Woh Hup Digital and IT department is looking for a Senior/Cyber Security Engineer is responsible for maintaining and improving the organization’s cybersecurity posture on an ongoing basis. As a Cyber Security Engineer, you will implement security solutions, and work with vendors to monitor, detect and contain cybersecurity incidents to minimize impact to the organization.
Responsibilities
- Review and development of security framework e.g. NIST framework, information security policies, processes /procedures, and guidelines on an ongoing basis
- Work with the internal IT team and external vendor to conduct security assessments and to evaluate, implement and enhance the network perimeter security e.g. endpoint security, MFA, Identity Access Management and Privileged Access Management.
- Identify security gaps, perform threat risk assessments in current setup and propose mitigating measures.
- Standardize and refine security incident response and escalation processes.
- Escalate security incidents and non-compliances on a timely basis.
- Monitor information security alerts triage, mitigate, and escalate issues as needed.
- Provide security advisory to end users on regular basis.
- IT Security Management of various aspect, e.g. network security, server security, application security, end point security and email security.
- Keep abreast of industrial IT security advancements and introduce appropriate security enhancements to IT infrastructure and systems.
- Attend to any other reasonable duties as assigned by the IT Infrastructure Manager and Infrastructure Team lead.
Requirements
- Diploma or Degree in engineering, science or information technology, or equivalent education.
- Minimium 1 year of related work experience in cybersecurity management and security governance.
- Good working knowledge of security risk management, security governance framework and compliance (IT Security Audit / log review), technical vulnerability management, application security, security technologies (system hardening, IDS/IPS,firewall), security incident response and security assessment.
- Hands-on experience on the following IT Security Tools will have added advantage
- Endpoint Protection (e.g. Microsoft Defender, Sophos)
- Email Security (e.g. Mimecast, ProofPoint, Cisco Email Security)
- Next Generation firewall (e.g. Meraki, Fortigate, Checkpoint)