Search by job, company or skills

IT & Cybersecurity Executive (Senior-Lead)

5-8 Years
SGD 5,200 - 6,500 per month
  • Posted 7 days ago
  • Be among the first 10 applicants

Job Description

KEY RESPONSIBILITIES

A. Microsoft 365 E3/E5 Platform Administration

The candidate will be responsible for the day-to-day administration and security configuration of the organization's Microsoft 365 E3/E5 tenant, serving as the primary M365 administrator:

  • Administer user accounts, licences, groups (Entra ID), and conditional access policies in Microsoft Entra ID (formerly Azure AD) - including MFA enforcement, passwordless authentication setup, and guest access governance.

  • Configure and maintain Microsoft Defender for Business for endpoint protection across all company devices - including threat policies, antivirus profiles, attack surface reduction rules, and alert triage.

  • Deploy and manage Microsoft Intune for Mobile Device Management (MDM) and Mobile Application Management (MAM), covering device enrolment, compliance policies, and configuration profiles for Windows and mobile endpoints.

  • Manage Microsoft Purview compliance solutions - including Data Loss Prevention (DLP) policies, sensitivity labels, retention policies, communication compliance, and eDiscovery as required.

  • Administer Microsoft Defender for Office 365 (Plan 1/2 equivalent) - including Safe Links, Safe Attachments, anti-phishing policies, and spoof intelligence.

  • Configure and maintain Microsoft Sentinel (SIEM) for log ingestion, security event correlation, alert rules, and incident tracking. Develop and maintain basic KQL queries for monitoring and reporting.

  • Operate and maintain Microsoft Teams as the primary collaboration platform - including channel governance, meeting policies, external access controls, and Teams Phone configurations where applicable.

  • Manage SharePoint Online and OneDrive for Business - including site provisioning, permission structures, external sharing policies, and information architecture in alignment with the organization's data classification policy.

  • Maintain Exchange Online - including mail flow rules, anti-spam/anti-malware policies, shared mailboxes, distribution lists, and calendar management.

  • Monitor the Microsoft 365 Secure Score dashboard and implement recommended improvement actions on a scheduled cadence. Produce monthly security posture reports for management review.

  • Administer Microsoft 365 Backup and support disaster recovery testing as scheduled.

  • Manage the migration path from Microsoft 365 Business plans to E3/E5 licensing as required - including licence reconciliation, feature parity checks, and user communications.

B. ISO/IEC 27001:2022 ISMS Implementation Support

The candidate will work directly with management to support the organization's ISO/IEC 27001:2022 certification programme, acting as the primary documentation and operational owner for the ISMS:

  • Maintain and regularly update the ISMS document registry - including the Statement of Applicability (SoA), Risk Register, Asset Register, and all mandatory ISMS records as required by Clauses 5, 6, 7, 8, 9, and 10 of ISO/IEC 27001:2022.

  • Conduct scheduled information security risk assessments using the organization's defined risk assessment methodology - identifying threats, vulnerabilities, likelihood, and impact across information assets.

  • Coordinate and document internal ISMS audits in accordance with the audit programme - including scheduling, checklist preparation, evidence collection, finding documentation, and corrective action tracking.

  • Manage the corrective action and nonconformity register - tracking root cause analyses, remediation actions, responsible owners, and closure deadlines.

  • Support the preparation and coordination of external surveillance audits and the initial certification audit by the appointed certification body (CB).

  • Conduct and document information security awareness training sessions for all staff - covering phishing awareness, clean desk policy, data handling, acceptable use, and incident reporting procedures.

  • Maintain the Supplier and Third-Party Security Assessment process - including vendor risk questionnaires, contract clause reviews, and periodic reassessments for critical service providers.

  • Monitor the organization's compliance posture against all applicable controls in Annex A of ISO/IEC 27001:2022, and maintain gap tracking documentation.

  • Support management review meetings by preparing ISMS performance metrics, KPI dashboards, and input data covering audit results, incident statistics, risk treatment status, and security objective progress.

C. Security Policy Framework - Operationalization & Compliance

The organization has established a twelve-policy information security framework. The candidate will own the operationalization, monitoring, and periodic review of all policies:

  • Information Security Policy (Master) - maintain as living document ensure all referenced sub-policies remain current and consistent.

  • Acceptable Use Policy (AUP) - enforce via Intune compliance baselines and M365 communication compliance conduct periodic user attestation exercises.

  • Access Control Policy - maintain Role-Based Access Control (RBAC) matrices conduct quarterly Privileged Access Reviews (PAR) across M365, SharePoint, and connected systems.

  • Data Classification & Handling Policy - implement and enforce via Microsoft Purview sensitivity labels ensure all shared documents are appropriately labelled before distribution to clients and partners.

  • Incident Response Policy - maintain and periodically test the Incident Response Plan (IRP) manage the incident log and ensure timely escalation and reporting.

  • Business Continuity & Disaster Recovery Policy - maintain BC/DR documentation coordinate at least one tabletop exercise annually.

  • Change Management Policy - operate the IT change request and approval workflow maintain the change log.

  • Password & Authentication Policy - enforce MFA, password less authentication, and password complexity via Entra ID Conditional Access and Intune. Administer the corporate password manager.

