freehire launches on Product Hunt on 26 August.

Follow →

IT & Cybersecurity Executive (Senior-Lead)

Summary

Lead Microsoft 365 security and compliance for a Singapore-based engineering consultancy, administering Defender, Sentinel, Purview, and ISO 27001 ISMS while enforcing MFA, DLP, and endpoint policies across Windows and mobile devices.

KEY RESPONSIBILITIES

A. Microsoft 365 E3/E5 Platform Administration

The candidate will be responsible for the day-to-day administration and security configuration of the organization's Microsoft 365 E3/E5 tenant, serving as the primary M365 administrator:

  • Administer user accounts, licences, groups (Entra ID), and conditional access policies in Microsoft Entra ID (formerly Azure AD) — including MFA enforcement, passwordless authentication setup, and guest access governance.

  • Configure and maintain Microsoft Defender for Business for endpoint protection across all company devices — including threat policies, antivirus profiles, attack surface reduction rules, and alert triage.

  • Deploy and manage Microsoft Intune for Mobile Device Management (MDM) and Mobile Application Management (MAM), covering device enrolment, compliance policies, and configuration profiles for Windows and mobile endpoints.

  • Manage Microsoft Purview compliance solutions — including Data Loss Prevention (DLP) policies, sensitivity labels, retention policies, communication compliance, and eDiscovery as required.

  • Administer Microsoft Defender for Office 365 (Plan 1/2 equivalent) — including Safe Links, Safe Attachments, anti-phishing policies, and spoof intelligence.

  • Configure and maintain Microsoft Sentinel (SIEM) for log ingestion, security event correlation, alert rules, and incident tracking. Develop and maintain basic KQL queries for monitoring and reporting.

  • Operate and maintain Microsoft Teams as the primary collaboration platform — including channel governance, meeting policies, external access controls, and Teams Phone configurations where applicable.

  • Manage SharePoint Online and OneDrive for Business — including site provisioning, permission structures, external sharing policies, and information architecture in alignment with the organization's data classification policy.

  • Maintain Exchange Online — including mail flow rules, anti-spam/anti-malware policies, shared mailboxes, distribution lists, and calendar management.

  • Monitor the Microsoft 365 Secure Score dashboard and implement recommended improvement actions on a scheduled cadence. Produce monthly security posture reports for management review.

  • Administer Microsoft 365 Backup and support disaster recovery testing as scheduled.

  • Manage the migration path from Microsoft 365 Business plans to E3/E5 licensing as required — including licence reconciliation, feature parity checks, and user communications.

B. ISO/IEC 27001:2022 ISMS Implementation Support

The candidate will work directly with management to support the organization's ISO/IEC 27001:2022 certification programme, acting as the primary documentation and operational owner for the ISMS:

  • Maintain and regularly update the ISMS document registry — including the Statement of Applicability (SoA), Risk Register, Asset Register, and all mandatory ISMS records as required by Clauses 5, 6, 7, 8, 9, and 10 of ISO/IEC 27001:2022.

  • Conduct scheduled information security risk assessments using the organization's defined risk assessment methodology — identifying threats, vulnerabilities, likelihood, and impact across information assets.

  • Coordinate and document internal ISMS audits in accordance with the audit programme — including scheduling, checklist preparation, evidence collection, finding documentation, and corrective action tracking.

  • Manage the corrective action and nonconformity register — tracking root cause analyses, remediation actions, responsible owners, and closure deadlines.

  • Support the preparation and coordination of external surveillance audits and the initial certification audit by the appointed certification body (CB).

  • Conduct and document information security awareness training sessions for all staff — covering phishing awareness, clean desk policy, data handling, acceptable use, and incident reporting procedures.

  • Maintain the Supplier and Third-Party Security Assessment process — including vendor risk questionnaires, contract clause reviews, and periodic reassessments for critical service providers.

  • Monitor the organization's compliance posture against all applicable controls in Annex A of ISO/IEC 27001:2022, and maintain gap tracking documentation.

  • Support management review meetings by preparing ISMS performance metrics, KPI dashboards, and input data covering audit results, incident statistics, risk treatment status, and security objective progress.

C. Security Policy Framework — Operationalization & Compliance

The organization has established a twelve-policy information security framework. The candidate will own the operationalization, monitoring, and periodic review of all policies:

  • Information Security Policy (Master) — maintain as living document; ensure all referenced sub-policies remain current and consistent.

  • Acceptable Use Policy (AUP) — enforce via Intune compliance baselines and M365 communication compliance; conduct periodic user attestation exercises.

  • Access Control Policy — maintain Role-Based Access Control (RBAC) matrices; conduct quarterly Privileged Access Reviews (PAR) across M365, SharePoint, and connected systems.

  • Data Classification & Handling Policy — implement and enforce via Microsoft Purview sensitivity labels; ensure all shared documents are appropriately labelled before distribution to clients and partners.

  • Incident Response Policy — maintain and periodically test the Incident Response Plan (IRP); manage the incident log and ensure timely escalation and reporting.

  • Business Continuity & Disaster Recovery Policy — maintain BC/DR documentation; coordinate at least one tabletop exercise annually.

