Our client is a leader in the telecommunications infrastructure industry. It is seeking to
employ an experienced professional to join them as
Senior / Manager - Cyber Security & IT Governance (Ref:
KHXXX)
The successful candidate is responsible for the assessment development
implementation and maintenance of enterprise-wide cyber security and IT Governance
programmes to preserve the confidentiality integrity and availability of information
resources. As part of the IT leadership team he/she will be expected to provide
technical leadership and consultation across the organization and also work with external
experts to implement security solutions and detect and contain cybersecurity incidents.
The Job
A) Cyber Security
Assess and review environment and cybersecurity measures to ensure security
and operational effectiveness e.g. network system application endpoint security
physical and logical access security etc.
Review and develop security framework information security policies processes
procedures and guidelines.
Conduct cybersecurity risk assessments penetration tests and IT controls tests.
Identify security gaps and propose mitigating measures and escalate security
incidents and non-compliances on a timely basis.
Evaluate deploy and maintain cybersecurity infrastructure to improve
cybersecurity posture.
Design implement and maintain security incident response and escalation
procedures.
Monitor analyze and correlate events to determine the best course of action to
mitigate and contain threats when detected.
improve cybersecurity awareness of staff e.g. by conducting awareness training.
Automate security controls data and processes.
B) IT Governance
Review and enhance IT policies standards guidelines and best practices
regularly to ensure alignment with organization objectives and industry best
practices.
Develop and implement effective change management plans (such as
communication plans and training programs) to drive adoption and compliance.
Participate in audit planning meetings with internal / external auditors
collate/provide the required materials on a timely basis validate audit findings
provide remediation solutions and implement the agreed solutions on a timely
basis.
Drive security access and activity log reviews on a regular basis.
Promote IT risk management governance and compliance culture across the
organization.
C) IT Management
Contribute to IT strategic planning and budgeting.
Ensure IT vendors meet contractual obligations.
Maintain up-to-date knowledge on cybersecurity technologies and standards.
Attend to any other reasonable duties as assigned by Director Information
Technology.
The Candidate
Degree in engineering science or information technology or equivalent education.
Minimum 10 years of related work experience in cybersecurity management and
security governance. Candidates with additional experience will be considered
for the Senior Manager position.
Good working knowledge of security risk management security governance
framework and compliance (IT Security Audit / log review) technical vulnerability
management (vulnerability assessment penetration testing) application security
security technologies (system hardening IDS/IPD firewall) security incident
response and security assessment.
Strong understanding of cybersecurity standards.
Hands-on experience with cybersecurity tools such as Next Generation Firewalls
SASE Endpoint Protection Data Loss Protection Email Security etc.
Interested professionals are to submit their applications and CVs in MS Word format
stating current and expected salary packages to as an
expression of their interest. We regret that only short-listed candidates will be notified.
Required Experience:
Manager