jobs in Skyro

Skyro Hiring! Full Time IT Operations - Security Lead in Federal Territory - Ricebowl

IT Operations - Security Lead

Skyro

Undisclosed

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

Role Overview

We are seeking an experienced IT & Information Security Lead to own all IT operations and information security for the local market. This role combines hands-on technical execution with security leadership and operational accountability.

You will act as the primary IT authority for the market, responsible for secure infrastructure, network operations, identity and access management, regulatory compliance, and end-user support. This is a hands-on role requiring deep operational and security expertise.


Key Responsibilities

Information Security

  • Own and enforce the market’s security control baseline across endpoints, users, and infrastructure.
  • Manage vulnerability lifecycle (scanning, prioritisation, patching, reporting).
  • Maintain secure configurations and endpoint hardening standards.
  • Administer and operate security tooling (EDR/XDR, encryption, email security).
  • Enforce identity and access security (MFA, least privilege, access reviews, JML controls).
  • Lead incident response (detection, containment, escalation, post-incident review).
  • Ensure proper logging, alert investigation, and remediation of security findings.
  • Assess third-party/vendor security risk.
  • Report on security posture, incidents, and risk to leadership and global security teams.

IT Operations & End-User Support

  • Serve as the primary IT contact for the market.
  • Provision and support secure endpoints, mobile devices, and workplace technology.
  • Manage ticket queues and service levels.
  • Lead onboarding and offboarding processes.
  • Maintain documentation, standards, and operational procedures.

Network & Infrastructure

  • Own the design and operation of the office network (routing, switching, VLANs, firewalls, VPN, Wi‑Fi).
  • Monitor network performance, availability, and security.
  • Administer Microsoft 365, Entra ID, and MDM (Intune).
  • Maintain local servers, storage, and backup systems (where applicable).
  • Ensure physical and environmental infrastructure standards are met.

Compliance, Governance & Vendors

  • Operate IT and security controls aligned with regulatory and data protection requirements.
  • Maintain audit readiness and evidence for ISO 27001/SOC 2/NIST/CIS-based controls.
  • Manage IT vendors, contracts, procurement, and asset lifecycle.
  • Maintain accurate asset registers and documentation.

Leadership & Projects

  • Lead local IT staff and/or managed service providers.
  • Deliver IT and security initiatives, office expansions, and technology rollouts.
  • Escalate complex issues to global teams as required.
  • Provide regular reporting to senior leadership.


Required Qualifications & Experience

  • Unrestricted right to work in the role’s location (no sponsorship).
  • 6–8+ years in IT operations/support, including 2–3+ years in a lead or sole IT owner capacity.
  • Strong hands-on information security experience (EDR, vulnerability management, hardening, email/phishing defence, log/alert triage).
  • Demonstrated incident response experience.
  • Solid network engineering and firewall administration experience.
  • Strong identity and access management practice (MFA, least privilege, conditional access).
  • Microsoft 365 and Entra ID administration expertise.
  • Endpoint management across Windows and macOS (patching, encryption, imaging, compliance).
  • Experience operating security control frameworks (ISO 27001, SOC 2, NIST, CIS) and supporting audits.
  • Vendor and contract management experience.
  • ITSM/change management experience.
  • Experience in a regulated environment (financial services or similar preferred).
  • Professional English proficiency.
  • Ability to work on-site with occasional travel.


Preferred

  • Security certifications (Security+, SSCP, CySA+, GCIH, ISO 27001 LI/LA, CISSP, CISM).
  • Networking certifications (CCNA/CCNP, Network+, Fortinet NSE).
  • Microsoft certifications (SC-200/300, MD-102, MS-102, AZ-104).
  • SIEM/SOAR experience (Sentinel, Splunk, Elastic).
  • Familiarity with financial regulatory frameworks and data protection laws.
  • AWS/GCP operational security exposure.
  • Business continuity and disaster recovery testing experience.
  • Scripting/automation skills (PowerShell, Bash, Python).
  • Experience establishing IT/security operations from scratch in a new market.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More