Назад
Company hidden
обновлено 28 дней назад

IT Security Manager (Cloud Security)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Security Manager (Cloud Security): Owning product, cloud, and corporate security across Pixlr with an accent on governance, application security, AWS controls, and incident response. Focus on embedding secure SDLC practices, operating cloud and application security tooling, and coordinating risk, privacy, detection, and resilience activities.

Location: On-site in Bandar Sunway, Selangor, Malaysia

Company

Security operations cover hirify.global’s product, cloud, and corporate environments.

What you will do

  • Define and operate the security program across governance, risk, compliance, application security, cloud security, and incident response.
  • Maintain policies, conduct risk and vendor assessments, classify data, and support ISO 27001 and SOC 2 audit readiness.
  • Embed threat modeling, secure coding, security reviews, and SAST, DAST, dependency, and secret scanning into the SDLC and CI/CD pipelines.
  • Implement AWS identity, logging, monitoring, threat detection, hardening, policy-as-code, encryption, and key management controls.
  • Coordinate incident response, centralized detection and alerting, business continuity, disaster recovery, and backup verification.
  • Manage access hygiene, privacy impact assessments, data retention, security training, and operational risk metrics with cross-functional stakeholders.

Requirements

  • 6–10 years of experience in IT or application security, including ownership of security programs or AppSec/CloudSec functions.
  • Hands-on experience with application security, secure SDLC practices, vulnerability management, and common security tooling.
  • Practical expertise in AWS security services, identity and access management, and cloud security monitoring.
  • Strong understanding of ISO 27001, SOC 2, PDPA, GDPR, and related security governance and regulatory principles.
  • Ability to lead incident response and communicate security risks to technical and non-technical stakeholders.

Nice to have

  • CISSP, CCSP, AWS Security Specialty, or ISO 27001 Lead Implementer/Auditor certification.
  • Experience in creative, EdTech, or high-scale consumer SaaS environments and exposure to SOC 2 or ISO 27001 programs.
  • Experience with GRC platforms such as Drata or Vanta, container and Kubernetes security, serverless security, SBOMs, or software supply-chain practices.

Culture & Benefits

  • Additional annual leave credited yearly.
  • Medical and insurance coverage.
  • Optical and dental subsidies.
  • Training, guidance, and opportunities to build confidence and professional skills.
  • Work with people from diverse skill sets and experiences.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →