Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
The Hoffman Agency

APAC IT Manager, Cybersecurity

The Hoffman Agency

. Own the lifecycle of security documentation, including IT Security Policy, Security Incident Response Procedures, Business Continuity Plan, Disaster Recovery Plan, AI Policy oversight, and related documents .

Posted 9/16/2026full-timeKuala Lumpur • MalaysiaMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing security documentation, conducting risk assessments, and ensuring compliance with industry standards such as ISO 27001 and NIST CSF. Proficient in utilizing security tools like Microsoft Defender and Intune while providing training and support to enhance cybersecurity awareness across the organization.

Highest-signal resume keywords
IT Security Policy ManagementRisk Assessment and ComplianceISO 27001 CertificationMicrosoft 365 Security ToolsSecurity Awareness Training

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentSecurity AuditsCompliance Gap AnalysisEndpoint ProtectionVulnerability ManagementSecurity FrameworksDocumentation Skills
Soft Skills
Strong Communication SkillsTeam Collaboration
Tools & Technologies
Microsoft DefenderSophosBitLockerMicrosoft IntuneAzure AD / Entra ID
Certifications & Qualifications
CISSPCISMCompTIA Security+ISO 27001 Lead ImplementerISO 27001 Auditor
Industry Keywords
Cybersecurity GovernanceData Protection RegulationsGDPRCCPAPDPA SingaporeChina PIPL

Tech Stack

Tools & technologies
AzureCyber Security

About the role

Key responsibilities & impact
  • Own the lifecycle of security documentation, including IT Security Policy, Security Incident Response Procedures, Business Continuity Plan, Disaster Recovery Plan, AI Policy oversight, and related documents
  • Keep security frameworks current, aligned with evolving threats, and compliant with industry standards and regional privacy regulations
  • Maintain, update, and upgrade security systems including Microsoft Defender, Sophos, BitLocker, and Microsoft Intune
  • Lead obtaining and maintaining security certifications such as ISO 27001, SOC 2, and Cyber Essentials
  • Coordinate with external auditors, prepare certification documentation, and drive remediation of identified gaps
  • Respond to client security questionnaires, RFPs, and due diligence requests
  • Research and recommend cost-effective security tools and controls
  • Manage annual information security risk assessments across Microsoft 365, endpoint infrastructure, and third-party integrations
  • Coordinate internal and external audits, track findings, and drive remediation plans
  • Design, develop, and deliver annual security awareness training, including phishing simulations and policy refreshers through HAcademy
  • Monitor vulnerability alerts from vendor advisories, threat intelligence feeds, and endpoint protection tools
  • Assess threats, coordinate patches or mitigations with the IT team, and escalate incidents according to procedures
  • Research, evaluate, and recommend security solutions; manage cybersecurity vendors and tool integrations
  • Contribute to procurement decisions with the Regional IT Director and maintain vendor relationships
  • Provide backup IT support and infrastructure functions, including endpoint troubleshooting, user support escalations, Microsoft 365 administration, and infrastructure tasks
  • Train and advise the wider IT team on cybersecurity best practices
  • Provide ad hoc end-user support and infrastructure assistance to ensure reliable IT operations

Requirements

What you’ll need
  • Bachelor’s degree or above in Information Security, Computer Science, Information Technology, or a related field from a reputable university
  • At least 4 years of experience in IT security, cybersecurity governance, or a related information security role
  • Solid understanding of security frameworks and standards (e.g., ISO 27001, NIST CSF, CIS Controls)
  • Experience conducting risk assessments, security audits, and compliance gap analyses
  • Familiarity with Microsoft 365 security and compliance tools (Microsoft Defender for Office 365, Azure AD / Entra ID, Intune)
  • Experience responding to client security questionnaires and RFPs in a professional services or agency context
  • Knowledge of endpoint protection solutions and vulnerability management practices
  • Understanding of data protection regulations across key operating regions (e.g., GPDR, CCPA, PDPA Singapore, China PIPL, etc.)
  • Strong documentation and communication skills in English
  • Proficiency in another language such as Chinese would be an advantage due to support of users in China
  • Relevant certifications are a plus: CISSP, CISM, CompTIA Security+, ISO 27001 Lead Implementer/Auditor, or equivalent
  • Preference for candidates with existing rights to work in Malaysia

Benefits

Comp & perks
  • A competitive salary
  • Benefits package
  • Career advancement opportunities
  • Four-week sabbatical after four years
  • Hybrid work arrangement