KEY RESPONSIBILITIES
A. Microsoft 365 E3/E5 Platform Administration
The candidate willbe responsible forthe day-to-day administration and security configuration of the organization's Microsoft 365 E3/E5 tenant, serving as the primary M365 administrator:
- Administer user accounts,licences, groups (Entra ID), and conditional access policies in Microsoft Entra ID (formerly Azure AD) — including MFA enforcement,passwordlessauthentication setup, and guest access governance.
- Configure andmaintainMicrosoft Defender for Business for endpoint protection across all company devices — including threat policies, antivirus profiles, attack surface reduction rules, and alert triage.
- Deploy and manage Microsoft Intune for Mobile Device Management (MDM) and Mobile Application Management (MAM), covering device enrolment, compliance policies, and configuration profiles for Windows and mobile endpoints.
- Manage Microsoft Purview compliance solutions — including Data Loss Prevention (DLP) policies, sensitivity labels, retention policies, communication compliance, and eDiscovery asrequired.
- Administer Microsoft Defender for Office 365 (Plan 1/2 equivalent) — including Safe Links, Safe Attachments, anti-phishing policies, and spoof intelligence.
- Configure andmaintainMicrosoft Sentinel (SIEM) for log ingestion, security event correlation, alert rules, and incident tracking. Develop andmaintainbasic KQL queries for monitoring and reporting.
- Operate andmaintainMicrosoft Teams as the primary collaboration platform — including channel governance, meeting policies, external access controls, and Teams Phone configurations where applicable.
- Manage SharePoint Online and OneDrive for Business — including site provisioning, permission structures, external sharing policies, and information architecture in alignment with the organization's data classification policy.
- Maintain Exchange Online — including mail flow rules, anti-spam/anti-malware policies, shared mailboxes, distribution lists, and calendar management.
- Monitor the Microsoft 365 Secure Score dashboard and implement recommended improvement actions on a scheduledcadence. Produce monthly security posture reports for management review.
- Administer Microsoft 365 Backup and support disaster recovery testing as scheduled.
- Manage the migration path from Microsoft 365 Business plans to E3/E5 licensing asrequired— includinglicencereconciliation, feature parity checks, and user communications.
B. ISO/IEC 27001:2022 ISMS Implementation Support
The candidate will work directly with management to support the organization's ISO/IEC 27001:2022 certificationprogramme, acting as the primary documentation and operational owner for the ISMS:
- Maintain and regularly update the ISMS document registry — including the Statement of Applicability (SoA), Risk Register, Asset Register, and all mandatory ISMS records as required by Clauses 5, 6, 7, 8, 9, and 10 of ISO/IEC 27001:2022.
- Conduct scheduled information security risk assessments using the organization's defined risk assessmentmethodology—identifyingthreats, vulnerabilities, likelihood, and impact across information assets.
- Coordinate and document internal ISMS auditsin accordance withthe auditprogramme— including scheduling, checklist preparation, evidence collection, finding documentation, and corrective action tracking.
- Manage the corrective action and nonconformity register — tracking root cause analyses, remediation actions, responsible owners, and closure deadlines.
- Support the preparation and coordination of external surveillance audits and theinitialcertification audit by the appointed certification body (CB).
- Conduct and document information security awareness training sessions for all staff — covering phishing awareness, clean desk policy, data handling, acceptable use, and incident reporting procedures.
- Maintain the Supplier and Third-Party Security Assessment process — including vendor risk questionnaires, contract clause reviews, and periodic reassessments for critical service providers.
- Monitor the organization's compliance posture against all applicable controls in Annex A of ISO/IEC 27001:2022, andmaintain gap tracking documentation.
- Support management review meetings by preparing ISMS performance metrics, KPI dashboards, andinputdata covering audit results, incident statistics, risk treatment status, and security objective progress.
C. Security Policy Framework — Operationalization & Compliance
The organization hasestablisheda twelve-policy information security framework. The candidate will own the operationalization, monitoring, and periodic review of all policies:
- Information Security Policy (Master) —maintainas livingdocument; ensure all referenced sub-policiesremaincurrent and consistent.
- Acceptable Use Policy (AUP) — enforce via Intune compliance baselines and M365 communication compliance; conduct periodic user attestation exercises.
- Access Control Policy —maintainRole-Based Access Control (RBAC) matrices; conduct quarterly Privileged Access Reviews (PAR) across M365, SharePoint, and connected systems.
- Data Classification & Handling Policy — implement and enforce via Microsoft Purview sensitivity labels; ensure all shared documents are appropriately labelled before distribution to clients and partners.
- Incident Response Policy — maintain and periodically test the Incident Response Plan (IRP); manage the incident log and ensure timely escalation and reporting.
- Business Continuity & Disaster Recovery Policy — maintain BC/DR documentation; coordinate at least one tabletop exercise annually.
- Change Management Policy — operate the IT change request and approval workflow; maintain the change log.
