We are seeking a self-motivated, authoritative Cyber & Information Security Manager to take ownership of our security ecosystem. You will transition our environment from standard IT operations into a mature, framework-driven cybersecurity posture. You will act as the core bridge between technical execution, external vendor ecosystems, and senior business leadership (CFO & Board of Directors).
As this is a lean team, you must be comfortable being highly hands-on with tools while simultaneously architecting policies and training frameworks from the ground up.
about the job
- Lead real-world incident response efforts, drawing on your proven, direct experience handling live security incidents.
- Monitor tools like TrendMicro daily across server, email, mobile, and endpoint environments to identify threats.
- Investigate and resolve critical vulnerabilities by working closely in the trenches with our IT teams.
- Act as a true partner rather than a police officer by working directly with application owners to coordinate patching and fix issues together.
- Manage penetration tests and annual assessments, actively helping teams remediate identified gaps instead of just flagging findings and walking away.
- Translate complex cyber risks into clear, actionable business terms to effectively brief Management and the Board of Directors.
- Cultivate a cyber-aware culture by leading quarterly security training for staff across all boutiques and corporate teams.
- Run monthly phishing simulations and provide actionable improvement plans.
- Ensure strict compliance with the PDPA by partnering with the DPO on privacy audits, risk assessments, and policy updates.
- Leverage frameworks like NIST CSF or ISO 27001 to lead our preparations for external audits, such as the Cyber Trust Mark Certification.
- Evaluate third-party vendor security to ensure our contracts include the necessary controls and audit rights.
skills and experience required
5+ years in cybersecurity, with clear experience managing external vendors/agencies and driving incident response.
Exceptional ability to explain technical risk to non-technical corporate executives. You must possess the professional maturity and firmness required to enforce security policies across engineering and application teams.
Highly hands-on with security tools (EDR, Vulnerability Scanners, Email Security) but strategically capable of building policies from scratch.
CISSP, CISM, or CRISC are highly preferred to ensure immediate credibility with senior stakeholders.
whats on offer
The permanent role for a Cyber & Information Security Manager offers a salary range of $ 7,000 – $ 8,000, along with additional company perks. This is a great opportunity to take the lead and collaborate closely with technology teams on global, enterprise-wide initiatives within the organization.
To apply online please use the 'apply' function, alternatively you can reach meat https://www.linkedin.com/in/Oliviatoh-032330132/. (EA: 94C3609 / R22109942)