Manager, IT Security

Pixlr Sdn Bhd

Subang Jaya

On-site

MYR 180,000 - 300,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Pixlr Sdn Bhd in Malaysia is seeking a hands-on IT Security Manager to own product, cloud, and corporate security across the company. You will define and run our security program from policy to incident response, partnering with Engineering, IT, Product, Legal, and Operations.

The role covers governance, risk & compliance, application and product security, cloud controls in AWS, access hygiene, privacy, and security enablement.

Qualifications

  • 6–10 years of experience in IT or application security, including ownership of security programmes or AppSec/CloudSec functions.
  • Strong hands-on experience with application security, secure SDLC practices, and vulnerability management.
  • Practical expertise in AWS security services, identity and access management, and cloud security monitoring.
  • Experience with common security tooling, including SAST, DAST, dependency scanning, secret management, and security logging platforms.
  • Solid understanding of security governance frameworks and regulatory principles, including ISO 27001, SOC 2, PDPA, and GDPR.
  • Proven ability to lead incident response activities and communicate security risks clearly to technical and non-technical stakeholders.
  • Nice-to-haves: Certifications: CISSP, CCSP, AWS Security Specialty, ISO 27001 Lead Implementer/Auditor.

Responsibilities

  • Establish and maintain security policy stack aligned with ISO 27001 and SOC 2 controls.
  • Conduct security risk assessments, vendor reviews, and data classification activities.
  • Support audit readiness with evidence collection, control testing, and maintenance of mappings.
  • Embed security in the SDLC with threat modelling, secure coding standards, and reviews.
  • Operate application security tooling in CI/CD pipelines for SAST/DAST and dependency analysis.
  • Guide engineering on secure design, OWASP Top 10, API security, and supply-chain risk.
  • Implement cloud security controls across AWS including IAM, logging, monitoring, and threat detection.
  • Define baseline hardening standards and policy-as-code controls for cloud and infra.
  • Drive container, serverless, and data protection security practices.
  • Develop and maintain incident response plans and coordinate with Engineering and IT.
  • Operate centralised security logging, alerting, and detection capabilities.
  • Maintain business continuity and disaster recovery security requirements.

Skills

Application security
Secure SDLC
Vulnerability management
AWS security
Identity & access management
Security monitoring
Incident response
Security governance

Tools

SAST
DAST
Dependency scanning
Secret management
Security logging platforms

Job description

We're hiring a hands‑on IT Security Manager to own product, cloud, and corporate security across Pixlr. You'll define and run our security program, from policy, AWS Cloud Security, to AppSec and incident response, while partnering closely with Engineering, IT, Product, Legal, and Operations.

The Job:
1. Security Governance, Risk & Compliance

Establish and maintain the security policy stack, aligned with ISO 27001, SOC 2 controls, and applicable privacy regulations (e.g., PDPA, GDPR).

Conduct security risk assessments, vendor and third-party reviews, and data classification activities.

Support audit readiness through evidence collection, control testing, and maintenance of security control mappings.

2. Application & Product Security

Embed security practices within the software development lifecycle, including threat modelling, secure coding standards, and security reviews.

Own and operate application security tooling within CI/CD pipelines, including static, dynamic, and dependency analysis.

Guide engineering teams on secure design principles, OWASP Top 10, API security, and supply‑chain risk considerations.

Implement and operate cloud security controls across AWS environments, including identity management, logging, monitoring, and threat detection services.

Define baseline hardening standards, guardrails, and policy‑as‑code controls for cloud and infrastructure environments.

Drive container, serverless, and data protection security practices, including encryption and key management.

Develop and maintain incident response plans and coordinate security incident handling with Engineering and IT teams.

Operate centralised security logging, alerting, and detection capabilities.

Maintain business continuity and disaster recovery security requirements, including backup and recovery verification.

5. Access Hygiene & Privacy

Enforce identity lifecycle management and access controls across cloud platforms, SaaS systems, and data environments.

Partner with Legal and Data teams on privacy impact assessments, data retention practices, and data loss prevention controls.

6. Culture, Enablement & Operations

Deliver security awareness and role‑based training for engineering, product, and operations teams.

Define and track security operational metrics to monitor risk, control coverage, and remediation effectiveness.

Balance security requirements with delivery velocity and cost considerations through cross‑functional collaboration.

The Person

6–10 years of experience in IT or application security, including ownership of security programmes or AppSec/CloudSec functions

Strong hands‑on experience with application security, secure SDLC practices, and vulnerability management

Practical expertise in AWS security services, identity and access management, and cloud security monitoring

Experience with common security tooling, including SAST, DAST, dependency scanning, secret management, and security logging platforms

Solid understanding of security governance frameworks and regulatory principles, including ISO 27001, SOC 2, PDPA, and GDPR

Proven ability to lead incident response activities and communicate security risks clearly to technical and non‑technical stakeholders

Nice‑to‑haves:

Certifications: CISSP, CCSP, AWS Security Specialty, ISO 27001 Lead Implementer/Auditor.

Experience with creative/EdTech or high‑scale consumer SaaS; exposure to SOC 2/ISO27001 journeys and GRC platforms (e.g., Drata/Vanta).

Container/Kubernetes security, serverless security, and SBOM/supply chain practices.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, IT Security
Manager, IT Security

Pixlr Group • Subang Jaya

On-site
MYR 180,000 - 240,000
Annual leaves
Medical cover
Subsidies
+2
Security Program Lead: AppSec, Cloud & IT
Security Program Lead: AppSec, Cloud & IT

Pixlr Group • Subang Jaya

On-site
MYR 180,000 - 240,000
Annual leaves
Medical cover
Subsidies
+2
IT Security Manager - Cloud, AppSec & Incident Response
IT Security Manager - Cloud, AppSec & Incident Response

Pixlr Sdn Bhd • Subang Jaya

On-site
MYR 180,000 - 300,000
Cloud Security Manager
Cloud Security Manager

StarHub • Petaling Jaya

On-site
MYR 240,000 - 360,000
Health insurance
Cloud Security Manager
Cloud Security Manager

StarHub • Petaling Jaya

On-site
MYR 240,000 - 360,000
Health insurance
Cloud Security Manager
Cloud Security Manager

Starhub Ltd • Petaling Jaya

On-site
MYR 180,000 - 240,000
Regional Assistant Manager, Security Engineering
Regional Assistant Manager, Security Engineering

ZUS COFFEE • Selangor

On-site
MYR 180,000 - 300,000
Product Security Engineer
Product Security Engineer

Agensi Pekerjaan Penta Consultancy Sdn. Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Application Security Specialist – AppSec / DevSecOps
Senior Application Security Specialist – AppSec / DevSecOps

Randstad Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 210,000
Product Security Architect
Product Security Architect

Confidential Careers • Kuala Lumpur

On-site
MYR 180,000 - 240,000