Position Title: Senior/Manager, IT Security Management
Department: IT Security & Compliance Management
Unit: IT Security Management
To: Head, IT Security & Compliance Management
Location: AirBorneo Airways Headquarters, Kuching, Sarawak
Position Overview
The Senior/Manager, IT Security Management is responsible for the strategic design, implementation, and oversight of AirBorneo’s cybersecurity posture. This role ensures the protection of the airline’s digital assets, critical aviation systems, and passenger data against evolving cyber threats. The position serves as the primary technical authority for security governance, risk management, and incident response, coordinating closely with sister IT departments to support AirBorneo’s 24/7 global airline operations.
Key Responsibilities
A. Security Strategy & Governance
- Own the roadmap for enterprise-wide security architecture, ensuring alignment with the Zero Trust Network Access (ZTNA) framework.
- Develop and enforce IT security policies, standards, and procedures based on industry best practices and internal hardening standards.
- Maintain the security service catalogue and provide strategic input for the protection of National Critical Information Infrastructure (NCII).
B. Cyber Defence & Operations
- Lead technical security operations, overseeing endpoint security, threat protection, and vulnerability management.
- Manage advanced security solutions such as Post-Quantum Cryptography (PQC) readiness and secure remote access technologies.
- Direct incident response activities, ensuring rapid containment and remediation of security breaches to maintain business continuity.
C. Compliance & Risk Management
- Ensure full compliance with the Cyber Security Act 2024 (Act 854), PDPA 2024, ICAO Annex 17 – Security guidelines/standards, etc, where applicable.
- Coordinate regular security audits, penetration testing, and risk assessments across regional offices and airport facilities.
- Manage local backup and disaster recovery validation for critical workstations and infrastructure.
D. Automation & Secure Integration
- Drive the adoption of automated security orchestration, automation, and response (SOAR) workflows to improve detection efficiency.
- Partner with IT Application teams to integrate security “hooks” and automated software distribution security checks within the CI/CD pipeline.
- Implement automated system updates and remote security patching policies in coordination with other IT sister departments.
E. Identity & Access Management (IAM)
- Enforce the principle of least privilege through robust user access management and hardware provisioning controls.
- Oversee Active Directory and Office 365 security configurations to prevent unauthorized access and data leakage.
F. Vendor & Security Service Management
- Manage relationships with third‑party cybersecurity vendors and managed security service providers (MSSP).
- Monitor and enforce vendor Service Level Agreements (SLAs) regarding security patch releases and emergency support.
- Lead and upskill a team of security analysts and engineers, fostering a culture of security awareness across AirBorneo.
Provide monthly security posture reports, equipment lifecycle forecasting, and threat intelligence briefings to IT Leadership.
Qualifications & Experience
Required
- Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field.
- 7–10 years of experience in IT Security Management or equivalent, with at least 5 years dedicated to IT Security or Governance.
- 3+ years in a leadership or senior supervisory role.
- Deep technical expertise in:
- Endpoint Detection and Response (EDR) and Zero Trust architecture.
- Cloud security and on‑premise network resilience.
- Identity administration (Active Directory/Office 365).
- Experience managing high‑pressure, 24/7 security monitoring environments such as Security Operations Centre (SOC).
Preferred
- Experience with multi‑site regional management and remote forensic tools.
- Knowledge of Enterprise Architecture frameworks (e.g., TOGAF 10) to align security with business goals.
- Certified Information Systems Security Professional (CISSP) or CISM.
- CompTIA Security+ or Network+.
- Certified Associate in Project Management (CAPM), Project Management Professional (PMP), PRINCE2, etc.