Skip to content

Open nowPosted 75 days ago

Manager, IT Security

Workable (global search)108,016 open roles

Where
Bandar Sunway, Selangor, Malaysia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowManager, IT SecurityWorkable (global search) · Bandar Sunway, Selangor, Malaysia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 75 days ago

Workable (global search) median: 7 days open

The posting

We’re hiring a hands-on IT Security Manager to own product, cloud, and corporate security across Pixlr. You’ll define and run our security program, from policy and risk to AppSec and incident response, while partnering closely with Engineering, IT, Product, Legal, and Operations.

The Job:

1. Security Governance, Risk & Compliance

  • Establish and maintain the security policy stack, aligned with ISO 27001, SOC 2 controls, and applicable privacy regulations (e.g., PDPA, GDPR).
  • Conduct security risk assessments, vendor and third-party reviews, and data classification activities.
  • Support audit readiness through evidence collection, control testing, and maintenance of security control mappings.

2. Application & Product Security

  • Embed security practices within the software development lifecycle, including threat modelling, secure coding standards, and security reviews.
  • Own and operate application security tooling within CI/CD pipelines, including static, dynamic, and dependency analysis.
  • Guide engineering teams on secure design principles, OWASP Top 10, API security, and supply-chain risk considerations.

3. Cloud & Platform Security

  • Implement and operate cloud security controls across AWS environments, including identity management, logging, monitoring, and threat detection services.
  • Define baseline hardening standards, guardrails, and policy-as-code controls for cloud and infrastructure environments.
  • Drive container, serverless, and data protection security practices, including encryption and key management.

4. Detection, Response & Resilience

  • Develop and maintain incident response plans and coordinate security incident handling with Engineering and IT teams.
  • Operate centralised security logging, alerting, and detection capabilities.
  • Maintain business continuity and disaster recovery security requirements, including backup and recovery verification.

5. Access Hygiene & Privacy

  • Enforce identity lifecycle management and access controls across cloud platforms, SaaS systems, and data environments.
  • Partner with Legal and Data teams on privacy impact assessments, data retention practices, and data loss prevention controls.

6. Culture, Enablement & Operations

  • Deliver security awareness and role-based training for engineering, product, and operations teams.
  • Define and track security operational metrics to monitor risk, control coverage, and remediation effectiveness.
  • Balance security requirements with delivery velocity and cost considerations through cross-functional collaboration.

Requirements

The Person:

  • 6–10 years of experience in IT or application security, including ownership of security programmes or AppSec/CloudSec functions.
  • Strong hands-on experience with application security, secure SDLC practices, and vulnerability management.
  • Practical expertise in AWS security services, identity and access management, and cloud security monitoring.
  • Experience with common security tooling, including SAST, DAST, dependency scanning, secret management, and security logging platforms.
  • Solid understanding of security governance frameworks and regulatory principles, including ISO 27001, SOC 2, PDPA, and GDPR.
  • Proven ability to lead incident response activities and communicate security risks clearly to technical and non-technical stakeholders.

Nice-to-Haves

  • Certifications: CISSP, CCSP, AWS Security Specialty, ISO 27001 Lead Implementer/Auditor.
  • Experience with creative/EdTech or high-scale consumer SaaS; exposure to SOC 2/ISO27001 journeys and GRC platforms (e.g., Drata/Vanta).
  • Container/Kubernetes security, serverless security, and SBOM/supply chain practices.

Benefits

  • Annual Leaves- Additional annual leave will be credited to you on a yearly basis.
  • Medical and Insurance Coverages - We have got you covered.
  • Subsidies - Enhancing your well-being, we offer optical and dental subsidies.
  • Opportunities - Above training and guidance, you will have the opportunity to try, to build your confidence and become your best self, and to interact and build a strong relationship.
  • Rocking Diversity- Play hard, work harder with people of diverse skill sets and experiences! Challange yourself to step out of your comfort zone, and you'll find yourself growing in way you'd never imagine.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.