- Location
- Penang, MY, Malaysia
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Bachelor
- Source
- Workday
Description
Job Summary
Enovix is seeking a highly experienced Staff IT, Cybersecurity & Operational Technology (OT) to strengthen the security of our enterprise IT systems, manufacturing environments, applications, infrastructure, and data.
This is a senior-level, hands-on technical role responsible for assessing cyber risk, designing and implementing security controls, monitoring threats, investigating incidents, and improving security across both Information Technology and Operational Technology environments. The successful candidate will work closely with IT, engineering, manufacturing, facilities, products, legal, and business teams to ensure that security is incorporated into system design, deployment, and ongoing operations.
The ideal candidate combines strong technical engineering capabilities with analytical judgment and understands how to scale security practices within a growing, global organization.
Key Responsibilities
Security Engineering and Architecture
Conduct security architecture reviews and provide risk-based guidance across enterprise IT, cloud, application, network, manufacturing, and OT initiatives. Define security requirements and technical controls based on system criticality and business risk. Partner with IT, engineering, and manufacturing teams to embed security across the technology lifecycle. Design and maintain controls protecting confidentiality, integrity, and availability. Evaluate and help deploy security tools. Review network architecture for segmentation, access control, remote access, and resilience. Advise on IAM, endpoint, network, cloud, data protection, and vulnerability management.
IT and OT Security
Assess security posture across corporate IT and manufacturing OT (ICS, production networks, connected equipment, engineering workstations). Identify gaps and coordinate remediation with system owners. Develop controls suited to manufacturing constraints (safety, availability, production continuity). Support IT/OT segmentation, asset visibility, privileged access, and monitoring. Review changes to manufacturing systems for cyber and operational risk. Work with vendors and internal teams on production system security. Maintain familiarity with the Purdue Model, NIST SP 800-82, and ISA/IEC 62443.
Security Monitoring and Analysis
Monitor and analyze security events, logs, and threat intelligence to identify incidents. Improve detection logic, dashboards, and escalation procedures. Investigate using SIEM, EDR, network monitoring, identity, and cloud tools. Perform root-cause analysis and control validation. Support threat hunting across IT, cloud, and OT environments.
Vulnerability and Risk Management
Conduct assessments and technical risk analyses across IT and OT. Prioritize findings by exploitability, criticality, and business impact. Drive remediation with system owners and validate outcomes. Support penetration testing and independent assessments. Help develop hardening standards and secure configuration baselines.
Incident Response
Serve as a senior technical member of the IR team across IT, cloud, application, network, and OT incidents. Coordinate triage, containment, eradication, recovery, and evidence collection. Perform root-cause analysis and recommend corrective actions. Maintain and test IR plans, playbooks, and communication workflows. Participate in tabletop exercises and coordinate with stakeholders and external providers during major incidents.
Third-Party and Technology Risk
Review security of third-party technologies, vendors, and manufacturing equipment, including data flows, access, and integration methods. Identify third-party risks and recommend controls. Work with procurement, legal, and business owners to address security requirements before implementation or renewal.
Governance, Compliance, and Documentation
Support compliance programs aligned to NIST, ISO 27001, SOC 2, SOX, and relevant OT standards. Translate requirements into practical controls. Produce clear assessment reports, standards, and operational playbooks. Support audits, customer reviews, and regulatory assessments. Track security metrics and stay current on threats, technologies, and regulations.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or related field, or equivalent experience.
- 6+ years of progressive experience in cybersecurity, security engineering, or security operations.
- Hands-on experience securing enterprise IT (networks, endpoints, servers, applications, identity, cloud).
- Strong grasp of threat models, attack techniques, and defense-in-depth.
- Experience with SIEM, EDR/XDR, network detection, vulnerability management, and log management.
- Experience investigating incidents, including containment and root-cause analysis.
- Strong network security knowledge (firewalls, segmentation, VPNs, DNS, proxies).
- Experience with risk assessments, architecture reviews, and third-party reviews.
- Knowledge of IAM, privileged access, and least privilege principles.
- Familiarity with NIST CSF, ISO 27001, SOC 2, SOX.
- Strong technical writing and stakeholder communication skills.
- Ability to manage multiple priorities with limited supervision.
Preferred Qualifications
- Experience in securing OT/ICS or connected production equipment.
- Knowledge of OT protocols (Modbus, OPC UA, Ethernet/IP, PROFINET, PLCs, HMIs, SCADA).
- Familiarity with ISA/IEC 62443, NIST SP 800-82, Purdue Model.
- Experience with IT/OT segmentation, asset discovery, and OT monitoring.
- Experience with AWS, Azure, or GCP.
- Experience with Microsoft security stack (AD, Entra ID, M365, endpoint management).
- Scripting/automation experience (PowerShell, Python, APIs, SOAR).
- Experience in semiconductor, battery, or advanced manufacturing environments.
- Relevant certification (CISSP, CISM, GIAC, GCIH, GCIA, GICSP, Security+, CCSP, ISA/IEC 62443).
Core Competencies
- Strong analytical and investigative skills; sound risk-based judgment; ability to work independently across IT, engineering, and manufacturing teams; disciplined documentation; ability to lead investigations without direct reports; effective stakeholder influence; clear communication; composure under incident pressure.