

Search by job, company or skills
About Hytech
Hytech is a leading management consulting firm headquartered in Australia and Singapore, specialising in digital transformation for fintech and financial services organisations. We deliver end-to-end consulting services and provide robust middle- and back-office solutions that enable our clients to optimise operations, enhance efficiency, and stay ahead in a fast-evolving digital landscape. Our client portfolio includes top global trading platforms and leading crypto exchanges.
We apply AI and data-driven approaches to real-world financial use cases, including risk management, process optimization, and decision support, with a focus on delivering practical impact.
With more than 2,000 professionals worldwide, Hytech has a strong and growing international presence, with offices across Australia, Singapore, Malaysia, Taiwan, the Philippines, Thailand, Morocco, Cyprus, Dubai, and beyond.
Role Positioning
The OST (Office Security Team) serves as the core hub for platform architecture and security capabilities, acting as the L3 final responder for complex outages and security incidents. The team implements and executes security policies defined by GRC on the platform side. Its stakeholders include platform owners, Corporate IT (Tier-1 / Tier-2), and security-incident escalation parties. It does not handle end-user requests such as fault reporting or device deployment directly.
Key Responsibilities
1. Identity & Access Platform
• Deploy and administer global AD / Entra ID (Azure AD) architecture, including hybrid synchronization via Entra Connect, OU structure design, and multi-region identity integration.
• Configure and manage SSO and Conditional Access policies (enforce rules defined by GRC; policy creation is out-of scope).
• Administer Global VPN / ZTNA and M365 Admin platforms, covering security baselines and access control.
2. Endpoint & Network Infrastructure
• Deploy and manage Mac / iOS MDM (Jamf Pro / Intune): baseline configuration, certificate issuance, patch management, and remote lock / wipe operations.
• Build, configure and operate global enterprise-grade Wi-Fi 802.1X authentication architecture (Aruba / Ruijie AC), including RADIUS and certificate-based access.
• Deploy and manage SASE / ZTNA network security edge platforms: policy configuration, split-tunnel setup, and network ACL rules.
• Hands-on implementation of above-mentioned platforms, covering PoC, pilot roll-out and production go-live (not limited to planning work only).
3. AI Platform Governance & Execution
• Administer AI enterprise platforms (Claude Enterprise / ChatGPT Enterprise): provision individual and shared team seats, conduct whitelist evaluation, and manage backend permissions.
• Manage credit / seat budget allocation and consumption tracking (GPT credits, Claude USD billing), enforce tiered quota controls by user role.
• Process Tier-0 capability access requests (MCP, Cowork, Agent Building, Codex Cloud+Internet, Canvas) in compliance with GRC approval policies, and coordinate roll-out with the AI Department.
4. Security Incident & Compliance Collaboration
• Act as the L3 escalation handler for platform-side security incidents; support SOC on XDR alert investigation and root-cause remediation.
• Implement and enforce security policies and controls defined by GRC (policy definition is out-of-scope).
• Supply platform-level data, logs and evidence for compliance audits led by GRC (audit execution itself is out-of-scope).
5. Technical Sourcing & Project Support
• Provide technical specifications and vendor / solution evaluation recommendations to inform purchasing decisions (procurement execution is out-of-scope: no inquiry, order processing or payment responsibilities).
• Deliver cross-team work with Corporate IT, SOC and GRC following the corporate office-security RACI governance model.
• Establish and maintain SOPs and architecture documentation for platform operations.
• Complete other platform-related tasks assigned by the supervisor. Required Experience & Technical Competencies
• Minimum 3 years of hands-on experience in enterprise IT infrastructure, identity management or cybersecurity engineering; proven practical deployment experience (beyond advisory-only support).
• Solid knowledge of AD / Entra ID (Azure AD), including hybrid synchronization, GPO, OU structure and permission models.
• Practical working experience with Mac / iOS MDM solutions; Jamf Pro preferred, Intune considered a plus, covering baseline policies, certificate issuance and patch management.
• Hands-on experience with enterprise Wi-Fi 802.1X / RADIUS architecture (Aruba / Ruijie is a plus), as well as SASE / ZTNA platforms.
• Proficiency in M365 Admin, Conditional Access / MFA, and VPN platform administration.
• Prior experience managing enterprise AI platforms (Claude Enterprise, ChatGPT Enterprise or comparable solutions) is a plus.
• Track record of supporting SOC / GRC teams for security incident response and policy implementation.
• Ability to translate business / procurement requirements into technical specifications, without owning end-to-end procurement workflows.
• Strong cross-regional collaboration skills across multiple time-zones and legal entities; capable of independent delivery under RACI governance frameworks.
• Excellent verbal and written communication skills in both English and Chinese.
• Able to work under pressure and effectively respond to platform-level emergency incidents.
Job ID: 152977821