Senior IT Security

Tribe Digital

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Performance bonus
Medical insurance
Certification sponsorship
Career development opportunities

Job summary

Tribe Digital in Malaysia seeks an experienced IT Security & Endpoint Management leader to own identity, endpoint, and network access controls for our agent workforce.

The role ensures compliance with client requirements, manages patching and device management, and acts as the escalation point for IT support. You will enforce policy precedence and coordinate with client teams.

Qualifications

  • Bachelor's degree or equivalent in a relevant field.
  • 3+ years in IT security or identity & access management.
  • Experience with Entra ID (Azure AD) and Active Directory.

Responsibilities

  • Administer Microsoft Entra ID accounts and integrate with Active Directory.
  • Deploy and support YubiKey MFA devices for all agents.
  • Define, document, and enforce password policies per client requirements.
  • Manage conditional access, RBAC, and privileged identity management.
  • Ensure identity configurations comply with client setup requirements.
  • Manage all agent laptops via Microsoft Intune, including enrollment and compliance.
  • Enforce USB port disablement and allow USB-C for YubiKey MFA on all endpoints.
  • Ensure endpoints run Windows 11 and no end-of-life software.
  • Own monthly endpoint and server patch cadence, deployment scheduling and remediation.
  • Maintain software inventory and perform updates.

Skills

Entra ID
Active Directory
YubiKey MFA
Intune
SSE/SASE
Windows 11
Patch management
RBAC
EDR tools
PowerShell

Education

Bachelor's degree in Computer Science, IT, Cybersecurity, or related

Tools

Autopilot
WSUS

Job description

We are seeking an experienced IT Security & Endpoint Management to own and operate the security, identity, endpoint, and network access controls for our agent workforce. This role is critical to ensuring compliance with our client mandatory security requirements, including Entra ID, Intune endpoint management, YubiKey MFA, SSE-enforced web filtering, and strict USB port controls.

The successful candidate will act as the primary technical authority for endpoint security and identity, manage patching and compliance, and serve as the escalation point for IT support operations. Configuration requirements will take precedence in the event of conflicts, and this role must ensure full alignment.

About the Role

We are seeking an experienced IT Security & Endpoint Management to own and operate the security, identity, endpoint, and network access controls for our agent workforce. This role is critical to ensuring compliance with our client mandatory security requirements, including Entra ID, Intune endpoint management, YubiKey MFA, SSE-enforced web filtering, and strict USB port controls.

The successful candidate will act as the primary technical authority for endpoint security and identity, manage patching and compliance, and serve as the escalation point for IT support operations. Configuration requirements will take precedence in the event of conflicts, and this role must ensure full alignment.

Key Responsibilities
Identity & Access Management
  • Administer Microsoft Entra ID accounts and integrate them with Pinnacle's Active Directory.

  • Deploy, manage, and support YubiKey MFA devices for all agents accessing client applications.

  • Define, document, and enforce password policies in line with client requirements.

  • Manage conditional access, role-based access control (RBAC), and privileged identity management.

  • Ensure identity configurations comply with client mandatory setup requirements.

Endpoint Security & Management
  • Manage all agent laptops via Microsoft Intune, including enrollment, configuration profiles, compliance policies, and conditional access.

  • Enforce USB port disablement across all endpoints, while enabling USB-C access for YubiKey MFA devices.

  • Ensure all endpoints run Windows 11 and comply with the "no end-of-life software" mandate.

  • Own the monthly endpoint and server patching cadence, including deployment scheduling, reboot management, compliance tracking, and remediation of failed patches.

  • Maintain an accurate software inventory and manage application deployment and updates.

Network, SSE & Platform Access
  • Configure agent laptop access to software and other non-client platforms to route through client SSE.

  • Enforce client web filtering and internet access policies on all agent endpoints.

  • Troubleshoot SSE connectivity, latency, and access issues.

  • Ensure no unauthorized bypass of SSE or web filtering controls.

IT Support & Operations
  • Lead and mentor the IT support team, defining roles, responsibilities, and escalation paths.

  • Manage firewalls, Active Directory, and related infrastructure.

  • Oversee support coverage models, response arrangements, and escalation procedures.

  • Coordinate with client IT team on compliance, audits, and configuration conflicts.

  • Maintain documentation for all security configurations, policies, and procedures.

Physical Security & Site Access
  • Manage and review card access system logs for the primary site.

  • Enforce after-office-hours and premises entry policies.

  • Configure card access systems to enforce client access policy (e.g., no entry after office hours).

