Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Tribe Digital in Malaysia seeks an experienced IT Security & Endpoint Management leader to own identity, endpoint, and network access controls for our agent workforce.
The role ensures compliance with client requirements, manages patching and device management, and acts as the escalation point for IT support. You will enforce policy precedence and coordinate with client teams.
We are seeking an experienced IT Security & Endpoint Management to own and operate the security, identity, endpoint, and network access controls for our agent workforce. This role is critical to ensuring compliance with our client mandatory security requirements, including Entra ID, Intune endpoint management, YubiKey MFA, SSE-enforced web filtering, and strict USB port controls.
The successful candidate will act as the primary technical authority for endpoint security and identity, manage patching and compliance, and serve as the escalation point for IT support operations. Configuration requirements will take precedence in the event of conflicts, and this role must ensure full alignment.
We are seeking an experienced IT Security & Endpoint Management to own and operate the security, identity, endpoint, and network access controls for our agent workforce. This role is critical to ensuring compliance with our client mandatory security requirements, including Entra ID, Intune endpoint management, YubiKey MFA, SSE-enforced web filtering, and strict USB port controls.
The successful candidate will act as the primary technical authority for endpoint security and identity, manage patching and compliance, and serve as the escalation point for IT support operations. Configuration requirements will take precedence in the event of conflicts, and this role must ensure full alignment.
Administer Microsoft Entra ID accounts and integrate them with Pinnacle's Active Directory.
Deploy, manage, and support YubiKey MFA devices for all agents accessing client applications.
Define, document, and enforce password policies in line with client requirements.
Manage conditional access, role-based access control (RBAC), and privileged identity management.
Ensure identity configurations comply with client mandatory setup requirements.
Manage all agent laptops via Microsoft Intune, including enrollment, configuration profiles, compliance policies, and conditional access.
Enforce USB port disablement across all endpoints, while enabling USB-C access for YubiKey MFA devices.
Ensure all endpoints run Windows 11 and comply with the "no end-of-life software" mandate.
Own the monthly endpoint and server patching cadence, including deployment scheduling, reboot management, compliance tracking, and remediation of failed patches.
Maintain an accurate software inventory and manage application deployment and updates.
Configure agent laptop access to software and other non-client platforms to route through client SSE.
Enforce client web filtering and internet access policies on all agent endpoints.
Troubleshoot SSE connectivity, latency, and access issues.
Ensure no unauthorized bypass of SSE or web filtering controls.
Lead and mentor the IT support team, defining roles, responsibilities, and escalation paths.
Manage firewalls, Active Directory, and related infrastructure.
Oversee support coverage models, response arrangements, and escalation procedures.
Coordinate with client IT team on compliance, audits, and configuration conflicts.
Maintain documentation for all security configurations, policies, and procedures.
Manage and review card access system logs for the primary site.
Enforce after-office-hours and premises entry policies.
Configure card access systems to enforce client access policy (e.g., no entry after office hours).
Oversee access management and monitoring for the alternate site (hot-desking or dedicated office).
Ensure all IT configurations comply with client mandatory requirements.
Escalate and resolve conflicting configurations, ensuring client requirements prevail.
Support internal and external audits related to identity, endpoint, and access security.
Maintain compliance tracking dashboards and reports for management.
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
3+ years of experience in IT security, endpoint management, or identity & access management.
Proven experience with Microsoft Entra ID (Azure AD) and Active Directory.
Hands‑on experience with Microsoft Intune for endpoint management and compliance.
Experience deploying and managing YubiKey / FIDO2 MFA devices.
Experience with SSE / SASE platforms (e.g., Zscaler, Netskope, Microsoft Defender for Cloud Apps).
Strong background in Windows 11 endpoint hardening and USB port control.
Experience with patch management tools and compliance tracking.
Microsoft Entra ID, Active Directory, Group Policy
Microsoft Intune, Autopilot, Conditional Access
YubiKey / FIDO2 MFA deployment
SSE / SASE configuration and troubleshooting
Firewall management (e.g., Fortinet, Palo Alto, Cisco)
PowerShell scripting for automation
Patch management (Intune, WSUS, or similar)
Endpoint detection and response (EDR) tools
Network security and web filtering
Strong stakeholder management and communication skills.
Ability to work under compliance-driven constraints.
Analytical and problem-solving mindset.
Ability to lead and mentor a team.
Detail-oriented with strong documentation skills.
Microsoft Certified: Identity and Access Administrator Associate
Microsoft Certified: Endpoint Administrator Associate
Microsoft Certified: Security, Compliance, and Identity Fundamentals
CompTIA Security+
CISSP or CISM (advantageous)
100% endpoint compliance with client Intune and security policies.
100% patch compliance within agreed monthly cadence.
Zero unauthorized USB port usage.
100% of agent access to Orencloud and non-client platforms routed via SSE.
Timely resolution of identity, endpoint, and access issues per SLA.
Successful audit outcomes with no critical findings.
Documented and enforced after-hours access policies.
Based at the primary site in Malaysia.
Occasional travel to the alternate site as required.
May require after-hours work during patching windows or incident response.
Must comply with client security policies and precedence requirements.
Competitive salary based on experience.
Performance bonus.
Medical and insurance benefits.
Professional certification sponsorship.
Career development opportunities.