- Location
- Kuala Lumpur - Corporate, Malaysia · Manila - Six/NEO
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Legal
- Experience
- 6+ years
- Education
- Master
- Source
- Workday
Description
Company:
Marsh RiskDescription:
We are seeking a talented individual to join our Information Technology team, part of our risk business at Marsh. This role will be based in Kuala Lumpur, Malaysia. This is a hybrid role that has a requirement of working at least three days a week in the office.
You will support our regional IT Operations team in maintaining and enhancing our cybersecurity and operational security posture across the Asia-Pacific region. This role encompasses vulnerability management, IT operational controls compliance, risk assessment, and security metric reporting to our CISO team. You will work closely with business teams, IT compliance colleagues, and stakeholders across multiple time zones to deliver on critical security and compliance initiatives.
We will count on you to:
Monitor and coordinate vulnerability management activities (DAST, SAST, Pen testing, infrastructure scans, SSL certificates and protocola) and support remediation tracking to meet SLAs
Monitor and manage IT operational controls compliance including user access reviews, service account management, multi-factor authentication rollout, password policy compliance, and risk management.
Support disaster recovery planning and execution, including annual DR plan reviews and database restore testing
Coordinate with vendors and business stakeholders on security requirements, third-party risk assessments, and incident response audit findings
Prepare weekly security metrics reporting and monthly operating reports for regional leadership and the CISO team
What you need to have:
Approximately 6+ years of experience in IT compliance, controls, cybersecurity, or a related field with exposure to security tools and concepts
Strong project management and administrative skills with the ability to prioritise workload and manage multiple stakeholders independently
Demonstrated attention to detail and commitment to meeting SLAs and compliance requirements; ability to learn and grow in cyber security domain
What makes you stand out?
Experience with cyber security concepts, vulnerability scanning tools (SNYK, GitGuardian, Edgescan, Bitsight), and security platforms (SIEM, IAM, MFA, DARE)
Ability to work across time zones and collaborate effectively with regional and global security teams
Demonstrated ability to lead or assist with small security-focused projects and contribute to global security posture initiatives
Why join our team:
We help you be your best through professional development opportunities, interesting work and supportive leaders.
We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.
Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.