
Security Architect
- Design and implement security frameworks for cloud and hybrid environments, integrating security controls across public, private clouds, and data centres.
- Conduct security assessments for new cloud deployments and changes, provide risk mitigation recommendations, and ensure security measures align with the organization's risk profile.
- Cloud Security Monitoring and Maintenance:
- Establish tools for monitoring, detecting, and responding to threats, regularly review security policies, and conduct audits and risk assessments for cloud infrastructure.
- Manage Cloud Security Posture Management (CSPM) solutions to detect and respond to security misconfigurations in cloud environments.
- Monitor cloud environments for security incidents, analyse alerts, and take prompt action to mitigate risks.
- Assist in responding to cloud security incidents, perform forensic investigations, and implement preventive measures based on findings.
- Configure and maintain cloud-native security services like IAM, PAM, KMS, and Security Groups.
- Compliance, Policy and Standards Development and Governance:
- Create, update, and maintain cloud security policies, standards, and procedures to address evolving threats and compliance needs.
- Automate security processes and compliance checks using tools to ensure continuous compliance.
- Security Assessments and Penetration Testing:
- Conduct security assessments and penetration tests to identify vulnerabilities, providing reports and remediation plans to stakeholders.
- Bachelor's Degree from a recognized university in Information Technology, Computer Science, Cybersecurity, or other relevant fields; and/or
- Professional Cybersecurity-related certifications by recognized professional body. (e.g. CISSP, CCSP or equivalent industry certifications.) ; and/or
- Microsoft Cybersecurity Architect Expert, Azure Security Engineer, AWS Certified Security or GCP Professional Cloud Security Engineer are added advantages
- Minimum of 5 years working experience in information security
- Minimum of 3 years of hands-on experience in security cloud environments
- Strong knowledge of cloud security best practices and frameworks (Malaysia Public Sector Cloud Policy, NIST, ISO27001, etc
- Experience with cloud native security services and tools
- Strong incident response and threat-hunting skills.
Professional Competencies
- Azure Security Services: Expertise in Azure security tools like Azure EntraID, Azure Security Center, Sentinel, Key Vault, and DDoS protection.
- Monitoring & Detection: Experience in SIEM implementation, log analytics, and threat hunting.
- Incident Response: Knowledge in cloud forensics, post-incident analysis, and response.
- Network Security: Understanding of cloud networking (e.g., VPC/.NET design, Hub-Spoke architecture) and access control measures like network segmentation.
- Data Security: Expertise in encryption (e.g., key management, encryption at rest/in transit) and data protection strategies (e.g., DLP, access control policies).
- Security Assessment: Experience in cloud penetration testing, vulnerability management, risk assessment, and threat modelling
- ANNUAL LEAVE
- EPF
- SOCSO