Lead, Information & Infrastructure Security

MiCare Sdn Bhd

Shah Alam

On-site

MYR 180,000 - 320,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

MiCare leads a regional managed care group seeking a Lead, Information & Infrastructure Security to oversee IT infrastructure, security operations and governance. The role drives security strategy, regulatory compliance and risk management across critical systems and services.

The incumbent will manage vulnerability assessments, incident response, IAM controls and third-party risk, ensuring resilience and continuity aligned with BCM and RMiT requirements.

Qualifications

  • Bachelor's degree in IT, CS or cybersecurity required.
  • Professional certifications such as CISSP, CISM or CISA desirable.
  • Minimum 5–8 years in IT infrastructure, information security or related roles.
  • Experience with ISO 27001, ITIL/COBIT and BCM is advantageous.

Responsibilities

  • Lead IT infrastructure operations including servers, networks and security controls.
  • Develop and govern information security strategy and risk management.
  • Oversee vulnerability management, monitoring and incident response.
  • Manage access controls, IAM and PAM, with least privilege.
  • Coordinate audits, compliance with RMiT, ISO27001 and PDPR.
  • Lead security awareness and continuous improvement.

Skills

Technical leadership
Infrastructure management
Cybersecurity
Risk management
Governance

Education

Bachelor's Degree in IT/CS/cybersecurity

Job description

Lead, Information & Infrastructure Security

We are seeking an experienced and motivated Infrastructure & Security Lead to lead and manage the organization’s IT infrastructure, operations and information security functions, ensuring the availability, reliability, performance, resilience and security of critical IT systems, networks and infrastructure. The role oversees IT infrastructure, network and cybersecurity, vulnerability management, access controls, security monitoring, backup and disaster recovery, IT risk management, audits, regulatory compliance and client due diligence, while leading infrastructure and security teams, managing technology vendors and providing technical guidance for business and technology initiatives. The ideal candidate should possess strong technical leadership, infrastructure management, cybersecurity, risk management and governance capabilities, with a good understanding of Bank Negara Malaysia’s Risk Management in Technology (RMiT), Business Continuity Management (BCM), ISO 27001/ISMS, Personal Data Protection requirements and applicable regulatory or contractual requirements. Experience in the banking, financial services, insurance, healthcare or Third-Party Administrator (TPA) industry will be an added advantage.

Key Responsibilities:

1. IT Infrastructure & Operations

Lead and manage day-to-day IT infrastructure operations, including servers, virtualization, storage, networks, firewalls, connectivity and other core infrastructure, ensuring high availability, reliability, performance and capacity.

Oversee infrastructure maintenance, upgrades, patching, hardening, lifecycle and capacity planning, including technology refresh requirements and resolution of infrastructure incidents and service disruptions.

Establish and maintain infrastructure standards, configurations and operational procedures; ensure changes are properly assessed, documented, tested and implemented, and effectively manage infrastructure vendors and technical support partners.

2. Network & Security Infrastructure

Oversee network infrastructure, including firewalls, VPN, Internet connectivity, SD-WAN and related security controls, ensuring secure, reliable and resilient network operations.

Manage and review firewall rules, VPN access, network segmentation, access controls and security configurations to maintain appropriate infrastructure protection.

Work with service providers and vendors to investigate and resolve network, connectivity and infrastructure security issues, ensuring security controls are properly implemented and maintained.

3. Information Security Strategy & Governance

Develop, implement and maintain the organization’s information security strategy, roadmap, policies, standards, procedures and technical controls in alignment with business objectives and applicable regulatory and industry requirements.

Promote security-by-design principles across infrastructure, applications, projects and technology initiatives, ensuring security requirements are incorporated throughout the technology lifecycle.

Act as an internal information security advisor and consulting resource, providing guidance to management and relevant stakeholders on security matters.

4. Information Security Risk Management

Identify, assess and manage information security and technology risks across infrastructure, systems, applications, vendors, third parties and technology environments.

Establish, monitor and coordinate risk mitigation and remediation plans, ensuring outstanding security risks are addressed within agreed timelines.

Support security and technology risk assessments for new projects, systems, applications and technology changes, ensuring appropriate security requirements are identified and implemented.

5. Vulnerability & Security Management

Oversee vulnerability management activities, including vulnerability scanning, security assessments and penetration testing, and coordinate remediation with relevant IT teams and vendors.

Monitor emerging cybersecurity threats and assess their potential impact on the organization’s technology environment, infrastructure and security posture.

Ensure operating systems, infrastructure and security devices are appropriately patched, hardened and securely configured, with controls periodically reviewed for effectiveness.

6. Security Monitoring & Incident Response

Oversee security monitoring and security event management activities, including coordination with SOC or managed security service providers where applicable.

Lead the technical response to information security incidents covering detection, analysis, containment, eradication and recovery, while coordinating with internal departments, management and external parties during significant incidents.

Ensure security incidents are properly documented, investigated and followed by corrective and preventive actions, with appropriate controls implemented to minimize recurrence.

