Senior Executive, IT Security Operations
Summary
Oversee and execute IT security operations for a financial services company, managing firewalls, WAFs, and incident response while ensuring compliance with regional regulations like PDPA and PCI-DSS.
Job Responsibilities
1. Security Operations & BAU
· Manage and administer configuration changes on production Firewalls, Web Application Firewalls (WAF), Application Load Balancer, network access controller and related network devices
· Approve and implement business-as-usual (BAU) security access and modification requests
· Maintain security rules, firewall policies, and system hardening
· Monitor security infrastructure health to ensure continuous, optimal performance
· Collaborate with network and infrastructure teams to resolve engineering issues
2. Security Incident Management & Reporting
· Provide comprehensive security operational reporting to management teams regularly
· Monitor security reporting dashboards to identify anomalous network and system behavior
· Ensure security incidents are tracked, investigated, and properly managed to resolution
· Respond to security incidents as a key technical escalation point
· Partner with the Managed Security Services Provider (MSSP) to ensure incident follow-up
· Review security incidents, firewall policies and operational performance with the vendor on a regular basis.
· Sign-off on vendor security reports, service level agreements (SLAs), and incident closures.
3. Vulnerability, Threat & API Management
· Manage API security configurations, gateways, and authentication controls
· Analyze threat intelligence feeds to proactively defend against emerging security risks
· Manage the end-to-end vulnerability assessment and penetration testing (VAPT) lifecycles
· Track patching schedules across systems to ensure timely remediation of flaws
4. Governance, Risk & Compliance
· Partner hand in hand with the IT Governance team on setup alignment
· Ensure day-to-day IT operations fully comply with internal corporate IT policies
· Align IT security standards with strict regional regulatory requirements
· Maintain continuous compliance for PDPA, MAS TRM, and PCI-DSS frameworks
· Prepare documentation, evidence, and reports for internal and external audits
· Update security policies to reflect evolving regional financial regulations
· Assess third-party vendor risks against corporate security frameworks
Job Requirements
Education & Experience
- Minimum 5 years of working experience within IT infrastructure and minimum 3 years of dedicated experience in IT Security
- Experience in Insurance or Financial Services Institutions (FSI) is highly preferred
- Degree in Computer Science, Information Technology, or related fields
Technical Skills &Competencies
- Hands-on expertise configuring enterprise-grade Firewalls, WAF technologies, Application gateway, Application load balancer, switches, Dot1x authentication and IPSec VPN
- Knowledge of Azure API security management principles, OAuth2, OWASP API Top 10, and modern authentication
- Vendor management skills to effectively govern external security partners and MSSPs
- Knowledge of MAS Guidelines, PDPA, and PCI-DSS compliance frameworks
- Certification in CISSP, CISM, CEH, or Azure Security Engineer (AZ-500) is preferred
- Analytical mindset to troubleshoot network security anomalies under pressure
Soft Skills
- Communication skills to explain complex technical risks clearly to non-technical stakeholders
- Team player to collaborate effectively across multi-disciplinary IT and governance infrastructure groups
- Adaptability to maintain focus and drive successful resolutions in high-pressure incident response situations
- Stakeholder management