Routiqo

IT Information Security Management (ISM) / CyberSecurity Officer

Nationgate Solution (M)

  • Perai, Penang
  • Full-time

We are looking for a motivated and skilled IT Information Security Management System (ISMS) / Cyber Security Officer to support and strengthen the organization's cybersecurity posture, information security governance, and compliance initiatives. The ideal candidate will be responsible for implementing, monitoring, and maintaining security controls to protect the organization's information assets, systems, applications, networks, and infrastructure from cyber threats and security risks.

In this role, you will work closely with IT Infrastructure, Application, ERP, MES, WMS, Operations teams, vendors, auditors, and business users to ensure compliance with security policies, industry standards, and regulatory requirements. You will participate in security monitoring, vulnerability management, incident response, security assessments, audit activities, and continuous improvement of cybersecurity controls across the organization.

Key Responsibilities

  1. Support the implementation, maintenance, and continuous improvement of the organization's Information Security Management System (ISMS).
  2. Monitor and ensure compliance with information security policies, standards, procedures, and regulatory requirements.
  3. Assist in conducting information security risk assessments, security reviews, and gap analyses for systems, applications, and infrastructure.
  4. Identify, assess, and track security vulnerabilities, risks, and remediation activities.
  5. Support security incident investigation, containment, recovery, and Root Cause Analysis (RCA) activities.
  6. Monitor security alerts, logs, and events, and coordinate response actions when required.
  7. Coordinate vulnerability assessments, penetration testing activities, and remediation follow-up with internal teams and external vendors.
  8. Support cybersecurity controls related to network security, endpoint protection, user access management, and data protection.
  9. Perform user access reviews, privileged account reviews, and access control compliance checks.
  10. Participate in internal audits, customer audits, security assessments, and certification activities.
  11. Maintain security policies, procedures, standards, risk registers, audit evidence, and related documentation.
  12. Support cybersecurity awareness and training programs for employees.
  13. Review security requirements for new systems, applications, infrastructure changes, and IT projects.
  14. Collaborate with Infrastructure, Application, ERP, MES, WMS, Server/Database administrator and Operations teams to ensure security requirements are integrated into business and IT processes.
  15. Monitor compliance with security baselines, system hardening standards, patch management requirements, and cybersecurity policies.
  16. Support business continuity, disaster recovery, and IT resilience initiatives.
  17. Coordinate with vendors, customers, auditors, and business stakeholders on security-related matters.
  18. Stay updated on emerging cybersecurity threats, vulnerabilities, technologies, and industry best practices.

Qualifications

  • Bachelor's Degree in CyberSecurity, Information Technology, Computer Science, Information Security, or a related field.
  • Fresh graduates are encouraged to apply. Candidates with experience in Information Security, Cyber Security, IT Governance, Risk Management, Compliance, Infrastructure, or IT Operations will have an added advantage.
  • Basic understanding of cybersecurity principles, information security practices, and risk management concepts.
  • Familiarity with networking concepts, Windows environments, Active Directory, and enterprise IT infrastructure.
  • Knowledge of Information Security Management Systems (ISMS) and security standards is an advantage.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Good communication and interpersonal skills.
  • Ability to work independently and collaboratively with cross-functional teams.
  • Strong documentation, organizational, and reporting skills.
  • Willingness to participate in security incident response activities when required.

Preferred Skills

  • Basic understanding of information security standards such as ISO 27001, NIST Cybersecurity Framework, or CIS Controls.
  • Familiarity with security monitoring, endpoint protection, antivirus, vulnerability management, and email security solutions.
  • Understanding of network security concepts, including firewalls, VPNs, network segmentation, and access controls.
  • Familiarity with Active Directory, user account administration, and privileged access management.
  • Knowledge of Windows Server security hardening, patch management, and system security best practices is an advantage.
  • Experience supporting audit preparation, compliance assessments, and security documentation is preferred.
  • Relevant certifications such as Security+, SC-900, ISO 27001 Foundation, CEH, or equivalent certifications are an added advantage.
  • Excellent communication skills to collaborate with users, management, auditors, customers, vendors, and technical teams.
  • Proficiency in English and Mandarin is preferred due to communication and collaboration with overseas customers, vendors, and business partners.

Skills

  • Analytical
  • Chinese
  • Communication
  • Cybersecurity
  • English
  • Financial reporting
  • Networking
  • Problem solving
  • Risk assessment
  • Teamwork
  • Windows server