Identifies and addresses legal and customer security requirements within the region
Supports the implementation of the global Information Security Management System (ISMS) and global business continuity standards within the region
Implements the global risk-based approach to protecting information and other assets within his/her region and performs vulnerability management related tasks
...
Report the Group's security posture, incident trends, risk exposure, and improvement progress to the Group IDT Director and senior management.
Manage security tooling and managed-security-service vendors at the operational level, including service quality, licence utilisation, and cost.
Operate and continuously improve Group security monitoring, covering SIEM use cases, log sources, detection rules, and alert triage across endpoints, servers, network, and cloud services.
...
Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Work collaboratively with various cybersecurity units and cross-functional teams to guarantee robust information security governance across CelcomDigi.
Lead the design, implementation and management of defendable security architectures including ZeroTrust models, enhancing security capabilities and maturity across diverse infrastructures such as IT, telecommunications and multi-cloud environments (AWS, Azure).
Provide authoritative guidance to internal business units and project teams to support compliance with mandatory Digital Cybersecurity Checklist (DCC) requirements and endorsements.
...
We seek to strike a balance between diversity, inclusion and merit to achieve our mission of infusing diversity in thinking and skillsets into our organisation. Candidates are assessed based on merit and potential, in line with our mission to attract and recruit the best talent available. Expanding on our “Digital at the Core” ethos, we are progressively digitising the employee journey and experience to provide a strong foundation for our people to drive life-long learning, achieve their career aspirations and grow talent from within our organisation.
Security Framework Alignment: Oversee the definition and maintenance of the Bank’s technical security standards, ensuring strict alignment with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Guide the review and updating of technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, Network Access Control (NAC) systems (Cisco ISE), and related perimeter devices.
Audit & Compliance Remediation: Lead technical readiness for internal, external, and regulatory audits. Drive team execution to track, prioritize, and validate the remediation of security findings and vulnerabilities across business units.
...