jobs in Mode Fair Sdn Bhd

Mode Fair Hiring! Full Time Senior Cybersecurity in WP Kuala Lumpur - Ricebowl

KL City, WP Kuala Lumpur

Share
Save

Working Location

  • Kuala Lumpur, Kuala Lumpur Kuala Lumpur WP Kuala Lumpur Malaysia

Job Description

Responsibilities

About the company

ModeFair is an expanding tech venture that excels in GovTech. We provide a holistic suite of services, ranging from strategic counsel and conceptualisation to UI/UX design, custom-made development & integration, and routine IT management.

We aim to retain strong talent with a conducive working environment and competitive benefits. Our culture is fast-paced: everyone uses AI heavily in their daily work, delivery speed and efficiency matter, and we hold people accountable for how they use their time. We promote trust, responsibility, and open communication — and we expect high ownership.

About the job

We are hiring a hands-on Senior Cybersecurity lead for our Kuala Lumpur office — someone who can own the function and act as Head of Cybersecurity. You report to the CTO as the company’s principal security SME — not a governance-only or management-only seat.

You are the company’s appointed Data Protection Officer (DPO) under Malaysia’s PDPA. You own personal data protection practices, including personal data breach assessment and notification.

You personally design, implement, test and operate security controls. You can run with a small team or alone when needed. Strong senior security engineers who can own the full Head scope are welcome even if they have not held a Head title before.

Willing to go the extra mile — build custom security and monitoring tools with Claude Code / AI agents (detection, log analysis, response tooling) instead of defaulting to expensive commercial SIEM / log platforms when an in-house build fits. Commercial tools (EDR, SIEM, and similar) are fine when they earn the cost. Vendor “AI features” alone are not enough.

Full on-site, Monday–Friday at Sunway Tower, Jalan Ampang, Kuala Lumpur. No hybrid or remote.

Key responsibilities

Security leadership & hands-on delivery

  • Set and execute cybersecurity priorities and the improvement roadmap with the CTO

  • Design and review security across apps, cloud, infra, network, endpoints, identity and data

  • Personally implement, configure, test and troubleshoot controls when required

  • Build and run practical monitoring, detection, investigation and incident response

  • Lead response to ransomware, attacks, data leakage and major incidents (containment, recovery, evidence, stakeholders)

  • Own BCM / BCP / DR / incident and ransomware playbooks — and test them

  • Drive vulnerability work, threat hunting and security validation; support 99.9% service availability targets

  • Embed security into delivery and DevSecOps; secure code, endpoints, cloud, email, file share, messaging and AI tools

  • Give the CTO clear visibility of material risks, incidents and open issues

  • Progress ISMS / ISO 27001 readiness when the company moves that way (you don’t need to already be the certified Lead Auditor)

  • Serve as Data Protection Officer (DPO) under Malaysia’s PDPA: own personal data protection practices and personal data breach assessment and notification

Security tools, automation & AI

  • Combine open-source tools, in-house scripts/agents, Claude Code (or comparable), and commercial products only where they add clear value

  • Judge effectiveness, effort, ops load and cost before recommending a buy

  • Use AI for log/alert analysis, threat hunting, pentest support, vuln analysis, secure code review, IR automation and reporting — responsibly

Skills & experience required

  • Strong hands-on cybersecurity, architecture and incident response experience

  • Direct involvement in serious incidents (ransomware, compromise or major data loss) — not only tabletop theory

  • BCM / DR planning and testing experience

  • Solid across app, cloud, infra, endpoint, network, identity and data security

  • Practical work with pen testing, vuln management, SIEM, EDR, DLP and monitoring

  • Experience securing cloud (AWS and Huawei Cloud preferred) plus Linux, Windows and modern web apps

  • Working knowledge of ISO 27001, NIST, CIS Controls and MITRE ATT&CK

  • Working knowledge of Malaysia’s PDPA and practical DPO duties (consent, retention, access requests, breach assessment). Willingness to take the DPO seat is required

  • Can write scripts, build automations and integrate tools

  • Hands-on with Claude Code or similar AI engineering tools to build real security capability — not chat-only

  • Can operate independently without a large team

  • Leadership: at least ~2 years leading cyber people or owning a security function (pentest, SOC, security engineering or IR). Strong senior ICs who have already been the accountable owner may still fit

  • At least one active (not expired) practical certification in penetration testing or SOC / incident response (e.g. OSCP, GPEN, GCIH, GCIA, CySA+ or equivalent). More active certs are preferred

  • Aligned with the CTO; escalate real risk clearly; finish remediation and verify it stuck

  • Willing to be on-call for serious incidents (evenings / weekends / PH when needed)

Nice to have

  • Additional active practical cybersecurity certifications beyond the minimum

  • Prior SME or lean-team experience building security without a big budget

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More