IT & Cybersecurity Executive (Senior-Lead)
Summary
Lead Microsoft 365 security and compliance for a Singapore-based engineering consultancy, administering Defender, Sentinel, Purview, and ISO 27001 ISMS while enforcing MFA, DLP, and endpoint policies across Windows and mobile devices.
KEY RESPONSIBILITIES
A. Microsoft 365 E3/E5 Platform Administration
The candidate will be responsible for the day-to-day administration and security configuration of the organization's Microsoft 365 E3/E5 tenant, serving as the primary M365 administrator:
Administer user accounts, licences, groups (Entra ID), and conditional access policies in Microsoft Entra ID (formerly Azure AD) — including MFA enforcement, passwordless authentication setup, and guest access governance.
Configure and maintain Microsoft Defender for Business for endpoint protection across all company devices — including threat policies, antivirus profiles, attack surface reduction rules, and alert triage.
Deploy and manage Microsoft Intune for Mobile Device Management (MDM) and Mobile Application Management (MAM), covering device enrolment, compliance policies, and configuration profiles for Windows and mobile endpoints.
Manage Microsoft Purview compliance solutions — including Data Loss Prevention (DLP) policies, sensitivity labels, retention policies, communication compliance, and eDiscovery as required.
Administer Microsoft Defender for Office 365 (Plan 1/2 equivalent) — including Safe Links, Safe Attachments, anti-phishing policies, and spoof intelligence.
Configure and maintain Microsoft Sentinel (SIEM) for log ingestion, security event correlation, alert rules, and incident tracking. Develop and maintain basic KQL queries for monitoring and reporting.
Operate and maintain Microsoft Teams as the primary collaboration platform — including channel governance, meeting policies, external access controls, and Teams Phone configurations where applicable.
Manage SharePoint Online and OneDrive for Business — including site provisioning, permission structures, external sharing policies, and information architecture in alignment with the organization's data classification policy.
Maintain Exchange Online — including mail flow rules, anti-spam/anti-malware policies, shared mailboxes, distribution lists, and calendar management.
Monitor the Microsoft 365 Secure Score dashboard and implement recommended improvement actions on a scheduled cadence. Produce monthly security posture reports for management review.
Administer Microsoft 365 Backup and support disaster recovery testing as scheduled.
Manage the migration path from Microsoft 365 Business plans to E3/E5 licensing as required — including licence reconciliation, feature parity checks, and user communications.
B. ISO/IEC 27001:2022 ISMS Implementation Support
The candidate will work directly with management to support the organization's ISO/IEC 27001:2022 certification programme, acting as the primary documentation and operational owner for the ISMS:
Maintain and regularly update the ISMS document registry — including the Statement of Applicability (SoA), Risk Register, Asset Register, and all mandatory ISMS records as required by Clauses 5, 6, 7, 8, 9, and 10 of ISO/IEC 27001:2022.
Conduct scheduled information security risk assessments using the organization's defined risk assessment methodology — identifying threats, vulnerabilities, likelihood, and impact across information assets.
Coordinate and document internal ISMS audits in accordance with the audit programme — including scheduling, checklist preparation, evidence collection, finding documentation, and corrective action tracking.
Manage the corrective action and nonconformity register — tracking root cause analyses, remediation actions, responsible owners, and closure deadlines.
Support the preparation and coordination of external surveillance audits and the initial certification audit by the appointed certification body (CB).
Conduct and document information security awareness training sessions for all staff — covering phishing awareness, clean desk policy, data handling, acceptable use, and incident reporting procedures.
Maintain the Supplier and Third-Party Security Assessment process — including vendor risk questionnaires, contract clause reviews, and periodic reassessments for critical service providers.
Monitor the organization's compliance posture against all applicable controls in Annex A of ISO/IEC 27001:2022, and maintain gap tracking documentation.
Support management review meetings by preparing ISMS performance metrics, KPI dashboards, and input data covering audit results, incident statistics, risk treatment status, and security objective progress.
C. Security Policy Framework — Operationalization & Compliance
The organization has established a twelve-policy information security framework. The candidate will own the operationalization, monitoring, and periodic review of all policies:
Information Security Policy (Master) — maintain as living document; ensure all referenced sub-policies remain current and consistent.
Acceptable Use Policy (AUP) — enforce via Intune compliance baselines and M365 communication compliance; conduct periodic user attestation exercises.
Access Control Policy — maintain Role-Based Access Control (RBAC) matrices; conduct quarterly Privileged Access Reviews (PAR) across M365, SharePoint, and connected systems.
Data Classification & Handling Policy — implement and enforce via Microsoft Purview sensitivity labels; ensure all shared documents are appropriately labelled before distribution to clients and partners.
Incident Response Policy — maintain and periodically test the Incident Response Plan (IRP); manage the incident log and ensure timely escalation and reporting.
Business Continuity & Disaster Recovery Policy — maintain BC/DR documentation; coordinate at least one tabletop exercise annually.
