Semua lowongan
Logo MixWork Pte. Ltd

Cybersecurity & Compliance Analyst

MixWork Pte. Ltd

On-siteFull-timeMid LevelTechnology & IT
KOTA ADM. JAKARTA SELATAN16 Ags 2026
Information SecurityNetwork Security
Lamar Sekarang

via KarirHub Kemnaker

✦ Otomatis diisi data lowongan ini

Buat Surat Lamaran

Deskripsi Pekerjaan

Key Responsibilities

SOC Partner Management and Incident Response

  • Manage client’s third-party SOC partner relationship: set monitoring requirements, review escalated alerts, challenge the partner's findings where necessary, and ensure SLA compliance.
  • Receive and act on escalated security incidents from the SOC partner: direct containment actions, coordinate with affected teams, and produce incident reports for the Head of IT.
  • Conduct periodic reviews of the SOC partner's detection coverage and reporting quality; recommend adjustments to monitoring scope and escalation thresholds.

Security Policy Ownership

  • Own client’s IT security policy library: review policies at least annually, update them when systems or regulatory obligations change, and obtain sign-off from the Head of IT.
  • Conduct ISO 27001 gap assessments against client’s current security controls; track findings, assign remediation owners, and monitor closure.
  • Support SaaS and vendor security assessments: review new tools for data handling risks and provide a structured go / no-go recommendation to the Head of IT before onboarding.

Security Awareness and Phishing Programme

  • Design, schedule, and deliver client’s annual security awareness training programme for all staff; maintain training records.
  • Plan and execute biannual phishing simulation exercises; measure click-through and submission rates, report outcomes, and run follow-up coaching for high-risk users.
  • Produce targeted awareness materials for specific risk areas (e.g. ransomware, social engineering, AI tool misuse) as new threats emerge.

Identity Governance and Data Protection Compliance

  • Manage Azure RBAC and Privileged Identity Management (PIM): conduct quarterly access reviews, enforce just-in-time admin activation, and remediate over-privileged accounts.
  • Configure and maintain Conditional Access policies in Azure Entra ID: MFA enforcement, device compliance requirements, and location-based access controls.
  • Manage Microsoft Purview: DLP policies, sensitivity labels, information barriers, and compliance reports relevant to PDPA and UU PDP data handling requirements.
  • Support the Head of IT (DPO) with PDPA compliance: maintain the Data Processing Agreement register, assist with DPIAs for new SaaS systems, and support data breach investigation and notification procedures.

Vulnerability Management and Reporting

  • Review vulnerability findings surfaced by CrowdStrike Falcon Spotlight across client’s endpoints; prioritise remediation based on risk, and track closure with asset owners.
  • Assess client’s current endpoint device estate and produce a recommendation to the Head of IT on Mobile Device Management (MDM) strategy, covering risk exposure, scope of enforcement, and implementation approach for both Singapore and offshore users.
  • Produce monthly security posture reports: open vulnerabilities and ageing, incident summary, access review outcomes, and Secure Score trends across Microsoft 365.

Nice to Have

  • SC-200 (Microsoft Security Operations Analyst Associate), AZ-500, CISSP, or CISM certification.
  • Singapore PDPA compliance experience or equivalent data protection regulatory exposure.
  • Experience running phishing simulations with measurable outcomes.
  • SaaS or retail environment security assessment experience.

Kualifikasi

Required Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.
  • Minimum 4 years of IT security experience with demonstrated responsibility for security policy, compliance, or security operations oversight.
  • Hands-on experience managing or liaising with a third-party SOC or MSSP, including reviewing escalations and challenging vendor output.
  • Working knowledge of Microsoft Azure and Microsoft 365 security controls (Entra ID, Purview, Defender for Endpoint, Conditional Access).
  • Familiarity with ISO 27001 framework: gap assessment, risk register, and control documentation.
  • Good English for written incident reports, policy documentation, and regular communication with the Singapore Head of IT.

Technical Proficiency

Core (must be able to operate on day one)

  • Azure Entra ID: Conditional Access policies, PIM, Identity Protection, RBAC access reviews.
  • Microsoft Purview: DLP policy configuration, sensitivity labels, compliance manager.
  • Microsoft Defender for Endpoint: alert triage and endpoint security concepts; familiarity with MDM integration is an advantage.
  • Microsoft 365 security posture: Secure Score interpretation, tenant-level security settings.
  • Security policy drafting and review: structured policy documents aligned to ISO 27001 or NIST CSF.

Working Knowledge (enough to review and challenge partner output)

  • SIEM concepts: understanding alert logic, detection rules, and escalation thresholds sufficient to hold a SOC partner accountable.
  • CrowdStrike Falcon Spotlight: vulnerability prioritisation and remediation tracking.
  • Endpoint security concepts: EDR, device compliance baselines, patch management.

Kualifikasi

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.
  • Minimum 4 years of IT security experience with demonstrated responsibility for security policy, compliance, or security operations oversight.
  • Hands-on experience managing or liaising with a third-party SOC or MSSP, including reviewing escalations and challenging vendor output.
  • Working knowledge of Microsoft Azure and Microsoft 365 security controls (Entra ID, Purview, Defender for Endpoint, Conditional Access).
  • Familiarity with ISO 27001 framework: gap assessment, risk register, and control documentation.
  • Good English for written incident reports, policy documentation, and regular communication with the Singapore Head of IT.
  • Azure Entra ID: Conditional Access policies, PIM, Identity Protection, RBAC access reviews.
  • Microsoft Purview: DLP policy configuration, sensitivity labels, compliance manager.
  • Microsoft Defender for Endpoint: alert triage and endpoint security concepts; familiarity with MDM integration is an advantage.
  • Microsoft 365 security posture: Secure Score interpretation, tenant-level security settings.
  • Security policy drafting and review: structured policy documents aligned to ISO 27001 or NIST CSF.
  • SIEM concepts: understanding alert logic, detection rules, and escalation thresholds sufficient to hold a SOC partner accountable.
  • CrowdStrike Falcon Spotlight: vulnerability prioritisation and remediation tracking.
  • Endpoint security concepts: EDR, device compliance baselines, patch management.

