Search by job, company or skills

Deputy Cyber Security Manager

5-7 Years
  • Posted an hour ago
  • Be among the first 10 applicants

Job Description

The Deputy Cyber Security Manager supports the organisation's cybersecurity governance, risk management, compliance, security operations, incident response and cyber resilience initiatives across Singapore and Malaysia operations.

This role safeguards information assets, strengthens compliance readiness, manages cybersecurity technologies and coordinates security improvement initiatives with internal stakeholders, Managed Security Service Providers, vendors and auditors.

Job Responsibilities

Cyber Security Governance & Compliance

  • Implement and maintain cybersecurity policies, standards, procedures and supporting documentation.
  • Support compliance with PDPA, CSA Cyber Essentials / Cyber Trust, ISO 27001, NIST Cyber Security Framework and relevant audit requirements.
  • Conduct security risk and control gap assessments, support internal and external audits, and track remediation actions.
  • Maintain control registers, risk registers, evidence repositories and management reporting materials.

Security Operations & Incident Response

  • Manage security monitoring across endpoint, identity, email, network and cloud platforms.
  • Operate and review alerts from Microsoft Defender XDR, Microsoft Defender for Office 365, Microsoft Sentinel, Darktrace and other security tools.
  • Coordinate with MSSPs on monitoring, escalation, containment and incident response activities.
  • Investigate phishing, malware, suspicious activity and account compromise events, including root cause analysis and post-incident reviews.
  • Prepare cybersecurity threat reports, incident summaries, remediation updates and management dashboards.

Risk, Vulnerability & Third-Party Security

  • Conduct vulnerability assessments, security posture reviews and risk assessments.
  • Track vulnerability remediation with infrastructure, application, project site and vendor teams.
  • Review third-party security risks, vendor due diligence responses and cybersecurity clauses in contracts.
  • Recommend prioritised mitigation plans and security control enhancements.

Cyber Crisis Readiness & Business Resilience

  • Support incident response planning, crisis escalation procedures and cyber crisis committee readiness.
  • Maintain incident response playbooks, contact lists, escalation workflows and war-room materials.
  • Coordinate tabletop exercises, simulations and lessons-learnt reviews.
  • Support Business Impact Analysis and the development of ransomware, data breach and crisis communication guidelines.

Security Awareness & Data Protection

  • Develop and deliver cybersecurity awareness programmes, phishing simulations and follow-up interventions.
  • Promote secure behaviour, cyber hygiene and responsible data handling across departments and project sites.
  • Support the Data Protection Officer in privacy controls, incident handling and Data Protection Impact Assessments.
  • Assist with investigations involving data leakage or suspected breaches and review security requirements for personal data processing.

Project Security & Security Architecture

  • Review cybersecurity requirements for new IT projects, cloud services, business applications and digitalisation initiatives.
  • Support cloud, identity, endpoint and network security reviews.
  • Promote Zero Trust, secure-by-design and least-privilege principles.
  • Evaluate security technologies and work with business functions to embed cybersecurity controls into processes.

Job Requirements

  • Degree or Diploma in Cyber Security, Information Technology, Computer Science, Information Systems or a related discipline.
  • Minimum 5 years of cybersecurity experience, preferably in an enterprise or multi-site environment, including at least 2 years in a senior analyst, engineer, lead or supervisory role.
  • Practical experience in cybersecurity incident management, security operations, audit support, vulnerability management and security improvement projects.
  • Experience coordinating with MSSPs, vendors, auditors and cross-functional business stakeholders.
  • Hands-on knowledge of Microsoft Defender XDR, Microsoft Defender for Office 365, Microsoft Sentinel, Microsoft 365 Security & Compliance, identity and access management, endpoint protection, email security and cloud security.
  • Strong understanding of risk assessments, cybersecurity frameworks, audit evidence preparation, management reporting and data protection controls.
  • Possess analytical thinking, sound judgement, strong documentation discipline and clear stakeholder communication skills.
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer / Lead Auditor, CEH, Security+, SC-200, SC-300, SC-100 or equivalent are preferred.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 153815883

Similar Jobs

Singapore

Skills:

cloud securityEmail SecurityIdentity And Access Managementrisk assessmentsendpoint protectionMicrosoft Defender XDRMicrosoft 365 Security Complianceaudit evidence preparationdata protection controlscybersecurity policiescybersecurity frameworksMicrosoft SentinelMicrosoft Defender for Office 365

Beware of Scammers

We don’t charge money for job offers