Stand out for this role — generate a tailored resume and cover letter in about a minute.
Hong Leong Bank Berhad is seeking a Senior Security Advisor & Technical Project Manager to bridge cybersecurity engineering and business delivery. You will architect resilient security postures, oversee major incident responses, and lead end-to-end security projects across cloud and on‑premises environments.
This role requires 8+ years in information security with hands-on project leadership, deep security architecture experience (Zero Trust, NIST CSF, ISO 27001), and strong ability to translate
Overview
We are seeking an experienced and versatile Senior Security Advisor & Technical Project Manager to bridge the gap between complex cybersecurity engineering and high-impact business delivery.
In this dual-capability role, you will act as a trusted advisor to senior leadership and clients—architecting resilient security postures, steering critical incident response scenarios, and leading end-to-end technical security projects. You aren’t just overseeing project schedules; you have the deep technical chops to evaluate architectures, challenge technical designs, and guide incident handling when high‑severity threats emerge.
Security Maturity & Roadmaps: Evaluate organizational security maturity, compliance gaps and threat models to deliver actionable, business-aligned security roadmaps.
Architecture & Secure Design: Assess and guide secure architecture patterns across cloud, hybrid environments, zero‑trust frameworks, network defense, and IAM systems.
Architecture Review Board (ARB) Alignment: Serve as the primary security engineering liaison to the ARB, ensuring proposed solutions align smoothly with enterprise architecture standards.
Solution Advisory: Provide hands‑on security architecture guidance to project delivery teams from project inception through post‑implementation review.
Major Incident Oversight: Act as the senior technical escalation lead for high‑severity (P1/P2) security incidents, breach responses, threat hunting escalations, and operational outages.
Root‑Cause Analysis (RCA): Direct structural RCAs following critical incidents and conduct analyses on recurring operational bottlenecks, legacy technical debt, and friction points.
Continuous Optimization: Direct remediation roadmaps to ensure long‑term resilience and feed operational learnings back into delivery models to streamline engineering workflows.
RFP/RFI Technical Leadership: Drive technical requirements and security evaluations for RFIs/RFPs, working directly with Procurement to evaluate and select vendors, software, and third‑party partners.
Vendor & Scope Management: Partner with business stakeholders and procurement to ensure vendor SOWs align with delivery outcomes, cost controls, and operational expectations.
End-to-End Delivery: Scope, budget, resource, and manage complex cybersecurity projects (e.g., SIEM/SOAR deployments, Cloud Migrations, SOC transformations, Zero Trust implementations).
Cross‑Functional Leadership: Direct cross‑functional teams of security engineers, architects, developers, and third‑party vendors.
Executive Stakeholder Management: Bridge technical and executive conversations by translating complex technical risks into clear, business‑focused insights for C‑level leadership.
8+ years in information security, with at least 3–5 years leading complex technical projects or consulting engagements.
Proven track record evaluating and advising on enterprise security architectures and cloud security designs.
Direct, hands‑on experience in Incident Response (IR), threat analysis, or SOC operations.
Frameworks & Architecture: In‑depth knowledge of Security Architecture principles (Zero Trust, NIST CSF, ISO 27001).
Incident Response & Forensics: Practical understanding of the IR lifecycle (NIST / SANS framework), SIEM/EDR logs, packet analysis, and digital forensics fundamentals.
Cloud & Modern Infrastructure: Hands‑on familiarity with security controls in AWS, Azure, or GCP, as well as modern enterprise stack technologies (Container security, API security, CI/CD security).
HONG LEONG GROUP PERSONAL DATA POLICY
Hong Leong Group use personal data in accordance with the Hong Leong Group Privacy Notice (New Applicants) which can be found at http://www.hongleong.com/download/HLG_Privacy_Notice_New_Applicants.pdf
By providing to us your personal data, you hereby consent to the processing of your personal data with the said Privacy Notice.
To help fast track investigation, please include here any other relevant details that prompted you to report this job ad as fraudulent / misleading / discriminatory / salary below minimum wage.