Industry: Information and Communications Technology
Consultant Registration Number: R1982194
Brand Name: 02C3423
SHARE
Job Title
Senior Executive (Governance and PMO)
Job Summary
We are seeking a Cybersecurity Specialist to support day-to-day cybersecurity operations across the organization. This role is hands-on and operational, covering security monitoring, alert triage, phishing simulations, user awareness training, vulnerability management, and support for enterprise security platforms. The role also supports security reporting, audits, and ongoing security projects under established governance and direction.
Key Responsibilities
Security Operations & Incident Response
Perform daily alert triage and monitoring of SOC emails and security notifications.
Investigate logs and security alerts from security platforms and service providers.
Support incident response activities, including investigation, containment, and follow-up actions when required.
Track and follow up on pending or critical security alerts with internal teams and vendors.
Prepare and share monthly security report and threat summaries.
Phishing Simulation & Security Awareness
Plan and execute monthly phishing simulation campaigns
Coordinate follow-up training for users who fail phishing simulations.
Prepare and distribute phishing campaign reports to relevant stakeholders
Coordinate and schedule cybersecurity awareness training
Prepare and distribute monthly cybersecurity newsletters.
Vulnerability & Endpoint Management
Monitor outstanding vulnerabilities across properties and systems.
Support and guide IT teams on vulnerability remediation activities.
Perform periodic reconciliation between endpoint management and endpoint protection platforms to ensure coverage and accuracy.
Security Platforms & Tool Support
Support daily operations and investigations using security tools such as:
Endpoint Detection & Response (e.g. CrowdStrike)
Identity and access platforms (e.g. Microsoft Entra ID)
Secure Web Gateway, DLP, and email security solutions
Assist with configuration reviews, troubleshooting, and fine-tuning of security policies.
Audit, Access Review & Assurance
Support annual access reviews for security platforms to ensure least-privilege and removal of dormant accounts.
Assist with yearly vulnerability assessments and penetration testing activities, including coordination and remediation tracking.
Work with IT teams and auditors to prepare audit artifacts and supporting evidence.
Project & Issue Tracking
Support cybersecurity projects
Coordinate with IT managers from distributed properties and track deployment issues, vendor tickets, and remediation actions.
Coordinate user acceptance testing (UAT) activities with internal teams and vendors.
Maintain clear documentation of issues, decisions, and resolutions.
Qualifications
Required
Bachelor’s degree in Information Security, IT, or a related field, or equivalent practical experience.
3–5 years of hands-on experience in cybersecurity operations or IT security roles.
Practical experience with:
Security alert monitoring and incident triage
Phishing simulations and security awareness programs
Vulnerability management and remediation tracking
Endpoint and identity platforms
Comfortable working with dashboards, logs, spreadsheets, and documentation.
Ability to operate independently within defined processes and escalate issues appropriately.
Experience with tools such as CrowdStrike, ManageEngine, Microsoft Entra ID and firewalls
Familiarity with security standards such as ISO 27001, PDPA, or PCI DSS.
Security certifications such as CISSP, Security+, CEH, or equivalent.
Personal Attributes
Detail-oriented and disciplined in follow-ups and documentation.
Coordination skills when working with IT teams, vendors, and business stakeholders.
Able to explain security findings clearly to non-technical audiences.
Comfortable balancing operational workload with ongoing projects.