AI Security & Identity Lead
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: Hybrid β Selangor or Penang office, Malaysia. Minimal travel may be required for team meetings or training.
Company
is a Nasdaq-listed provider of enterprise software support, managed services, and Agentic AI ERP solutions for Oracle, SAP, VMware, and other enterprise technology platforms.
What you will do
- Design and implement security architecture for authentication, authorization, encryption, audit logging, APIs, integrations, and air-gapped deployments.
- Build IAM capabilities including SSO, OAuth 2.0, OIDC, SAML, RBAC, ABAC, policy-as-code with OPA/Rego, token management, and customer identity federation.
- Establish data isolation and multi-tenancy security patterns that protect customer environments and data across the platform.
- Lead compliance observability for SOC 2, ISO 27001, GDPR, and related requirements, producing audit evidence, posture reports, and customer security documentation.
- Implement vulnerability management, security scanning, PII detection, secure code review, incident response alignment, and penetration-testing coordination.
- Lead and grow the Malaysia-based security and compliance observability function, including management of the Observability & Governance Engineer.
Requirements
- 8+ years of security engineering experience, including at least 3 years in a lead or management role.
- Experience designing security architectures for cloud-native, multi-tenant platforms and implementing enterprise IAM solutions.
- Hands-on knowledge of OAuth 2.0, OpenID Connect, SAML 2.0, JWT/JWS/JWE, Keycloak, Auth0, Okta, OPA/Rego, and HashiCorp Vault.
- Experience with application, API, cloud, encryption, certificate lifecycle, air-gap deployment, and CI/CD security.
- Experience producing audit evidence for SOC 2, ISO 27001, SOX, or equivalent frameworks, plus conducting threat modelling and security risk assessments.
- Fluent English is required in written and verbal communication.
Nice to have
- PostgreSQL, container, Kubernetes, infrastructure-as-code, SIEM, Zero Trust, HSM, cloud KMS, or LLM observability experience.
- Experience with AI assurance frameworks, third-party MCP or agent security models, and LLM gateway security patterns.
- Security, compliance, or audit certifications such as CISSP, CISM, CEH, AWS Security Specialty, CISA, or ISO 27001 Lead Auditor.
- Published security research or contributions to security-focused open-source projects.
Culture & Benefits
- Work in a remote-oriented environment with the role anchored to a Malaysia office on a hybrid basis.
- Collaborate with Platform Engineering, AI/ML, DevOps, Delivery, and security teams across three hubs.
- Opportunity to build a security and observability function and influence enterprise AI platform security.
- Work with a global organization serving Fortune 500, public-sector, government, and midmarket clients.
- Inclusive workplace supported by the companyβs Four Cs values: Company, Colleagues, Clients, and Community.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β