Назад
Company hidden
ΠΎΠ±Π½ΠΎΠ²Π»Π΅Π½ΠΎ 11 часов Π½Π°Π·Π°Π΄

AI Security & Identity Lead

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
hybrid
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
lead
Английский
c1
Π‘Ρ‚Ρ€Π°Π½Π°
Malaysia
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
AI Security & Identity Lead (AI Security/Cloud-Native ERP): Designing and operating security architecture, identity management, and compliance observability for a multi-tenant Agentic ERP Platform with an accent on authentication, authorization, data isolation, and AI-specific threat mitigation. Focus on building IAM and policy-as-code frameworks, producing audit-ready evidence, and leading security and compliance operations across distributed engineering hubs.

Location: Hybrid β€” Selangor or Penang office, Malaysia. Minimal travel may be required for team meetings or training.

Company

hirify.global is a Nasdaq-listed provider of enterprise software support, managed services, and Agentic AI ERP solutions for Oracle, SAP, VMware, and other enterprise technology platforms.

What you will do

  • Design and implement security architecture for authentication, authorization, encryption, audit logging, APIs, integrations, and air-gapped deployments.
  • Build IAM capabilities including SSO, OAuth 2.0, OIDC, SAML, RBAC, ABAC, policy-as-code with OPA/Rego, token management, and customer identity federation.
  • Establish data isolation and multi-tenancy security patterns that protect customer environments and data across the platform.
  • Lead compliance observability for SOC 2, ISO 27001, GDPR, and related requirements, producing audit evidence, posture reports, and customer security documentation.
  • Implement vulnerability management, security scanning, PII detection, secure code review, incident response alignment, and penetration-testing coordination.
  • Lead and grow the Malaysia-based security and compliance observability function, including management of the Observability & Governance Engineer.

Requirements

  • 8+ years of security engineering experience, including at least 3 years in a lead or management role.
  • Experience designing security architectures for cloud-native, multi-tenant platforms and implementing enterprise IAM solutions.
  • Hands-on knowledge of OAuth 2.0, OpenID Connect, SAML 2.0, JWT/JWS/JWE, Keycloak, Auth0, Okta, OPA/Rego, and HashiCorp Vault.
  • Experience with application, API, cloud, encryption, certificate lifecycle, air-gap deployment, and CI/CD security.
  • Experience producing audit evidence for SOC 2, ISO 27001, SOX, or equivalent frameworks, plus conducting threat modelling and security risk assessments.
  • Fluent English is required in written and verbal communication.

Nice to have

  • PostgreSQL, container, Kubernetes, infrastructure-as-code, SIEM, Zero Trust, HSM, cloud KMS, or LLM observability experience.
  • Experience with AI assurance frameworks, third-party MCP or agent security models, and LLM gateway security patterns.
  • Security, compliance, or audit certifications such as CISSP, CISM, CEH, AWS Security Specialty, CISA, or ISO 27001 Lead Auditor.
  • Published security research or contributions to security-focused open-source projects.

Culture & Benefits

  • Work in a remote-oriented environment with the role anchored to a Malaysia office on a hybrid basis.
  • Collaborate with Platform Engineering, AI/ML, DevOps, Delivery, and security teams across three hubs.
  • Opportunity to build a security and observability function and influence enterprise AI platform security.
  • Work with a global organization serving Fortune 500, public-sector, government, and midmarket clients.
  • Inclusive workplace supported by the company’s Four Cs values: Company, Colleagues, Clients, and Community.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’