Deskripsi pekerjaan Cybersecurity & Compliance Analyst MixWork Pte. Ltd.
⚠️ Important: This role requires professional working proficiency in English (written & spoken). All screenings, interviews, and daily work communication will be conducted exclusively in English. Basic or conversational-level English is not sufficient for this role.
About MixWork & Our Client
MixWork is the premier HR outsourcing partner for strategic workforce solutions, empowering brands and global organizations with skilled, dedicated, and professional top-tier regional teams from South East Asia to accelerate their business growth. On behalf of our client, a premier, household-name retail enterprise headquartered in Singapore with a well-established international footprint and a heritage of quality and operational excellence, we are seeking a dedicated professional to join their team as they actively modernize their omni-channel capabilities and leverage a sophisticated regional technology footprint to support their digital and brick-and-mortar operations.
Role Summary
This role is client’s internal security owner for all cybersecurity and compliance matters across the group's Singapore and offshore IT environments. The Cybersecurity & Compliance Analyst manages the client's relationship with the third-party SOC partner, owns security policy and awareness programmes, and supports the Head of IT in his capacity as Data Protection Officer (DPO) under Singapore PDPA and Indonesia UU PDP obligations.
This is not a SOC analyst role. The candidate may not operate a SIEM console directly. Instead, they set security requirements for the SOC partner, review and challenge what the partner reports, and ensure that security posture improvements land across all client’s systems and environments.
Manage client’s third-party SOC partner relationship: set monitoring requirements, review escalated alerts, challenge the partner's findings where necessary, and ensure SLA compliance.
Receive and act on escalated security incidents from the SOC partner: direct containment actions, coordinate with affected teams, and produce incident reports for the Head of IT.
Conduct periodic reviews of the SOC partner's detection coverage and reporting quality; recommend adjustments to monitoring scope and escalation thresholds.
Security Policy Ownership
Own client’s IT security policy library: review policies at least annually, update them when systems or regulatory obligations change, and obtain sign-off from the Head of IT.
Conduct ISO 27001 gap assessments against client’s current security controls; track findings, assign remediation owners, and monitor closure.
Support SaaS and vendor security assessments: review new tools for data handling risks and provide a structured go / no-go recommendation to the Head of IT before onboarding.
Plan and execute biannual phishing simulation exercises; measure click-through and submission rates, report outcomes, and run follow-up coaching for high-risk users.
Manage Azure RBAC and Privileged Identity Management (PIM): conduct quarterly access reviews, enforce just-in-time admin activation, and remediate over-privileged accounts.
Configure and maintain Conditional Access policies in Azure Entra ID: MFA enforcement, device compliance requirements, and location-based access controls.
Manage Microsoft Purview: DLP policies, sensitivity labels, information barriers, and compliance reports relevant to PDPA and UU PDP data handling requirements.
Support the Head of IT (DPO) with PDPA compliance: maintain the Data Processing Agreement register, assist with DPIAs for new SaaS systems, and support data breach investigation and notification procedures.
Vulnerability Management and Reporting
Review vulnerability findings surfaced by CrowdStrike Falcon Spotlight across client’s endpoints; prioritise remediation based on risk, and track closure with asset owners.
Assess client’s current endpoint device estate and produce a recommendation to the Head of IT on Mobile Device Management (MDM) strategy, covering risk exposure, scope of enforcement, and implementation approach for both Singapore and offshore users.
Produce monthly security posture reports: open vulnerabilities and ageing, incident summary, access review outcomes, and Secure Score trends across Microsoft 365.
Minimum 4 years of IT security experience with demonstrated responsibility for security policy, compliance, or security operations oversight.
Full Legal Compliance: Official employment contract managed under MixWork Indonesia, ensuring complete adherence to local labor laws and employment standards.
Healthcare & Social Security: Full registration and contributions for both BPJS Kesehatan and BPJS Ketenagakerjaan to ensure comprehensive coverage.
Religious Holiday Allowance: Guaranteed annual mandatory Religious Holiday Allowance (THR) paid in accordance with statutory government regulations.
What We Offer
Flexible Medical Benefit: Comprehensive healthcare coverage fully inclusive of dental, optical, outpatient care, and wellness treatments to support your overall well-being.
Regional Ecosystem: Access to ongoing global corporate alignment, dedicated HR support, and a stable, creative career trajectory with a premier international brand.
Important Notes
Language Requirement: As this is an international role, please note that all screenings and interviews will be conducted exclusively in English.
Equal Opportunity Employer: MixWork is committed to creating an inclusive, diverse, and fair workplace culture. We value talent and capability above all else, completely free from discrimination or bias.
Data lowongan bersumber dari glints. Tombol “Lamar” mengarahkan Anda ke halaman aslinya.