  • Change Management Policy — operate the IT change request and approval workflow; maintain the change log.

  • Password & Authentication Policy — enforce MFA, password less authentication, and password complexity via Entra ID Conditional Access and Intune. Administer the corporate password manager.

  • Physical & Environmental Security Policy — conduct periodic office security walkthroughs; maintain the clean desk checklist and visitor log; coordinate with building management on physical access controls.

  • Mobile Device & Remote Access Policy — enforce via Intune device compliance policies; maintain the approved device register.

  • Third-Party & Supplier Security Policy — manage vendor onboarding security assessments; maintain the Approved Vendor Register.

  • Data Retention & Destruction Policy — implement retention labels in M365 Purview; coordinate secure media disposal as required.

D. Endpoint, Network & Infrastructure Security Operations

As the organization's primary IT operator, the candidate will manage day-to-day security operations across the IT environment:

  • Manage endpoint security posture across all Windows workstations and mobile devices — including patch management (Windows Update for Business / Intune), vulnerability scanning, and remediation tracking.

  • Monitor and maintain the organization's email security posture — including DMARC, DKIM, and SPF records; review quarantine reports and respond to phishing reports from end users.

  • Administer the corporate SSH (Tailscale) solution for remote access — managing user provisioning, connection policies, and access logs.

  • Monitor network security appliances (firewall, switch management) in coordination with the organisation's managed services provider (MSP) or network vendor, and escalate anomalies.

  • Operate Microsoft Sentinel — reviewing security alerts, investigating incidents, maintaining playbooks, and producing regular threat intelligence summaries relevant to the semiconductor and engineering sector.

  • Perform vulnerability assessments using approved tools on a scheduled basis — documenting findings and tracking remediation in the risk register.

  • Manage DNS, domain registrar settings, SSL certificate renewals, and web hosting security configurations as applicable.

  • Support IT asset lifecycle management — procurement requests, asset tagging, configuration, deployment, and secure decommissioning.

E. SEMI E187 / E188 Cybersecurity Compliance Awareness

As a semiconductor facility design consultancy serving Tier-1 fabs, the organization must demonstrate awareness of and alignment with semiconductor-specific cybersecurity standards:

  • Develop and maintain working knowledge of SEMI E187 (Cybersecurity Specification for Fab Equipment) and SEMI E188 (Malicious Software Prevention for Fab Equipment).

  • Support the preparation of documentation and responses related to client cybersecurity requirements referencing SEMI E187 / E188, NIST SP 800-82, and IEC 62443 as applicable to the organization's scope.

  • Coordinate with client security teams (Advanced Nodes Manufacturers) on IT/OT interface requirements, data transfer procedures, and supplier security questionnaire responses.

  • Maintain awareness of ITRS Group semiconductor facility security guidelines and incorporate relevant controls into the organization's security posture where applicable.

F. Collaboration Platforms & Productivity Tools Administration

  • Administer Autodesk Construction Cloud (ACC) and BIM Collaborate Pro — including user provisioning, project workspace setup, access control, and document permission management for engineering project teams.

  • Support onboarding of Revit cloud work sharing workflows via ACC BIM Collaborate Pro, in coordination with the engineering team.

  • Administer other productivity and project management tools as adopted by the organization — maintaining user access, licence management, and security integration.

  • Provide tier-1 and tier-2 IT helpdesk support to all Singapore staff — including hardware/software troubleshooting, M365 support, account management, and device configuration.

QUALIFICATIONS & EXPERIENCE

Minimum Academic Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related discipline from a recognized institution.

  • At least 5-8 years of relevant experience with at least three (3) years of relevant IT/cybersecurity work

Preferred Certifications (not all required — any of the following is advantageous)

  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)

  • Microsoft Certified: Azure Administrator Associate (AZ-104) or M365 Administrator Associate (MS-102)

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)

  • CompTIA Security+ or CompTIA CySA+

  • Certified Information Systems Security Professional (CISSP) Associate or SSCP — advantageous but not required at junior level

  • ISO/IEC 27001 Lead Implementer or Internal Auditor certificate (PECB, BSI, or equivalent) — highly advantageous

  • ITIL 4 Foundation — advantageous for service management context

Work Experience Profile

  • Prior internship or employment in an IT administration, IT helpdesk, or cybersecurity support role is preferred but not mandatory for fresh graduates.

  • Demonstrable hands-on exposure to Microsoft 365 administration — even through self-study, certifications, or lab environments — is strongly valued.

  • Exposure to ISO 27001 documentation or ISMS-related project work (academic, internship, or professional) is an advantage.

  • Experience working in a small-to-medium enterprise (SME) context where the role demands multitasking and broad ownership across IT functions is preferred over large-enterprise single-function experience.

    Interested Parties please WhatsApp/Call us at 8893 3424 (Jasmine), and email your latest resume in WORD format to jl@businessedge.com.sg. You may call my office number at 65698233 (Ext.839) for a private & confidential discussion. EA License No.: 96C4864 Reg No.: R22108682 Lee Yit Foong Jasmine

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available