Skills yang Dibutuhkan

Information SecurityNetwork Security

Lowongan Serupa — Technology & IT

Lowongan Kerja Cybersecurity & Compliance Analyst di MixWork Pte. Ltd — KOTA ADM. JAKARTA SELATAN

Ayo bergabung dengan tim kami di MixWork Pte. Ltd sebagai Cybersecurity & Compliance Analyst! Ini bukan hanya pekerjaan, tapi kesempatan untuk menjadi pahlawan dunia digital di Jakarta Selatan. Dalam peran ini, kamu akan menjadi bagian integral dari tim keamanan kami, menjaga infrastruktur kami dari ancaman siber dan memastikan kepatuhan terhadap standar keamanan tertinggi. Ini adalah peluang yang sempurna bagi mereka yang ingin mengembangkan karir di bidang keamanan siber dan berkontribusi pada keamanan digital perusahaan terkemuka.

MixWork Pte. Ltd adalah perusahaan yang berkomitmen pada inovasi dan keunggulan dalam layanan mereka. Dengan bergabung dengan tim kami, kamu akan bekerja di lingkungan yang mendukung pengembangan profesional dan memberikan kesempatan untuk terlibat dalam proyek-proyek yang menantang dan berdampak nyata. Jika kamu berpikir bahwa kamu punya keahlian dan semangat untuk menjadi bagian dari tim yang menjaga keamanan digital, maka ini adalah posisi yang tepat untukmu.

Detail Posisi

Aspek Detail
Posisi Cybersecurity & Compliance Analyst
Perusahaan MixWork Pte. Ltd
Lokasi KOTA ADM. JAKARTA SELATAN
Status Kerja full-time
Tipe on-site

Tugas dan Tanggung Jawab Harian Sebagai Cybersecurity & Compliance Analyst di MixWork Pte. Ltd

Di MixWork Pte. Ltd, sebagai Cybersecurity & Compliance Analyst, kamu akan memiliki berbagai tanggung jawab yang menantang dan mengasyikkan. Berikut adalah beberapa tugas utama yang kamu akan lakukan:

  • Kerja sama dengan partner SOC dan respons terhadap insiden keamanan adalah bagian penting dari pekerjaan ini. Kamu akan mengelola hubungan dengan partner keamanan ketiga, menangani insiden keamanan yang di-escalate, dan memastikan semua proses sesuai dengan SLA.
  • Selain itu, kamu juga akan mengatur kebijakan keamanan IT, melakukan penilaian keamanan vendor, serta mendesain dan mengeksekusi program kesadaran keamanan dan simulasi phishing.
  • Kamu akan bekerja sama dengan tim internal dan eksternal untuk mengidentifikasi dan mengatasi ancaman keamanan, serta mengembangkan langkah-langkah untuk meningkatkan keamanan infrastruktur kami.
  • Menganalisis data keamanan dan membuat laporan untuk manajemen, serta memberikan rekomendasi untuk meningkatkan keamanan perusahaan.

Kualifikasi yang Dibutuhkan untuk Menjadi Cybersecurity & Compliance Analyst di MixWork Pte. Ltd

Untuk bergabung dengan tim kami, ada beberapa kualifikasi dan pengalaman yang diperlukan. Berikut adalah beberapa syarat utama yang harus kamu miliki:

  • Derajat sarjana di bidang Cybersecurity, Computer Science, atau Information Technology.
  • Minimal 4 tahun pengalaman di bidang keamanan IT, terutama dalam manajemen kebijakan keamanan, kepatuhan, atau pengawasan operasi keamanan.
  • Pengalaman langsung dalam mengelola atau berkolaborasi dengan SOC atau MSSP ketiga.
  • Pengetahuan mengenai kontrol keamanan Microsoft Azure dan Microsoft 365.
  • Familiar dengan framework ISO 27001.
  • Kemampuan berbahasa Inggris yang baik untuk komunikasi tertulis dan berkala dengan Head of IT di Singapura.

Cara Melamar Posisi Cybersecurity & Compliance Analyst di MixWork Pte. Ltd

Jika kamu tertarik dan merasa cocok dengan posisi ini, siapkan CV dan surat lamaranmu dengan baik. Gunakan CV Builder kami untuk membuat CV yang menonjolkan pengalaman dan keahlianmu. Jangan lupa sertakan Surat Lamaran yang memperjelas mengapa kamu adalah pilihan terbaik untuk posisi ini. Kami sarankan untuk mempersiapkan diri dengan baik sebelum mengirimkan lamaranmu.

Disclaimer

Informasi lowongan kerja ini bersumber dari pihak ketiga. SuratPlus tidak berafiliasi langsung dengan perusahaan dan tidak bertanggung jawab atas kesalahan informasi atau kerugian dalam proses rekrutmen. Selalu verifikasi detail lowongan dan jangan berikan informasi bank atau kartu kredit.

Pekerjaan Lainnya oleh MixWork Pte. Ltd

Pekerjaan Lainnya di KOTA ADM. JAKARTA SELATAN