Senior Manager, Digital Security

AIA Digital+

Kuala Lumpur

On-site

MYR 180,000 - 360,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

AIA Digital+ is seeking an experienced leader to drive global endpoint security across Windows, Linux, and cloud workloads. You will own strategy, standards, and governance for EDR/AV, device hardening, and policy management, coordinating with SOC and IR teams to improve detection, response, and posturing.

The role requires 8+ years in information security with 3+ years in management, deep knowledge of policy frameworks (CIS, MITRE ATT&CK), and hands-on experience with enterprise EDR platforms.

Qualifications

  • 8+ years in information security / endpoint security engineering or operations, incl. 3+ years in leadership.
  • Bachelor’s degree in a relevant field or equivalent practical experience.
  • Hands-on experience managing enterprise EDR and endpoint protection platforms at scale.

Responsibilities

  • Own global endpoint security product strategy and roadmap across EDR/AV and related controls.
  • Lead engineering design for endpoint policies and baselines using Intune, GPO, and config management tools.
  • Ensure 90%+ compliant deployment and update posture for endpoints and cloud workloads.
  • Operational ownership of endpoint security services: incident triage, change governance, problem management.
  • Partner with SOC/IR to optimize detection logic and containment actions; reduce MTTR.
  • Drive SIEM/data integration for endpoint telemetry and reliable log pipelines.

Skills

Endpoint security
Leadership
ITIL
Cloud security
SIEM
Incident response

Education

Bachelor’s degree in Computer Science, Computer Engineering, Information Systems, or related field

Tools

ProofPoint
Zscaler
Intune/MDM
GPO
CIS Benchmarks
MITRE ATT&CK
Azure
AWS
AliCloud

Job description

Provide technical and operational leadership for AIA’s global endpoint security capability—owning the strategy, engineering standards, and day-to-day governance of EDR/AV and endpoint hardening controls across Windows, Linux, and cloud workloads. Ensure high tool health and coverage, accelerate detection and response outcomes through SIEM/SOAR integrations and automation, and partner with SOC/IR, workplace/infra teams, and business stakeholders to reduce endpoint risk while maintaining user productivity.