- Password & Authentication Policy — enforce MFA, password less authentication, and password complexity via Entra ID Conditional Access and Intune. Administer the corporate password manager.
- Physical & Environmental Security Policy — conduct periodic office security walkthroughs; maintain the clean desk checklist and visitor log; coordinate with building management on physical access controls.
- Mobile Device & Remote Access Policy — enforce via Intune device compliance policies; maintain the approved device register.
- Third-Party & Supplier Security Policy — manage vendor onboarding security assessments; maintain the Approved Vendor Register.
- Data Retention & Destruction Policy — implement retention labels in M365 Purview; coordinate secure media disposal as required.
D. Endpoint, Network & Infrastructure Security Operations
As the organization's primary IT operator, the candidate will manage day-to-day security operations across the IT environment:
- Manage endpoint security posture across all Windows workstations and mobile devices — including patch management (Windows Update for Business / Intune), vulnerability scanning, and remediation tracking.
- Monitor and maintain the organization's email security posture — including DMARC, DKIM, and SPF records; review quarantine reports and respond to phishing reports from end users.
- Administer the corporate SSH (Tailscale) solution for remote access — managing user provisioning, connection policies, and access logs.
- Monitor network security appliances (firewall, switch management) in coordination with the organisation's managed services provider (MSP) or network vendor, and escalate anomalies.
- Operate Microsoft Sentinel — reviewing security alerts, investigating incidents, maintaining playbooks, and producing regular threat intelligence summaries relevant to the semiconductor and engineering sector.
- Perform vulnerability assessments using approved tools on a scheduled basis — documenting findings and tracking remediation in the risk register.
- Manage DNS, domain registrar settings, SSL certificate renewals, and web hosting security configurations as applicable.
- Support IT asset lifecycle management — procurement requests, asset tagging, configuration, deployment, and secure decommissioning.
E. SEMI E187 / E188 Cybersecurity Compliance Awareness
As a semiconductor facility design consultancy serving Tier-1 fabs, the organization must demonstrate awareness of and alignment with semiconductor-specific cybersecurity standards:
- Develop and maintain working knowledge of SEMI E187 (Cybersecurity Specification for Fab Equipment) and SEMI E188 (Malicious Software Prevention for Fab Equipment).
- Support the preparation of documentation and responses related to client cybersecurity requirements referencing SEMI E187 / E188, NIST SP 800-82, and IEC 62443 as applicable to the organization's scope.
- Coordinate with client security teams (Advanced Nodes Manufacturers) on IT/OT interface requirements, data transfer procedures, and supplier security questionnaire responses.
- Maintain awareness of ITRS Group semiconductor facility security guidelines and incorporate relevant controls into the organization's security posture where applicable.
F. Collaboration Platforms & Productivity Tools Administration
- Administer Autodesk Construction Cloud (ACC) and BIM Collaborate Pro — including user provisioning, project workspace setup, access control, and document permission management for engineering project teams.
- Support onboarding of Revit cloud work sharing workflows via ACC BIM Collaborate Pro, in coordination with the engineering team.
- Administer other productivity and project management tools as adopted by the organization — maintaining user access, licence management, and security integration.
- Provide tier-1 and tier-2 IT helpdesk support to all Singapore staff — including hardware/software troubleshooting, M365 support, account management, and device configuration.
QUALIFICATIONS & EXPERIENCE
Minimum Academic Qualifications
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related discipline from a recognized institution.
- At least 5-8 years of relevant experience with at least three (3) years of relevant IT/cybersecurity work
Preferred Certifications (not all required — any of the following is advantageous)
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- Microsoft Certified: Azure Administrator Associate (AZ-104) or M365 Administrator Associate (MS-102)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- CompTIA Security+ or CompTIA CySA+
- Certified Information Systems Security Professional (CISSP) Associate or SSCP — advantageous but not required at junior level
- ISO/IEC 27001 Lead Implementer or Internal Auditor certificate (PECB, BSI, or equivalent) — highly advantageous
- ITIL 4 Foundation — advantageous for service management context
Work Experience Profile
- Prior internship or employment in an IT administration, IT helpdesk, or cybersecurity support role is preferred but not mandatory for fresh graduates.
- Demonstrable hands-on exposure to Microsoft 365 administration — even through self-study, certifications, or lab environments — is strongly valued.
- Exposure to ISO 27001 documentation or ISMS-related project work (academic, internship, or professional) is an advantage.
- Experience working in a small-to-medium enterprise (SME) context where the role demands multitasking and broad ownership across IT functions is preferred over large-enterprise single-function experience.
- Interested Parties please WhatsApp/Call us at 8893 3424 (Jasmine), and email your latest resume in WORD format to jl@businessedge.com.sg. You may call my office number at 65698233 (Ext.839) for a private & confidential discussion. EA License No.: 96C4864 Reg No.: R22108682 Lee Yit Foong Jasmine