Bachelor's degree or above, majoring in Computer Science or a related field.
6+ years of working experience in the information security industry.
Familiar with the development and operation of SDL (Security Development Lifecycle), with hands-on penetration testing capabilities for web systems.
...
Implement and optimize endpoint governance using Microsoft Intune, including configuration profiles, compliance policies, security baselines, and device‑lifecycle management.
Support directory, identity, and device policy integration using Entra ID (Azure AD), ensuring secure authentication, conditional access, and identity‑driven device posture.
Apply and tune Group Policy Objects (GPO) and MECM (Microsoft Endpoint Configuration Manager) for on‑premises and hybrid Windows endpoint management.
...
Engage with leadership teams and stakeholders to facilitate timely decision-making and drive ownership of governance actions.
Provide data-driven recommendations to strengthen governance effectiveness and support organizational priorities.Promote a culture of accountability and operational discipline across NEO.
Act as the focal point for NEO engagements with Internal Audit and external auditors by driving cross-functional alignment and facilitating effective communication throughout the audit lifecycle.
...
Perfom server hardening tasks for Windows, Linux, Unix, AS400, and application servers in accordance with approved security standards, ensuring all configurations align with baseline requirements.
Review and verify server hardening checklists for compliance, escalating gaps or deviations to senior analysts or system owners for remediation.
Execute privileged ID (PID) onboarding, handover, unlock/reset, and password release requests following established approval processes and vaulting requirements.
...
Maintain the enterprise and IT risk registers; facilitate risk identification, assessment, treatment, and monitoring across business and technology functions.
Conduct periodic risk assessments covering infrastructure, applications, cloud services, data, and third parties.
Define and track KRIs and risk appetite metrics; report on trends, emerging risks, and control effectiveness.
...
Maintain the enterprise and IT risk registers; facilitate risk identification, assessment, treatment, and monitoring across business and technology functions.
Conduct periodic risk assessments covering infrastructure, applications, cloud services, data, and third parties.
Define and track KRIs and risk appetite metrics; report on trends, emerging risks, and control effectiveness.
...
Audit: Drive audit readiness by acting as a point of contact for all internal and external IT security audits and regulatory reviews (including BNM, HKMA, and MAS), ensuring the bank demonstrates high maturity levels and audit readiness at all times. Drive the end-to-end audit lifecycle including PCI-DSS and PwC engagements by coordinating evidence collection, justifying control effectiveness, and tracking all findings to verified closure to minimize compliance risks.
Projects & Change: Enable strategic IT security integration by participating in IT and Business project meetings. Conduct security reviews, risk assessments, and review User Acceptance Testing (UAT) to ensure all deliverables meet necessary security requirements with proper sign-off before deployment.
Housekeeping: Ensure a timely deletion and housekeeping of resigned, dormant, or unused user IDs based on HR cessation notifications to minimize the attack surface.
...
Incident Response & Forensics - Lead cloud security incident response, including investigation, containment, recovery, and root cause analysis for cloud-related security events.
...
Implement and optimize endpoint governance using Microsoft Intune, including configuration profiles, compliance policies, security baselines, and device‑lifecycle management.
Support directory, identity, and device policy integration using Entra ID (Azure AD), ensuring secure authentication, conditional access, and identity‑driven device posture.
Apply and tune Group Policy Objects (GPO) and MECM (Microsoft Endpoint Configuration Manager) for on‑premises and hybrid Windows endpoint management.
...
Provide insights into areas of potential vulnerability and recommend corrective action.
Keep up to date with industry trends, regulatory changes and emerging cybersecurity threats.
Plan, execute and manage the risk-based audit assignments as per the Audit Plan to ensure the audit fulfil the approved audit objectives and audit scope and the standards as prescribed in the Audit Methodology.
...