7. Identity & Access Management

Oversee infrastructure-related user access, privileged access and administrative accounts, ensuring least privilege, appropriate access control and segregation of duties principles are implemented.

Establish and maintain effective Joiner, Mover and Leaver (JML) processes and ensure periodic access reviews are performed for critical systems, privileged accounts and infrastructure.

Manage privileged access controls such as PAM where applicable, and collaborate with system owners and Information Security personnel to ensure access rights remain appropriate and properly reviewed.

8. Backup, Disaster Recovery & Business Continuity

Lead the development, implementation and maintenance of IT Disaster Recovery Plans (DRP), backup strategies, monitoring and recovery procedures to ensure critical systems have appropriate recovery capabilities.

Coordinate regular backup restoration, disaster recovery exercises and testing, ensuring recovery objectives are aligned with business requirements and Business Continuity Management (BCM) needs.

Participate in Business Impact Analysis (BIA) activities to identify critical systems, processes, dependencies and recovery requirements, and ensure weaknesses identified from DR exercises or incidents are properly addressed.

9. Audit, Compliance & Regulatory Requirements

Coordinate and support internal and external IT infrastructure and information security audits, maintaining appropriate evidence, documentation and records and working closely with auditors and relevant stakeholders.

Ensure audit findings, recommendations and remediation actions are properly tracked and completed within agreed timelines.

Support compliance with applicable regulatory, industry and contractual requirements, including Bank Negara Malaysia RMiT, Business Continuity Management, ISO 27001/ISMS, Personal Data Protection requirements and client-specific information security requirements.

10. Client Due Diligence & Security Assessments

Manage and coordinate client information security questionnaires, due diligence requests, IT assessments, audits and security reviews.

Coordinate responses with Infrastructure, Application, Data and other relevant teams, ensuring information provided is accurate, consistent and supported by appropriate evidence.

Provide relevant technical and security documentation to demonstrate the organization’s security posture and support client requirements.

11. Policy, Procedure & Documentation

Develop, review and maintain IT infrastructure, operations and information security policies, procedures, SOPs, operational standards and technical guidelines.

Ensure infrastructure, security and operational processes are properly documented, implemented and consistently followed across relevant teams.

Periodically review and update policies and procedures to reflect changes in technology, regulatory requirements, security risks and business operations.

Lead, manage and mentor Infrastructure and Information Security personnel by defining responsibilities, objectives, KPIs, performance expectations and appropriate technical coverage.

Ensure effective resource allocation and operational support across IT infrastructure and security functions to meet business requirements.

Manage infrastructure and security vendors, service providers and external consultants, including performance, service levels, technical deliverables and third-party technology and security risks.

13. Security Awareness & Continuous Improvement

Support and coordinate information security awareness initiatives and training programs to promote a strong security culture across the organization.

Stay current with emerging cybersecurity threats, technologies, regulatory requirements and industry practices, assessing opportunities to strengthen the organization’s security posture.

Drive continuous improvement in infrastructure resilience, security and operational effectiveness through process enhancement, automation, monitoring and improved technology controls.

Act as a key technical and information security advisor to the IT HOD and senior management, providing recommendations on infrastructure, cybersecurity, technology investments and risk matters.

Collaborate with Application, Project Management, Data, HR, Finance, Legal, Risk and other business functions to ensure technology initiatives meet infrastructure, availability, security and business requirements.

Participate in technology projects and provide appropriate technical and security guidance throughout implementation, while performing other duties as assigned.

QUALIFICATIONS

Candidate must possess at least a Bachelor's Degree in Information Technology, Computer Science, Cybersecurity or equivalent.

Relevant professional certifications such as CISSP, CISM, CISA, CEH, CCNA, CCNP, Fortinet, Palo Alto, Microsoft, VMware or equivalent are highly desirable.

Candidates with relevant combinations of qualifications, certifications and practical experience will also be considered.

Experiences:

Minimum 5–8 years of experience in IT infrastructure, information security, cybersecurity or related IT functions.

At least 2 years of experience in a leadership or managerial role.

Proven experience managing IT infrastructure and operations.

Proven experience in information security management and security controls.

Experience with network, firewall, server, virtualization, backup and disaster recovery technologies.

Experience managing internal and external audits, including preparation, coordination and remediation of audit findings.

Experience managing client security assessments and due diligence requests.

Experience developing and maintaining BCP and DRP.

Experience conducting or overseeing Business Impact Analysis (BIA).

Strong understanding of information security management frameworks and practices, including ISO 27001, ISMS, ITIL and COBIT.

Good understanding of BNM RMiT and BCM requirements will be an advantage.

