We are looking for a technically strong cybersecurity professional to join an established security team and help strengthen how security controls are assessed across a complex enterprise environment.
Unlike a traditional compliance-focused assurance role, this position requires someone who can go beyond policy reviews and practically assess whether security controls are working as intended. The role covers cloud, infrastructure, security technologies, endpoints and identity, with an increasing focus on using AI, scripting and automation to make assurance activities more efficient and scalable.
Key Responsibilities:
- Perform technical assessments of security controls across cloud, infrastructure, endpoints and enterprise security platforms.
- Review cloud environments and configurations to identify security weaknesses, control gaps and misconfigurations.
- Assess the effectiveness of technologies such as SIEM/SOAR, EDR/NDR, WAF, SASE, CSPM and threat intelligence platforms.
- Review controls across IAM, privileged access, endpoint security and remote-access/Zero Trust environments.
- Assess technology architectures and security implementations against recognised security standards and industry practices.
- Perform practical control testing through activities such as configuration reviews, log analysis, IAM policy reviews and security-control validation.
- Use AI, scripting and automation to improve areas such as evidence collection, control assessment, security analysis and reporting.
- Translate technical findings into clear risk observations and recommendations for Technology and senior stakeholders.
- Work closely with Cloud, Infrastructure and Security teams to remediate identified weaknesses.
- Help improve and automate the broader cyber assurance methodology to reduce manual effort and provide better visibility over control effectiveness.
Requirements:
- At least 5 years of experience across cybersecurity, technical assurance, security engineering, technology risk or related areas.
- Strong technical understanding of cloud and enterprise security controls, ideally with experience across more than one cloud environment.
- Hands-on experience assessing, operating or implementing security technologies across areas such as endpoint security, SIEM/SOAR, network security, IAM/PAM, vulnerability management or cloud security.
- Ability to practically assess control effectiveness rather than relying solely on documentation and policy reviews.
- Familiarity with security frameworks and standards such as NIST CSF, ISO 27001 and Security-by-Design principles.
- Experience using Python, scripting, AI or other automation tools to improve cybersecurity or assurance processes would be highly advantageous.
- Strong analytical skills with the ability to communicate technical findings clearly to both technical and non-technical stakeholders.
To apply:
If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060