Change Management Policy — operate the IT change request and approval workflow; maintain the change log.
Password & Authentication Policy — enforce MFA, password less authentication, and password complexity via Entra ID Conditional Access and Intune. Administer the corporate password manager.
Physical & Environmental Security Policy — conduct periodic office security walkthroughs; maintain the clean desk checklist and visitor log; coordinate with building management on physical access controls.
Mobile Device & Remote Access Policy — enforce via Intune device compliance policies; maintain the approved device register.
Third-Party & Supplier Security Policy — manage vendor onboarding security assessments; maintain the Approved Vendor Register.
Data Retention & Destruction Policy — implement retention labels in M365 Purview; coordinate secure media disposal as required.
D. Endpoint, Network & Infrastructure Security Operations
As the organization's primary IT operator, the candidate will manage day-to-day security operations across the IT environment:
Manage endpoint security posture across all Windows workstations and mobile devices — including patch management (Windows Update for Business / Intune), vulnerability scanning, and remediation tracking.
Monitor and maintain the organization's email security posture — including DMARC, DKIM, and SPF records; review quarantine reports and respond to phishing reports from end users.
Administer the corporate SSH (Tailscale) solution for remote access — managing user provisioning, connection policies, and access logs.
Monitor network security appliances (firewall, switch management) in coordination with the organisation's managed services provider (MSP) or network vendor, and escalate anomalies.
Operate Microsoft Sentinel — reviewing security alerts, investigating incidents, maintaining playbooks, and producing regular threat intelligence summaries relevant to the semiconductor and engineering sector.
Perform vulnerability assessments using approved tools on a scheduled basis — documenting findings and tracking remediation in the risk register.
Manage DNS, domain registrar settings, SSL certificate renewals, and web hosting security configurations as applicable.
Support IT asset lifecycle management — procurement requests, asset tagging, configuration, deployment, and secure decommissioning.
E. SEMI E187 / E188 Cybersecurity Compliance Awareness
As a semiconductor facility design consultancy serving Tier-1 fabs, the organization must demonstrate awareness of and alignment with semiconductor-specific cybersecurity standards:
Develop and maintain working knowledge of SEMI E187 (Cybersecurity Specification for Fab Equipment) and SEMI E188 (Malicious Software Prevention for Fab Equipment).
Support the preparation of documentation and responses related to client cybersecurity requirements referencing SEMI E187 / E188, NIST SP 800-82, and IEC 62443 as applicable to the organization's scope.
Coordinate with client security teams (Advanced Nodes Manufacturers) on IT/OT interface requirements, data transfer procedures, and supplier security questionnaire responses.
Maintain awareness of ITRS Group semiconductor facility security guidelines and incorporate relevant controls into the organization's security posture where applicable.
F. Collaboration Platforms & Productivity Tools Administration
Administer Autodesk Construction Cloud (ACC) and BIM Collaborate Pro — including user provisioning, project workspace setup, access control, and document permission management for engineering project teams.
Support onboarding of Revit cloud work sharing workflows via ACC BIM Collaborate Pro, in coordination with the engineering team.
Administer other productivity and project management tools as adopted by the organization — maintaining user access, licence management, and security integration.
Provide tier-1 and tier-2 IT helpdesk support to all Singapore staff — including hardware/software troubleshooting, M365 support, account management, and device configuration.
QUALIFICATIONS & EXPERIENCE
Minimum Academic Qualifications
Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related discipline from a recognized institution.
At least 5-8 years of relevant experience with at least three (3) years of relevant IT/cybersecurity work
Preferred Certifications (not all required — any of the following is advantageous)
Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
Microsoft Certified: Azure Administrator Associate (AZ-104) or M365 Administrator Associate (MS-102)
Microsoft Certified: Security Operations Analyst Associate (SC-200)
CompTIA Security+ or CompTIA CySA+
Certified Information Systems Security Professional (CISSP) Associate or SSCP — advantageous but not required at junior level
ISO/IEC 27001 Lead Implementer or Internal Auditor certificate (PECB, BSI, or equivalent) — highly advantageous
ITIL 4 Foundation — advantageous for service management context
Work Experience Profile
Prior internship or employment in an IT administration, IT helpdesk, or cybersecurity support role is preferred but not mandatory for fresh graduates.
Demonstrable hands-on exposure to Microsoft 365 administration — even through self-study, certifications, or lab environments — is strongly valued.
Exposure to ISO 27001 documentation or ISMS-related project work (academic, internship, or professional) is an advantage.
Experience working in a small-to-medium enterprise (SME) context where the role demands multitasking and broad ownership across IT functions is preferred over large-enterprise single-function experience.
Interested Parties please WhatsApp/Call us at 8893 3424 (Jasmine), and email your latest resume in WORD format to jl@businessedge.com.sg. You may call my office number at 65698233 (Ext.839) for a private & confidential discussion. EA License No.: 96C4864 Reg No.: R22108682 Lee Yit Foong Jasmine