Experience in banking, finance, insurance, healthcare or TPA environments will be an advantage

MiCare Healthtech Holdings Pte Ltd (“MiCare”) is a regional, leading managed care organization headquartered in Singapore that administers, processes, and manages medical claims on behalf of insurance companies and self-insured corporate clients. The company serves more than 13 million members in Malaysia, Thailand, and the Philippines through its strong relationships with over 45 insurers and 6,500 corporate clients in Southeast Asia. MiCare has an extensive provider network of over 5,000 hospitals, clinics, and pharmacies. MiCare is a joint venture between Zuellig Group, Mitsui & Co (Asia Pacific) (“Mitsui”), and the International Finance Corporation (“IFC”), with Mitsui and IFC investing US$60 million into MiCare in 2021.

Zuellig Group is one of Asia's largest healthcare services groups providing distribution, digital and commercial solutions. The company has grown to become a US$13 billion business covering 13 markets with over 12,000 employees.

Mitsui is a Japanese conglomerate that focuses its business model on growth through trading, business management, and project development. Listed on the Tokyo Stock Exchange with a market capitalization of over US$40 billion, Mitsui brings a regional network of healthcare assets, including strong relationships with providers as well as extensive experience in digital transformation. Of note, Mitsui is the single largest shareholder of IHH Healthcare Bhd, the largest private hospitals group in Pan-Asia, operating 80 hospitals in 10 countries under a portfolio of brands such as Acibadem, Pantai, Fortis and Gleneagles.

IFC, a member of the World Bank Group, is the largest development institution focused on the private sector in emerging markets. IFC has an active portfolio of $2 billion in health care companies in emerging markets. Through these investments, IFC helps private providers meet the soaring demand for health care and supports governments in their goal of reaching Universal Health Coverage by 2030.

MiCare Healthtech Holdings Pte Ltd (“MiCare”) is a regional, leading managed care organization headquartered in Singapore that administers, processes, and manages medical claims on behalf of insurance companies and self-insured corporate clients. The company serves more than 13 million members in Malaysia, Thailand, and the Philippines through its strong relationships with over 45 insurers and 6,500 corporate clients in Southeast Asia. MiCare has an extensive provider network of over 5,000 hospitals, clinics, and pharmacies. MiCare is a joint venture between Zuellig Group, Mitsui & Co (Asia Pacific) (“Mitsui”), and the International Finance Corporation (“IFC”), with Mitsui and IFC investing US$60 million into MiCare in 2021.

Zuellig Group is one of Asia's largest healthcare services groups providing distribution, digital and commercial solutions. The company has grown to become a US$13 billion business covering 13 markets with over 12,000 employees.

Mitsui is a Japanese conglomerate that focuses its business model on growth through trading, business management, and project development. Listed on the Tokyo Stock Exchange with a market capitalization of over US$40 billion, Mitsui brings a regional network of healthcare assets, including strong relationships with providers as well as extensive experience in digital transformation. Of note, Mitsui is the single largest shareholder of IHH Healthcare Bhd, the largest private hospitals group in Pan-Asia, operating 80 hospitals in 10 countries under a portfolio of brands such as Acibadem, Pantai, Fortis and Gleneagles.

IFC, a member of the World Bank Group, is the largest development institution focused on the private sector in emerging markets. IFC has an active portfolio of $2 billion in health care companies in emerging markets. Through these investments, IFC helps private providers meet the soaring demand for health care and supports governments in their goal of reaching Universal Health Coverage by 2030.

Researching careers? Find all the information and tips you need on career advice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Claims Assessor (Shah Alam)
Claims Assessor (Shah Alam)

MiCare Sdn Bhd • Shah Alam

On-site
MYR 45,000 - 78,000
Client Servicing Executive (Account Management- Shah Alam)
Client Servicing Executive (Account Management- Shah Alam)

MiCare Sdn Bhd • Shah Alam

On-site
MYR 45,000 - 71,000
Great Bonus 2x per year
Free Parking
Customer Service Executive (Salary +Shift Allowance RM3000+)
Customer Service Executive (Salary +Shift Allowance RM3000+)

MiCare Sdn Bhd • Shah Alam

On-site
MYR 30,000 - 36,000
Free Parking
Information & Cybersecurity, Consultant
Information & Cybersecurity, Consultant

AIA Malaysia • Kuala Lumpur

On-site
MYR 70,000 - 90,000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Sr Executive / Asst Manager - Provider Management
Sr Executive / Asst Manager - Provider Management

IA International Assistance Sdn Bhd • Petaling Jaya

On-site
MYR 120,000 - 180,000
Assistant Risk Management and Business Resilience Manager
Assistant Risk Management and Business Resilience Manager

IHH Healthcare Malaysia • Kuala Lumpur

On-site
MYR 85,000 - 125,000
Biz Process Improvements, Digital Transformation
Biz Process Improvements, Digital Transformation

iCrest Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Manager Business Solutions, MediAsas
Manager Business Solutions, MediAsas

PROTECTHEALTH CORPORATION SDN. BHD. • Cyberjaya

On-site
MYR 180,000 - 280,000
Information & Cybersecurity, Consultant
Information & Cybersecurity, Consultant

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 80,000 - 100,000