Roles and Responsibilities
  • Own global endpoint security product strategy and roadmap (EDR/AV, exploit mitigation, device control, host firewall, application control), aligning to security architecture, regulatory expectations, and business priorities.
  • Lead engineering design for endpoint policies and baselines across Microsoft Intune, GPO, and configuration management tooling; define reusable standards for hardening, exceptions, and drift management.
  • Ensure effective security coverage across user endpoints, servers, and cloud workloads; drive agent lifecycle management (packaging, deployment, upgrades, health monitoring, decommissioning) and achieve/maintain ≥90% compliant deployment and update posture.
  • Operational ownership of endpoint security services: incident triage and escalation, problem management, major incident participation, change governance, and continuous service improvement (ITIL-aligned).
  • Partner closely with SOC and Incident Response teams to optimize detection logic, response playbooks, and containment actions (e.g., isolate host, kill process, quarantine file); reduce MTTD/MTTR for endpoint-driven incidents.
  • Drive SIEM/data integration for endpoint telemetry and alerts; ensure reliable log pipelines, enrichment, and normalization to enable analytics and reporting at scale.
  • Lead integration of adjacent security controls with endpoint platforms (e.g., email/web protection, secure web gateways, threat gateways such as Proofpoint and Zscaler) to improve end-to-end threat prevention and response.
  • Own governance for exception handling and risk acceptance: define criteria, technical compensating controls, approval workflow, and periodic review to minimize long-lived bypasses.
  • Drive vulnerability and exposure reduction through secure configuration baselines (e.g., CIS Benchmarks), mapping to frameworks (e.g., MITRE ATT&CK) and collaborating with patch/vulnerability management teams on prioritization.
  • Define service KPIs/SLAs, dashboards, and operational reporting for leadership and country stakeholders; run regular service reviews to improve adoption, stability, and user experience.
  • Lead vendor management for endpoint security tools and managed services: contract governance, performance management, roadmap influence, and cost optimization.
  • Coach and mentor engineers/analysts; build operating procedures, knowledge base articles, and runbooks to scale consistent support across regions.
  • Monitor emerging threats and platform changes (Windows, Linux, macOS where applicable, and cloud); continuously evaluate new features and recommend technical improvements with clear risk/​value trade‑offs.
  • Lead the strategy, implementation, and continuous improvement of endpoint security solutions, including EDR platforms.
  • Oversee endpoint security policy management across Intune and Group Policy Objects (GPO).
  • Drive feature enhancements and operational excellence in endpoint security tools.
  • Expand coverage on agent guardrails and runtime security to strengthen overall endpoint resilience.
  • Collaborate with IT, security operations, and compliance teams to align endpoint security with organizational goals.
  • Monitor emerging threats and industry trends to proactively adapt endpoint security measures.
  • Provide leadership, mentorship, and guidance to technical teams supporting endpoint security operations.
  • Experience managing endpoint security Products
  • Ability to manage the EDR and AV products in the estate
  • Strong understanding of ITIL process ie Incident Change Problem Major Incident Management would be an advantage
  • Proficient on these Endpoint principal areas.
  • o EndPoint Protection - Antivirus, HIPS, EDR
  • o Strong knowledge of Windows, Linux and Cloud
  • o COTS Security Hardening - Gold Images, ProofPoint, Exchange Online Protection, Threat Gateways
  • o Vulnerability Management - CIS Benchmarks, MITRE ATT&CK Framework
  • Manage and troubleshoot issues related to application, ensure stakeholder management for potential issues on endpoint tools
  • Coordinate with in country stakeholders to ensure there is atleast 90% compliance on deployment of agents and their updates
  • Drive integration of multiple tools such as ProofPoint, ZScaler with endpoint EDR solution.
  • 8+ years’ experience in information security / endpoint security engineering or operations, including 3+ years in a leadership or people-management role.
  • Bachelor’s degree in Computer Science, Computer Engineering, Information Systems, or a related field (or equivalent practical experience).
  • Hands‑on experience managing enterprise EDR and endpoint protection platforms at scale (policy design, deployment, upgrades, troubleshooting, and reporting).
  • Strong knowledge of endpoint OS and enterprise management: Windows (including GPO), Intune/MDM, and Linux fundamentals; understanding of identity and access concepts and how they impact endpoint controls.
  • Experience working closely with Security Operations Centers, Incident Response, and security architecture / systems engineering to deliver detection and response outcomes.
  • Experience with cloud environments (Azure, AWS, and/or AliCloud), including endpoint/workload telemetry and control integration.
  • Working knowledge of SIEM integration and data pipelines for security telemetry; ability to define log requirements and validate end-to-end ingestion quality.
  • Knowledge of automation/configuration management (e.g., scripting, orchestration) to improve operational efficiency and reduce manual effort.
  • Strong problem-solving and analytical skills; able to translate complex technical issues into risk, options, and recommendations for stakeholders.
  • Excellent written and verbal communication skills; ability to influence across global, cross-functional teams and at multiple seniority levels.
Preferred / Advantage
  • ITIL Foundation (or demonstrated experience running incident/change/problem management).
  • Security certifications such as CISSP, CISM, GCED/GCIA, or vendor certifications relevant to EDR/endpoint platforms.
  • Experience implementing security baselines (e.g., CIS) and working with threat frameworks (e.g., MITRE ATT&CK) for control mapping and detection engineering.
  • Experience operating in a regulated financial services environment and supporting audits, control testing, and evidence production.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Hong Kong and Macau • Cyberjaya

On-site
MYR 120,000 - 160,000
Competitive salary
Health insurance
Professional development opportunities
Microsoft Defender for Endpoint (MDE) SME - Implementation Team Lead
Microsoft Defender for Endpoint (MDE) SME - Implementation Team Lead

Hong Kong Unison Limited • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Microsoft Defender for Endpoint (MDE) SME - Implementation Team Lead
Microsoft Defender for Endpoint (MDE) SME - Implementation Team Lead

Unison Group • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Global Head of Endpoint Security & EDR Strategy
Global Head of Endpoint Security & EDR Strategy

AIA Digital+ • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Information Security Specialist – Endpoint Security
Information Security Specialist – Endpoint Security

HTC Global Services • Kuala Lumpur

On-site
MYR 110,000 - 170,000
EndPoint Security Subject Matter Expert
EndPoint Security Subject Matter Expert

DXC Technology • Petaling Jaya

On-site
MYR 120,000 - 180,000
DXC University
Flexible leave options
Volunteer days
IT Security Operation Lead
IT Security Operation Lead

Jobtailor • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Manager Endpoint Protection (Operation)
Manager Endpoint Protection (Operation)

Telekom Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Information Technology Operations Engineer
Information Technology Operations Engineer

Confidential Jobs • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IT Executive - Security Operations
IT Executive - Security Operations

Genting Malaysia • Kuala Lumpur

On-site
MYR 67,000 - 112,000