Specialist, IT CyberSecurity

Armstrong Asia

Sungai Buloh

On-site

MYR 120,000 - 180,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Armstrong Asia is seeking a Senior IT CyberSecurity Specialist to act as the group’s senior technical expert in information and cyber security. You will support protection of IT and OT environments, drive threat monitoring, incident response, vulnerability management, and access controls across sites.

Reporting to the Group IDT Director, you will translate security governance into site-level actions, work with stakeholders, and manage security tooling and vendors.

Qualifications

  • Experience in security operations and governance within a multinational environment.
  • Proven ability to implement and operate security controls and risk management.
  • Experience drafting security policy and standards aligned to ISO 27001/NIST CSF.

Responsibilities

  • Develop and maintain Group information security policy set, standards, and procedures.
  • Conduct cyber risk assessments and track remediation to closure.
  • Lead end-to-end investigation and response to security incidents.
  • Oversee security tooling and managed-security-service vendors at the operational level.
  • Maintain and test the cyber incident response plan and playbooks.
  • Define data protection controls and oversee identity and access management.

Skills

Security operations
SIEM/EDR tooling
Incident response
Vulnerability management
Identity and access management
Cloud security
ISO 27001 / NIST CSF
Scripting (PowerShell, Python)
Stakeholder management

Education

Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline

Tools

Microsoft Sentinel
Defender XDR
Splunk

Job description

The Specialist, IT CyberSecurity is the Group's senior technical expert for information and cyber security, supporting the protection of the Group's IT and operational technology environments across all sites.

Reporting to the Group IDT Director, the role provides the technical expertise behind the Group's security operations capability — threat monitoring, incident response, vulnerability management, endpoint and network security, and identity and access controls — and the governance framework that sits above it, covering security policy, standards, risk assessment, audit response, and regulatory compliance. The role combines hands-on technical delivery with policy development: it designs and operates security controls directly, and drafts the standards that, once approved by the Group IDT Director, site IT teams, application owners, and third-party providers are required to follow. It is an individual-contributor role without technical authority: its influence is exercised through the development of Group security strategy and operating plans, with ownership of those strategies and of the Group's security operations capability remaining with the Group IDT Director. The role works through site IT teams and functional stakeholders rather than direct reports, and managing security tooling and managed-service vendors at the operational level.

