Назад
Company hidden
2 дня назад

IT Security Manager

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

IT Security Manager (Cybersecurity): Owning product, cloud, and corporate security across the organization with an accent on security governance, risk compliance, and AppSec. Focus on embedding security within CI/CD pipelines, implementing AWS security controls, and coordinating incident response.

Location: On-site in Bandar Sunway, Selangor, Malaysia

Company

hirify.global is a creative software company providing high-scale consumer SaaS tools.

What you will do

  • Establish and maintain security policies aligned with ISO 27001, SOC 2, and privacy regulations (GDPR, PDPA).
  • Integrate security practices into the SDLC, including threat modeling, secure coding standards, and application security reviews.
  • Implement and operate AWS cloud security controls, including identity management, logging, and threat detection.
  • Develop and maintain incident response plans and coordinate security incident handling with Engineering and IT.
  • Enforce identity lifecycle management and access controls across cloud platforms and SaaS systems.
  • Deliver security awareness training and track operational risk metrics to monitor control coverage.

Requirements

  • 6–10 years of experience in IT or application security, including ownership of security programs.
  • Strong hands-on experience with secure SDLC practices and vulnerability management.
  • Practical expertise in AWS security services, IAM, and cloud security monitoring.
  • Proficiency with security tooling such as SAST, DAST, dependency scanning, and secret management.
  • Solid understanding of ISO 27001, SOC 2, PDPA, and GDPR frameworks.
  • Proven ability to lead incident response and communicate risks to technical and non-technical stakeholders.

Nice to have

  • Certifications: CISSP, CCSP, AWS Security Specialty, or ISO 27001 Lead Implementer/Auditor.
  • Experience with high-scale consumer SaaS or GRC platforms like Drata and Vanta.
  • Expertise in Kubernetes security, serverless security, and SBOM/supply chain practices.

Culture & Benefits

  • Accrued additional annual leave on a yearly basis.
  • Comprehensive medical and insurance coverage.
  • Optical and dental subsidies.
  • Opportunities for training, guidance, and professional growth.
  • Diverse and inclusive work environment with a focus on stepping out of comfort zones.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →