept informed.
  • Tickets and Remediation (Responsible): Own the security ticket queue end to end triage, investigate and remediate consulting the IF and ADM teams and the Central ACDC Team where the fix sits outside IS.
  • SOC Alerts Response and Remediation (Accountable): Own the local response to SOC alerts raised and worked by the Central ACDC Team validate, drive remediation to closure and sign off the outcome, consulting the IF and ADM teams and third-party vendors as required.
  • Vulnerability Scanning (Responsible): Execute vulnerability scans across the RDC estate on the platform owned and signed off by the Central AVM Team, consulting the AZT MY ISO and OE ISO on scope and findings.
  • Vulnerability Tracking and Remediation (Responsible): Track identified vulnerabilities to closure with the IF, ADM and application owners, reporting progress to the Central AVM Team (accountable) and consulting the AZT MY ISO and OE ISO.
  • Change Management (Responsible): Prepare, assess and implement security-related changes in line with the change process, with the Head of IS signing off and the IF and ADM teams informed.
  • Incident and Problem Management (Accountable): Own local security incident and problem management coordinate investigation and root-cause analysis with the Central ACDC Team (responsible), consult the IF and ADM teams, and keep the AZT MY ISO, OE ISO and OE IT Risk informed.
  • Access Management and User Access Review (Responsible): Process access requests together with the Central IAM, ACDC and Cloud WAF teams and run the half-yearly user access review for the RDC, with the Head of IS signing off.
  • Group Solutions / Services Management (Accountable): Act as the local owner for Group-provided security solutions and services delivered by the Central ACDC, AVM, IAM and Cloud WAF teams align requirements, oversee service quality and sign off local adoption.
  • Regulatory, Compliance and Audit Management (Responsible): Deliver the evidence, control checks and remediation actions required for regulatory, compliance and audit requests, consulting the AZT MY ISO, OE ISO, OE IT Risk and the Central IAM / Cloud WAF teams. Note: policy and standard setting sits with the ISO and OE IT Risk, not with this role.
  • Security Reporting and Knowledge Management (Responsible): Produce recurring and ad-hoc security reporting for the Head of IS, the Head of IF & IS and the Head of RDC, and maintain security documentation, runbooks and the knowledge base for the RDC.
  • Security Evaluation and Penetration Testing Support (Responsible / Consulted): Perform security evaluations of solutions and services jointly with the AZT MY ISO and OE ISO (shared responsible), and support penetration testing in a consulted / informed capacity pentests are managed by OE ISO through third-party engagement or run by Group (e.g. bug bounty, hackability) and are not executed by this role.
  • Security Project and Demand Support (Accountable / Consulted): Provide security input and sign-off for projects delivered with PMO (responsible) and third-party vendors, and act as a consulted party in demand management led by OE ISO.
  • Any other duties when deemed necessary. Completing projects on various issues when needed.Continuous Improvement: Keep current with emerging threats and security operations practice, and propose improvements to local processes, tooling and automation.
Key Responsibilities
  • Local Solutions / Services Monitoring and Management (Responsible): Monitor, operate and maintain the RDC's local security solutions and services, detecting and acting on potential security events and threats. The Head of IS signs off; the Head of IF & IS and the Head of RDC are kept informed.
  • Tickets and Remediation (Responsible): Own the security ticket queue end to end triage, investigate and remediate consulting the IF and ADM teams and the Central ACDC Team where the fix sits outside IS.
  • SOC Alerts Response and Remediation (Accountable): Own the local response to SOC alerts raised and worked by the Central ACDC Team validate, drive remediation to closure and sign off the outcome, consulting the IF and ADM teams and third-party vendors as required.
  • Vulnerability Scanning (Responsible): Execute vulnerability scans across the RDC estate on the platform owned and signed off by the Central AVM Team, consulting the AZT MY ISO and OE ISO on scope and findings.
  • Vulnerability Tracking and Remediation (Responsible): Track identified vulnerabilities to closure with the IF, ADM and application owners, reporting progress to the Central AVM Team (accountable) and consulting the AZT MY ISO and OE ISO.
  • Change Management (Responsible): Prepare, assess and implement security-related changes in line with the change process, with the Head of IS signing off and the IF and ADM teams informed.
  • Incident and Problem Management (Accountable): Own local security incident and problem management coordinate investigation and root-cause analysis with the Central ACDC Team (responsible), consult the IF and ADM teams, and keep the AZT MY ISO, OE ISO and OE IT Risk informed.
  • Access Management and User Access Review (Responsible): Process access requests together with the Central IAM, ACDC and Cloud WAF teams and run the half-yearly user access review for the RDC, with the Head of IS signing off.
  • Group Solutions / Services Management (Accountable): Act as the local owner for Group-provided security solutions and services delivered by the Central ACDC, AVM, IAM and Cloud WAF teams align requirements, oversee service quality and sign off local adoption.
  • Regulatory, Compliance and Audit Management (Responsible): Deliver the evidence, control checks and remediation actions required for regulatory, compliance and audit requests, consulting the AZT MY ISO, OE ISO, OE IT Risk and the Central IAM / Cloud WAF teams. Note: policy and standard setting sits with the ISO and OE IT Risk, not with this role.
  • Security Reporting and Knowledge Management (Responsible): Produce recurring and ad-hoc security reporting for the Head of IS, the Head of IF & IS and the Head of RDC, and maintain security documentation, runbooks and the knowledge base for the RDC.
  • Security Evaluation and Penetration Testing Support (Responsible / Consulted): Perform security evaluations of solutions and services jointly with the AZT MY ISO and OE ISO (shared responsible), and support penetration testing in a consulted / informed capacity pentests are managed by OE ISO through third-party engagement or run by Group (e.g. bug bounty, hackability) and are not executed by this role.
  • Security Project and Demand Support (Accountable / Consulted): Provide security input and sign-off for projects delivered with PMO (responsible) and third-party vendors, and act as a consulted party in demand management led by OE ISO.
  • Any other duties when deemed necessary. Completing projects on various issues when needed.Continuous Improvement: Keep current with emerging threats and security operations practice, and propose improvements to local processes, tooling and automation.
Key Requirements / Skills / Experiences
  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related field.
  • Proven experience in information security, network security, or a related role.
  • Strong understanding of security principles, practices, and technologies.
  • Hands‑on experience with security monitoring, SIEM/SOC alert handling and incident response tools and technologies.
  • Practical experience with vulnerability scanning and remediation tracking, and with access management / user access reviews (IAM, cloud and WAF platforms).
  • Working knowledge of ITIL-based incident, problem and change management, and comfort operating within a defined RACI across local and central/Group teams.
  • Proficiency in scripting or programming languages (e.g., Python, PowerShell) for automation tasks.
  • Familiarity with cloud security and security frameworks (e.g., NIST, ISO 27001).
  • Strong analytical and problem
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Operation Lead
IT Security Operation Lead

Jobtailor • Kuala Lumpur

On-site
MYR 60,000 - 90,000
IT Security Operation Lead_3266
IT Security Operation Lead_3266

Allianz • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Information Security C Governance Manager
Information Security C Governance Manager

Senheng Electric (KL) Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
IT Manager
IT Manager

Jobstreet Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 420,000
Information Security Officer (ISO) Asia-Pacific
Information Security Officer (ISO) Asia-Pacific

GEA Group • Shah Alam

On-site
MYR 243,000 - 485,000
Cyber Defense Lead
Cyber Defense Lead

Hong Leong Bank Berhad • Selangor

On-site
MYR 120,000 - 160,000
Incident Response Lead
Incident Response Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Manager, End User Computing & Application Support
Manager, End User Computing & Application Support

Apex Securities Berhad • Selangor

On-site
MYR 120,000 - 180,000