Senior Executive, IT Security Operations

Summary

Oversee and execute IT security operations for a financial services company, managing firewalls, WAFs, and incident response while ensuring compliance with regional regulations like PDPA and PCI-DSS.

Job Responsibilities


1. Security Operations & BAU

· Manage and administer configuration changes on production Firewalls, Web Application Firewalls (WAF), Application Load Balancer, network access controller and related network devices

· Approve and implement business-as-usual (BAU) security access and modification requests

· Maintain security rules, firewall policies, and system hardening

· Monitor security infrastructure health to ensure continuous, optimal performance

· Collaborate with network and infrastructure teams to resolve engineering issues

2. Security Incident Management & Reporting

· Provide comprehensive security operational reporting to management teams regularly

· Monitor security reporting dashboards to identify anomalous network and system behavior

· Ensure security incidents are tracked, investigated, and properly managed to resolution

· Respond to security incidents as a key technical escalation point

· Partner with the Managed Security Services Provider (MSSP) to ensure incident follow-up

· Review security incidents, firewall policies and operational performance with the vendor on a regular basis.

· Sign-off on vendor security reports, service level agreements (SLAs), and incident closures.

3. Vulnerability, Threat & API Management

· Manage API security configurations, gateways, and authentication controls

· Analyze threat intelligence feeds to proactively defend against emerging security risks

· Manage the end-to-end vulnerability assessment and penetration testing (VAPT) lifecycles

· Track patching schedules across systems to ensure timely remediation of flaws

4. Governance, Risk & Compliance

· Partner hand in hand with the IT Governance team on setup alignment

· Ensure day-to-day IT operations fully comply with internal corporate IT policies

· Align IT security standards with strict regional regulatory requirements

· Maintain continuous compliance for PDPA, MAS TRM, and PCI-DSS frameworks

· Prepare documentation, evidence, and reports for internal and external audits

· Update security policies to reflect evolving regional financial regulations

· Assess third-party vendor risks against corporate security frameworks

Job Requirements

Education & Experience

  • Minimum 5 years of working experience within IT infrastructure and minimum 3 years of dedicated experience in IT Security
  • Experience in Insurance or Financial Services Institutions (FSI) is highly preferred
  • Degree in Computer Science, Information Technology, or related fields

Technical Skills &Competencies

  • Hands-on expertise configuring enterprise-grade Firewalls, WAF technologies, Application gateway, Application load balancer, switches, Dot1x authentication and IPSec VPN
  • Knowledge of Azure API security management principles, OAuth2, OWASP API Top 10, and modern authentication
  • Vendor management skills to effectively govern external security partners and MSSPs
  • Knowledge of MAS Guidelines, PDPA, and PCI-DSS compliance frameworks
  • Certification in CISSP, CISM, CEH, or Azure Security Engineer (AZ-500) is preferred
  • Analytical mindset to troubleshoot network security anomalies under pressure

Soft Skills

  • Communication skills to explain complex technical risks clearly to non-technical stakeholders
  • Team player to collaborate effectively across multi-disciplinary IT and governance infrastructure groups
  • Adaptability to maintain focus and drive successful resolutions in high-pressure incident response situations
  • Stakeholder management