- Location
- Corporate Office-Kuala Lumpur, Malaysia
- Type
- Full-time
- Department
- Engineering
- Education
- Bachelor
- Source
- Workday
Description
Join DayOne – Shaping the Future of Data Infrastructure
DayOne is a global leader in the development and operation of high-performance data centers. As one of the fastest-growing companies in the industry, we’ve built a robust presence across Asia and Europe — and we’re just getting started.
As we expand into new international markets, we’re looking for talented, driven individuals to join us on this exciting journey. This is more than a job — it’s an opportunity to be a key contributor to our dynamic team and help shape the future of global data infrastructure.
If you're passionate about innovation, technology, and growth, we invite you to be part of DayOne’s next chapter.
Own DayOne's data governance and data loss prevention programme across Microsoft 365 E5 and Netskope SSE — classify enterprise data, drive sensitivity labelling, engineer and maintain DLP controls, and investigate data leaks end to end. This is the primary focus (~70% of the role).
The role also carries broader cybersecurity governance, risk, and compliance duties as part of a small Information Security team.
Key Responsibilities
Primary — Data Governance and Protection
1. Data Discovery and Classification
- Maintain the enterprise data classification framework and data inventory.
- Configure Purview sensitive info types, trainable classifiers, and exact data match.
- Run data estate scans across M365, endpoints, and file shares.
2. Sensitivity Labelling
- Deploy and tune manual and auto-labelling across Exchange, SharePoint, OneDrive, Teams, and endpoints.
- Maintain label taxonomy, scopes, encryption settings, and downgrade rules.
- Drive adoption with business units; track coverage, accuracy, and mis-labelling.
3. DLP Engineering and Maintenance
- Design, deploy, and tune Purview DLP across email, collaboration, endpoints, and browsers.
- Configure Netskope inline and API DLP; align policies with Purview labels.
- Govern cloud app usage: risk scoring, shadow IT discovery, sanctioned/unsanctioned controls.
- Integrate Endpoint DLP with Intune device control (USB, media, printing) and MAM for BYOD.
- Maintain the DLP estate: rule health, policy coverage, agent status, regression testing, false-positive tuning.
- Manage policy lifecycle and documented exceptions; keep configuration and change records current.
4. Leak Monitoring, Investigation, and Remediation
- Monitor DLP, Insider Risk, and Netskope telemetry for data leakage and anomalous data movement.
- Triage and investigate alerts across email, endpoint, cloud, removable media, and printing to closure.
- Proactively identify leak paths — shadow IT, over-shared links, guest access, unmanaged devices, coverage gaps.
- Analyze trends to pinpoint recurring leak sources, high-risk users, and exposed data sets.
- Recommend and implement fixes: policy changes, rule tuning, labelling, access restrictions, app controls, user coaching.
- Run content search and eDiscovery; preserve evidence, escalate confirmed exfiltration per IR runbook with the managed SOC.
Secondary — Cybersecurity GRC
5. Governance and Policy
- Support development, review, and communication of security policies, standards, and procedures.
- Track review cycles, approvals, version control, and publication status.
6. Risk Management
- Maintain the cybersecurity risk register: identification, assessment, treatment, and tracking.
- Facilitate risk assessments for systems, projects, and operational changes; follow up with risk owners.
7. Compliance and Audit Support
- Support ISO 27001, ISO 27701, SOC 2, PCI DSS, PDPA, GDPR, and NIS2 requirements.
- Prepare and organize audit evidence; track findings, non-conformities, and remediation closure.
- Maintain control matrices and cross-framework mapping.
8. Control Monitoring
- Perform periodic checks on access reviews, policy attestations, training completion, exceptions, and vendor compliance.
- Escalate control gaps and overdue actions to relevant stakeholders.
9. Third-Party Risk
- Conduct cybersecurity due diligence for vendors and third parties, focusing on data handling.
- Review security questionnaires and contractual requirements; track findings and remediation.
10. Awareness and Reporting
- Support awareness campaigns, policy communication, and data handling guidance for business users.
- Produce monthly labelling, DLP, and risk metrics; prepare management and committee reporting.
- Maintain accurate governance and compliance records.
Key Deliverables
- Data classification framework and data inventory
- Labelling policies with coverage and accuracy metrics
- Purview and Netskope DLP policy set, configuration baseline, and exception register
- Leakage risk assessments with recommended remediation
- Investigation records, evidence packs, and closure SLA reporting
- Cybersecurity risk register and treatment tracking
- Audit and certification evidence packs
- Compliance dashboards and management reports
- Third-party assessment trackers
- Framework and control mapping documentation
Skills and Qualifications
- Bachelor's degree in Cybersecurity, Information Security, IT, Risk, Audit, or related discipline.
- 3–6 years in data protection, security engineering, or GRC with hands-on DLP work.
- Deep hands-on Microsoft Purview (Information Protection, DLP, Insider Risk, eDiscovery), Defender, and Intune.
- Hands-on Netskope (inline and API DLP, CASB) or comparable SSE platform.
- KQL and PowerShell for investigation and automation.
- Working knowledge of PDPA, GDPR, and NIS2.
- Familiarity with ISO/IEC 27001, ISO/IEC 27701, NIST CSF, SOC 2, or PCI DSS.
- Experience supporting audits or certification activities.
- Clear written and verbal English; able to brief non-technical stakeholders.
- Strong documentation, coordination, and analytical skills.
Preferred Qualifications
- SC-401 (or legacy SC-400), SC-200, Netskope NCCSA/NCCSI, or equivalent.
- ISO/IEC 27001 Lead Implementer, Lead Auditor, or Internal Auditor; CISA or Security+.
- Insider risk programme experience.
- Data Centre, cloud, managed services, or critical infrastructure experience.
Competencies
- Strong ownership and accountability.
- Organised and methodical; manages multiple deadlines.
- Good judgment on governance and compliance matters.
- Engages effectively with technical teams, business users, auditors, and management.
- Balances security requirements with business realities.
DayOne is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
If you're ready to grow with one of the fastest-moving companies in the data center industry, apply now and be part of our global journey.