IT Security Operation Lead_3266

Job Level:  Professional
Location: 

Kuala Lumpur, MY

Area of Expertise:  IT & Tech Engineering
Unit:  Allianz Technology
Employing Entity:  Allianz Technology Sdn. Bhd.
Job Type:  Full-Time
Remote Job:  100% on-site
Employment Type:  Permanent
ID:  105470
Position Cluster: 

Key Responsibilities

  • Local Solutions / Services Monitoring and Management (Responsible): Monitor, operate and maintain the RDC's local security solutions and services, detecting and acting on potential security events and threats. The Head of IS signs off; the Head of IF & IS and the Head of RDC are kept informed.
  • Tickets and Remediation (Responsible): Own the security ticket queue end to end triage, investigate and remediate consulting the IF and ADM teams and the Central ACDC Team where the fix sits outside IS.
  • SOC Alerts Response and Remediation (Accountable): Own the local response to SOC alerts raised and worked by the Central ACDC Team validate, drive remediation to closure and sign off the outcome, consulting the IF and ADM teams and third-party vendors as required.
  • Vulnerability Scanning (Responsible): Execute vulnerability scans across the RDC estate on the platform owned and signed off by the Central AVM Team, consulting the AZT MY ISO and OE ISO on scope and findings.
  • Vulnerability Tracking and Remediation (Responsible): Track identified vulnerabilities to closure with the IF, ADM and application owners, reporting progress to the Central AVM Team (accountable) and consulting the AZT MY ISO and OE ISO.
  • Change Management (Responsible): Prepare, assess and implement security-related changes in line with the change process, with the Head of IS signing off and the IF and ADM teams informed.
  • Incident and Problem Management (Accountable): Own local security incident and problem management  coordinate investigation and root-cause analysis with the Central ACDC Team (responsible), consult the IF and ADM teams, and keep the AZT MY ISO, OE ISO and OE IT Risk informed.
  • Access Management and User Access Review (Responsible): Process access requests together with the Central IAM, ACDC and Cloud WAF teams and run the half-yearly user access review for the RDC, with the Head of IS signing off.
  • Group Solutions / Services Management (Accountable): Act as the local owner for Group-provided security solutions and services delivered by the Central ACDC, AVM, IAM and Cloud WAF teams align requirements, oversee service quality and sign off local adoption.
  • Regulatory, Compliance and Audit Management (Responsible): Deliver the evidence, control checks and remediation actions required for regulatory, compliance and audit requests, consulting the AZT MY ISO, OE ISO, OE IT Risk and the Central IAM / Cloud WAF teams. Note: policy and standard setting sits with the ISO and OE IT Risk, not with this role.
  • Security Reporting and Knowledge Management (Responsible): Produce recurring and ad-hoc security reporting for the Head of IS, the Head of IF & IS and the Head of RDC, and maintain security documentation, runbooks and the knowledge base for the RDC.
  • Security Evaluation and Penetration Testing Support (Responsible / Consulted): Perform security evaluations of solutions and services jointly with the AZT MY ISO and OE ISO (shared responsible), and support penetration testing in a consulted / informed capacity pentests are managed by OE ISO through third-party engagement or run by Group (e.g. bug bounty, hackability) and are not executed by this role.
  • Security Project and Demand Support (Accountable / Consulted): Provide security input and sign-off for projects delivered with PMO (responsible) and third-party vendors, and act as a consulted party in demand management led by OE ISO.
  • Any other duties when deemed necessary. Completing projects on various issues when needed.Continuous Improvement: Keep current with emerging threats and security operations practice, and propose improvements to local processes, tooling and automation.

 

Key Requirements / Skills / Experiences

  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related field.
  • Proven experience in information security, network security, or a related role.
  • Strong understanding of security principles, practices, and technologies.
  • Hands-on experience with security monitoring, SIEM/SOC alert handling and incident response tools and technologies.
  • Practical experience with vulnerability scanning and remediation tracking, and with access management / user access reviews (IAM, cloud and WAF platforms).
  • Working knowledge of ITIL-based incident, problem and change management, and comfort operating within a defined RACI across local and central/Group teams.
  • Proficiency in scripting or programming languages (e.g., Python, PowerShell) for automation tasks.
  • Familiarity with cloud security and security frameworks (e.g., NIST, ISO 27001).
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team.
  • Certifications in security or related areas (e.g., Certified Information Systems Security Professional - CISSP, Certified Ethical Hacker - CEH) are a plus.
  • This role may require Extended working hours OR as when required by the business availability and working outside regular hours to respond to security incidents or perform scheduled maintenance.
  • The position may involve collaboration with remote teams and vendors to ensure effective security operations and support.

Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us. 

At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. And the foundation for this is our inclusive workplace, where people and performance both matter, and nurtures a culture grounded in integrity, fairness, inclusion and trust. 

We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations. 

Great to have you on board. Let's care for tomorrow. 

 

Note: Having different strengths, experiences, perspectives and approaches is an integral part of Allianz‘ company culture. One means to achieve this is a regular rotation of Allianz Executive employees across functions, Allianz entities and geographies. Therefore, the company expects from its employees a general openness and a high motivation to regularly change positions and collect experiences across Allianz Group.