Responsibilities
Security Governance, Policy and Risk
  • Develop and maintain, for the Group IDT Director's approval, the Group information security policy set, standards, and procedures, and keep them aligned to recognised frameworks such as ISO 27001 and the NIST Cybersecurity Framework.
  • Conduct cyber risk assessments across Group and site systems, maintain the security risk register, and track remediation of identified risks to closure.
  • Recommend security requirements and standards for the Group IDT Director's endorsement, which site IT teams, application owners, and project teams are then required to apply, and support them in meeting these consistently.
  • Report the Group's security posture, incident trends, risk exposure, and improvement progress to the Group IDT Director and senior management.
  • Manage security tooling and managed-security-service vendors at the operational level, including service quality, licence utilisation, and cost.
Security Operations, Monitoring and Incident Response
  • Operate and continuously improve Group security monitoring, covering SIEM use cases, log sources, detection rules, and alert triage across endpoints, servers, network, and cloud services.
  • Lead investigation and response for security incidents end to end, including containment, eradication, recovery, root-cause analysis, and post-incident reporting.
  • Maintain and test the cyber incident response plan and playbooks, and coordinate escalation with site IT teams, business stakeholders, external responders, and authorities where required.
  • Oversee email, web, and endpoint protection controls — anti-malware, EDR, phishing defence, and content filtering — and tune them to reduce both risk and false positives.
  • Monitor threat intelligence relevant to the manufacturing and industrial sector, and translate it into detection, hardening, and awareness actions.
Vulnerability and Threat Management
  • Run the Group vulnerability management cycle — scanning, prioritization by risk and exploitability, remediation tracking, and verification — across servers, endpoints, network devices, and applications.
  • Define and monitor patching and hardening standards and baseline configurations, and report compliance against them by site and system.
  • Plan and coordinate penetration tests and security assessments, and drive remediation of findings to agreed timelines.
  • Assess the security of new systems, integrations, and cloud services before deployment, and recommend the controls required for approval.
  • Support security assurance for operational technology and manufacturing systems, including network segmentation between IT and OT environments.
Identity, Access and Data Protection
  • Develop and maintain identity and access management standards, including least-privilege, privileged-access controls, multi-factor authentication, and periodic access reviews and recertification.
  • Define and oversee data protection controls — classification, encryption, backup integrity, and data-loss prevention — for information held on premise and in cloud services.
  • Secure network and infrastructure architecture in conjunction with infrastructure teams, covering segmentation, firewall and remote-access policy, and secure configuration of cloud tenancies.
  • Assess and monitor the security of third parties and service providers, including due diligence, contractual security requirements, and periodic review.
Compliance, Audit and Security Awareness
  • Maintain readiness for internal and external audits, customer security assessments, and certification requirements, and coordinate responses and corrective actions.
  • Ensure Group practices meet applicable data-protection and regulatory obligations across the jurisdictions in which the Group operates, working with Legal and HR as required.
  • Design and run the Group security awareness programme, including training, phishing simulations, and targeted guidance for higher-risk roles.
  • Maintain security documentation, control evidence, and metrics to support governance reporting and audit enquiries.
Experience
  • Minimum 6 years of experience in IT, of which at least 3 years in a dedicated information security or cyber security role covering both operational security and governance.
  • Hands-on experience operating security monitoring and detection tooling (e.g. Microsoft Sentinel, Defender XDR, Splunk, or equivalent SIEM/EDR platforms), including alert triage and detection tuning.
  • Demonstrable experience leading security incident investigation and response end to end, including containment, root-cause analysis, and reporting to management.
  • Experience running a vulnerability management programme, including scanning tooling, risk-based prioritisation, patching standards, and remediation tracking across a distributed estate.
  • Experience implementing and operating identity and access management controls, including privileged access, multi-factor authentication, and access reviews.
  • Practical experience applying recognised security frameworks and standards (e.g. ISO 27001, NIST CSF, CIS Controls) and drafting security policy and standards.
  • Experience supporting internal and external audits, customer security assessments, or certification exercises, including evidence preparation and corrective action.
  • Experience securing cloud environments (Azure, AWS) and hybrid infrastructure, including network security, firewalls, and secure configuration baselines.
  • Experience working with a regional or global headquarters IT function within a multinational group, influencing security standards across sites without direct authority, is an advantage.
  • Experience in a manufacturing or industrial environment, including operational technology or IC S/SCADA security and IT/OT segmentation, is an advantage.
Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline.
  • Professional security certification is strongly preferred, e.g. CISSP, CISM, or CISA.
  • Cloud security certification is an advantage, e.g. Microsoft SC-200 or SC-100, AZ-500, or AWS Certified Security – Specialty.
  • ITIL Foundation or an equivalent service-management certification is an advantage.
  • Fluency in written and spoken English; additional Mandarin ability is an advantage given Group operations in China.
Technical
  • Strong grounding in security operations — threat detection, SIEM/EDR tooling, log analysis, and incident response.
  • Proficient in vulnerability management, secure configuration and hardening, patch management, and penetration-test remediation.
  • Sound knowledge of network, cloud, and endpoint security architecture, including segmentation, firewalls, encryption, and identity and access management.
  • Working knowledge of security frameworks, standards, and regulatory requirements (e.g. ISO 27001, NIST CSF, CIS Controls, data-protection legislation), and the ability to translate them into practical controls.
  • Competent with scripting and automation for security tasks and reporting (e.g. PowerShell, Python), and with security dashboards and metrics.
  • Informed view of emerging threats and of the security implications of AI tools and services adopted by the business.
Influence and Enablement
  • Develops Group security standards and drives their adoption by site IT teams, project teams, and vendors through advice, evidence, and escalation to the Group IDT Director, rather than direct authority.
  • Able to build credibility with technical teams and business stakeholders, and to influence adoption of security practices through advice and evidence.
  • Coordinates infrastructure, application, HR, Legal, and vendor parties to deliver consistent security outcomes across the Group.
Non-Technical
  • Strong analytical, investigative, problem-solving, and decision-making skills, with sound judgement under pressure.
  • Effective communication and stakeholder-management skills, able to explain security risk and trade-offs to non-technical stakeholders and senior management.
  • Ability to manage competing priorities across incidents, projects, and audit commitments, and to remain composed during security events.
  • Diligent and continuous-improvement mindset, with attention to detail, discretion in handling sensitive information, and a bias for documentation and automation.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Air Liquide • Petaling Jaya

On-site
MYR 120,000 - 180,000
Information Security C Governance Manager
Information Security C Governance Manager

Senheng Electric (KL) Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Security Engineer
Security Engineer

Mission Consultancy Services • Kuala Lumpur

On-site
MYR 80,000 - 120,000
Senior IT Security Architect
Senior IT Security Architect

Orsted • Kuala Lumpur

On-site
MYR 120,000 - 190,000
Senior IT Security Architect
Senior IT Security Architect

Orsted Asia Pacific • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Senior IT Security Architect
Senior IT Security Architect

Ørsted Group • Kuala Lumpur

On-site
MYR 367,000 - 572,000
IT Security Governance
IT Security Governance

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Regional Assistant Manager, Security Engineering
Regional Assistant Manager, Security Engineering

ZUS COFFEE • Selangor

On-site
MYR 180,000 - 300,000
Security Planning, SPX Express
Security Planning, SPX Express

SPX Express • Kuala Lumpur

On-site
MYR 100,440 - 167,400
Security Consultant
Security Consultant

NTT DATA • Kuala Selangor

On-site
MYR 120,000 - 180,000