Manager, IT SecurityID:56709
10,000 MYR ~ 14,000 MYRBukit Bintang/KLCC3日 ago概述
薪资
10,000 MYR ~ 14,000 MYR
产业类别
Finance(Banking), Finance(Securities), Finance(Other)
工作内容
< Job Purpose >
The incumbent will work with Head of IT in managing IT Security and Cyber Security efforts across the organization.
Manage all facets of first level support, including line managing first level staff and assets. Ensuring change control and Information Security procedures are followed across Rakuten Trade.
This role is also required to prepare and monitor Cyber Security policies, framework, budget and costing, strategic planning and audit matters, in consultation with the Head of IT.
< Duties & Responsibilities >
1. Specialize in IT Systems/Infrastructure Security; implement and monitor security measures for the protection of computer systems, networks, and information to ensure that all IT related security components are implemented in accordance with the compliance against organization's Information Security Policy and Management Standards, and other Statutory, Legal or Regulatory compliance requirements.
2. Oversee all day-to-day IT security incidents/administration/health check on current servers and network infrastructure security controls. Identify IT risks, threats, and vulnerabilities in the company’s technology infrastructure. Analyze and report computer network/servers/application security breaches or attempted breaches. Investigate security incidents, updates, and documents security control, perform risk assessments, take appropriate action to minimize harm and make recommendations to corrective action. Maintain incident documentation, participate in post-mortems, and write incident reports.
3. Establish and maintains IT security related policies, procedures, and guidelines. Perform annual reviews of the security related guidelines and control to ensure the efficiency and effectiveness of the Information Security controls and recommend improvements wherever is necessary. Develop comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancement.
4. Coordinate with internal, external audit and IT teams to during audits and provide the requested information on a timely basis and update the status of audit findings and remediations to IT management.
5. Drive continuous process improvement to all security functions utilizing KPIs and key metrics.
6. Advise on security operational controls to systems or applications during the design and implementation of new systema or technology.
7. Perform vulnerability and penetration testing management program, reporting with risk priorities, remediation and recommending appropriate solutions.
8. Responsible to manage and report to Management on any Cyber Security issues, statistical fault reports and status on weekly and monthly basis.
9. Participate in Business Continuity and Disaster recovery simulations including infrastructure, security readiness and checklists.
10. Provide periodic updates on cyber security activities, audits and briefing to Management and staff.
资格
应征条件
■ MUST REQUIIREMENTS
・5-10 years’ experience in either IT Security Technologies, IT General Control and IT Processes and Governance in finance service industry.
・At least 3-5 years’ experience managing teams of IT security engineers or support staff.
・Possess hands-on technical experience in setup/implementation/managing IT security related solution/system, including network security monitoring, NAC, L2/L3 firewalls, routing, switching, IDS/IPS, Proxy, WAF, VLAN, VPN Technology, Endpoint Detection and Response Solution, Backup Solution, Event Management (SIEM) Technologies, Content Filtering, Vulnerability Scans & Management, Encryption Technology, DHCP, DNS, HTTP, SSL, SSH, LDAP, IPSEC, etc
・Knowledge of ISO27001, NIST Security Framework, local regulator guidelines and requirement and other IT Security governance and controls.
■ ADVANTAGES
・Candidate from brokerage industry has advantage.
・Diploma / Degree in Information Technology or equivalent.
・Security Operations Centre (SOC) and Privileged Access Management (PAM) solutions knowledge would be an added advantage.
・Certified in Information Security Management System (ISMS) or professional security certification such as CISSP, CISM, CompTIA Security etc. would be an added advantage.
・ITILV4 Foundation and/or experience in Incident, Problem, Change and Configuration management would be an added advantage.
■ OTHERS
・Exceptional communication, problem solving and cross-group collaboration skills.
・Excellent command of written and spoken English.
・Ability to present technical concepts in business-friendly and user-friendly language.
・Self-starter with a positive work attitude and be able to work independently.
・Strong team player with ability to work in a team and as individual contributor.
・Ability to work on own initiative with minimal supervision, excellent time management, priorities and organizational skills to work on multi-tasks with high sense of urgency and tight deadlines.英文
-
其他语言
English
附加信息
福利制度
◆ Salary = RM 10,000 ~ RM 14,000
** Inclusive with fixed health allowance
◆ Annual Leave
- Below 5 years service: 18 days
- Over 5 years service: 24 days
◆ Medical Leave
- Below 2 years service: 14 days
- Over 2 years and below 5 years service: 18 days
- Over 5 years service: 22 days
◆ Fixed health allowance RM 125 / month
◆ Insurance (Etiqa) covering dependent (spouse and children)
- Outpatient
- Specialist
- Hospitalization
- Term Life (** employee only)
◆ Working on Public Holiday, Sat, Sun will be entitled to meal allowance (RM 15 ~ RM 30 / day) and Rest Day Allowance (RM 25 / day) or Replacement Leave
◆ Engagement Activities (company lunch inside office ...)
◆ Performance bonus 1 month averagely (Max 4 months previously)
(Parking around the company is around RM 200~RM 250 per month. No subsidy from company)工作时间
0830 ~ 1730
假日
Monday ~ Friday
0830 ~ 1730职业类别
请登入。