  • Physical & Environmental Security Policy - conduct periodic office security walkthroughs maintain the clean desk checklist and visitor log coordinate with building management on physical access controls.

  • Mobile Device & Remote Access Policy - enforce via Intune device compliance policies maintain the approved device register.

  • Third-Party & Supplier Security Policy - manage vendor onboarding security assessments maintain the Approved Vendor Register.

  • Data Retention & Destruction Policy - implement retention labels in M365 Purview coordinate secure media disposal as required.

D. Endpoint, Network & Infrastructure Security Operations

As the organization's primary IT operator, the candidate will manage day-to-day security operations across the IT environment:

  • Manage endpoint security posture across all Windows workstations and mobile devices - including patch management (Windows Update for Business / Intune), vulnerability scanning, and remediation tracking.

  • Monitor and maintain the organization's email security posture - including DMARC, DKIM, and SPF records review quarantine reports and respond to phishing reports from end users.

  • Administer the corporate SSH (Tailscale) solution for remote access - managing user provisioning, connection policies, and access logs.

  • Monitor network security appliances (firewall, switch management) in coordination with the organisation's managed services provider (MSP) or network vendor, and escalate anomalies.

  • Operate Microsoft Sentinel - reviewing security alerts, investigating incidents, maintaining playbooks, and producing regular threat intelligence summaries relevant to the semiconductor and engineering sector.

  • Perform vulnerability assessments using approved tools on a scheduled basis - documenting findings and tracking remediation in the risk register.

  • Manage DNS, domain registrar settings, SSL certificate renewals, and web hosting security configurations as applicable.

  • Support IT asset lifecycle management - procurement requests, asset tagging, configuration, deployment, and secure decommissioning.

E. SEMI E187 / E188 Cybersecurity Compliance Awareness

As a semiconductor facility design consultancy serving Tier-1 fabs, the organization must demonstrate awareness of and alignment with semiconductor-specific cybersecurity standards:

  • Develop and maintain working knowledge of SEMI E187 (Cybersecurity Specification for Fab Equipment) and SEMI E188 (Malicious Software Prevention for Fab Equipment).

  • Support the preparation of documentation and responses related to client cybersecurity requirements referencing SEMI E187 / E188, NIST SP 800-82, and IEC 62443 as applicable to the organization's scope.

  • Coordinate with client security teams (Advanced Nodes Manufacturers) on IT/OT interface requirements, data transfer procedures, and supplier security questionnaire responses.

  • Maintain awareness of ITRS Group semiconductor facility security guidelines and incorporate relevant controls into the organization's security posture where applicable.

F. Collaboration Platforms & Productivity Tools Administration

  • Administer Autodesk Construction Cloud (ACC) and BIM Collaborate Pro - including user provisioning, project workspace setup, access control, and document permission management for engineering project teams.

  • Support onboarding of Revit cloud work sharing workflows via ACC BIM Collaborate Pro, in coordination with the engineering team.

  • Administer other productivity and project management tools as adopted by the organization - maintaining user access, licence management, and security integration.

  • Provide tier-1 and tier-2 IT helpdesk support to all Singapore staff - including hardware/software troubleshooting, M365 support, account management, and device configuration.

QUALIFICATIONS & EXPERIENCE

Minimum Academic Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related discipline from a recognized institution.

  • At least 5-8 years of relevant experience with at least three (3) years of relevant IT/cybersecurity work

Preferred Certifications (not all required - any of the following is advantageous)

  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)

  • Microsoft Certified: Azure Administrator Associate (AZ-104) or M365 Administrator Associate (MS-102)

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)

  • CompTIA Security+ or CompTIA CySA+

  • Certified Information Systems Security Professional (CISSP) Associate or SSCP - advantageous but not required at junior level

  • ISO/IEC 27001 Lead Implementer or Internal Auditor certificate (PECB, BSI, or equivalent) - highly advantageous

  • ITIL 4 Foundation - advantageous for service management context

Work Experience Profile

  • Prior internship or employment in an IT administration, IT helpdesk, or cybersecurity support role is preferred but not mandatory for fresh graduates.

  • Demonstrable hands-on exposure to Microsoft 365 administration - even through self-study, certifications, or lab environments - is strongly valued.

  • Exposure to ISO 27001 documentation or ISMS-related project work (academic, internship, or professional) is an advantage.

  • Experience working in a small-to-medium enterprise (SME) context where the role demands multitasking and broad ownership across IT functions is preferred over large-enterprise single-function experience.

    Interested Parties please WhatsApp/Call us at 8893 3424 (Jasmine), and email your latest resume in WORD format to [Confidential Information]. You may call my office number at 65698233 (Ext.839) for a private & confidential discussion. EA License No.: 96C4864 Reg No.: R22108682 Lee Yit Foong Jasmine

More Info

Job Type:
Industry:
Employment Type:

Job ID: 152324115

Similar Jobs

Singapore

Skills:

sentinel IsmsIso 27001IntuneEntra IDDefenderPurviewTeamsSharepointMicrosoft 365 E3

Beware of Scammers

We don’t charge money for job offers