  • Oversee access management and monitoring for the alternate site (hot-desking or dedicated office).

Compliance & Governance
  • Ensure all IT configurations comply with client mandatory requirements.

  • Escalate and resolve conflicting configurations, ensuring client requirements prevail.

  • Support internal and external audits related to identity, endpoint, and access security.

  • Maintain compliance tracking dashboards and reports for management.

Requirements
Education
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).

Experience
  • 3+ years of experience in IT security, endpoint management, or identity & access management.

  • Proven experience with Microsoft Entra ID (Azure AD) and Active Directory.

  • Hands‑on experience with Microsoft Intune for endpoint management and compliance.

  • Experience deploying and managing YubiKey / FIDO2 MFA devices.

  • Experience with SSE / SASE platforms (e.g., Zscaler, Netskope, Microsoft Defender for Cloud Apps).

  • Strong background in Windows 11 endpoint hardening and USB port control.

  • Experience with patch management tools and compliance tracking.

Technical Skills
  • Microsoft Entra ID, Active Directory, Group Policy

  • Microsoft Intune, Autopilot, Conditional Access

  • YubiKey / FIDO2 MFA deployment

  • SSE / SASE configuration and troubleshooting

  • Firewall management (e.g., Fortinet, Palo Alto, Cisco)

  • PowerShell scripting for automation

  • Patch management (Intune, WSUS, or similar)

  • Endpoint detection and response (EDR) tools

  • Network security and web filtering

Soft Skills
  • Strong stakeholder management and communication skills.

  • Ability to work under compliance-driven constraints.

  • Analytical and problem-solving mindset.

  • Ability to lead and mentor a team.

  • Detail-oriented with strong documentation skills.

Certifications (Preferred)
  • Microsoft Certified: Identity and Access Administrator Associate

  • Microsoft Certified: Endpoint Administrator Associate

  • Microsoft Certified: Security, Compliance, and Identity Fundamentals

  • CompTIA Security+

  • CISSP or CISM (advantageous)

Key Performance Indicators (KPIs)
  • 100% endpoint compliance with client Intune and security policies.

  • 100% patch compliance within agreed monthly cadence.

  • Zero unauthorized USB port usage.

  • 100% of agent access to Orencloud and non-client platforms routed via SSE.

  • Timely resolution of identity, endpoint, and access issues per SLA.

  • Successful audit outcomes with no critical findings.

  • Documented and enforced after-hours access policies.

Working Conditions
  • Based at the primary site in Malaysia.

  • Occasional travel to the alternate site as required.

  • May require after-hours work during patching windows or incident response.

  • Must comply with client security policies and precedence requirements.

Compensation & Benefits
  • Competitive salary based on experience.

  • Performance bonus.

  • Medical and insurance benefits.

  • Professional certification sponsorship.

  • Career development opportunities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Security
Senior IT Security

Tribe Business Services Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Performance bonus
Medical and insurance benefits
Professional certification sponsorship
Information Security Operations Lead (Penang / Johor)
Information Security Operations Lead (Penang / Johor)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Endpoint Security & Identity Lead
Endpoint Security & Identity Lead

Tribe Business Services Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Performance bonus
Medical and insurance benefits
Professional certification sponsorship
Windows OS/ Desktop Security Developer
Windows OS/ Desktop Security Developer

Aventra Group • Kuala Lumpur

On-site
MYR 60,000 - 80,000
Competitive compensation and benefits
Training and certification support
Career growth opportunities
SCCM & Intune Engineer (1 year contract)
SCCM & Intune Engineer (1 year contract)

Gateway Search • Kuala Lumpur

On-site
MYR 67,000 - 112,000
Senior Wintel Security Engineer / Infrastructure Security Enginee
Senior Wintel Security Engineer / Infrastructure Security Enginee

Unison Group • Kuala Lumpur

On-site
MYR 120,000 - 190,000
Microsoft Security Engineer
Microsoft Security Engineer

Noventiq India, Ltd. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Bonus and allowances
Training opportunities
Birthday day off
+3
IT Administrator
IT Administrator

EdgeConneX • Kuala Lumpur

On-site
MYR 78,000 - 123,000
Competitive benefits
Workplace Technology Engineer
Workplace Technology Engineer

Getronics • Kuala Lumpur

On-site
MYR 90,000 - 180,000
Senior / Security Engineer (Malaysia Office)
Senior / Security Engineer (Malaysia Office)

ABPGroup Pte Ltd • Kuala Lumpur

On-site
MYR 90,000 - 130,000