Product Security Lead

Shah Alam, Malaysia

Apply now Apply later

About Us

Ideagen is the invisible force behind many things we rely on every day - from keeping airplanes soaring in the sky, to ensuring the food on our tables is safe, to helping doctors and nurses care for the sick.

 

So, when you think of Ideagen, think of it as the silent teammate that's always working behind the scenes to help those people who make our lives safer and better. 

 

Every day millions of people are kept safe using Ideagen software. We have offices all over the world including America, Australia, Malaysia and India with people doing lots of different and exciting jobs. 

 

Ideagen believe that by recruiting diverse and talented individuals, we create an inclusive community for all. We are committed to empowering all colleagues to maximise their potential and express their unique characteristics, experience, and knowledge to achieve their ambitions. 

 

The Product Security Lead is responsible for guiding, implementing, monitoring, and managing security principles and best practices across all the products of the business line, as well as working with the Cyber Security team across the business.This role will be an invaluable addition to Ideagen’s current and growing Cyber Security arsenal, driving change, and a cyber secure work culture.

 

Responsibilities

  • Cultivate security culture with your product technology and business colleagues. Products that have the right security culture will strive to prioritize sustainable controls and driving real risk reduction outcomes. Strong technical expertise in threat modelling is required, secure architecture design review, application security and cloud security principles. Embed the following security fundamentals such as threat modelling, solutions architecture, secure code review into agile product development by empowering technology teams to ship secure products faster that are secure from the start. Requires proactive integration into Product meetings for full understanding, and to set security expectations early in the process.
  • Know your products across their breadth and depth. Be fluent in your business line’s product's strategies and roadmaps as well as its key investment programs. Be aware of how product sits within the overarching strategy, and family portfolio. Identify unfamiliar technology components, capabilities, and business concepts and be self-motivated to learn all about them, applying critical thinking to identify hidden issues along the way. Be a subject matter expert in knowing the cyber risk posture of the entire Products.
  • Be your product's security thought leader. Learn from your product and cybersecurity teams and share best practice in both directions. Be recognized in your product as the clear point of escalation and subject matter expert for IT Risk and Cyber domains. Responsibility for adding to the Risk Register where required and following up on these actions. Main point of contact for sales account managers in reference in specific customer queries around security penetration testing, and able to identify and progress solutions.
  • Act with urgency managing emerging issues. Proactively monitor Key Risk Indicators to ensure issues are identified, quantified, communicated, and managed in a timely manner, including recommendations for resolution, and identifying the root cause/key themes.

 

Skills and Experience

· Experience with cloud technologies in high availability environments.· Reading, interpreting and being able to deliver a business level report of penetration reports.· Willingness to ask questions / question current practices in search of better solutions.· Knowledge and experience of cloud architecture/design, security challenges, and solutions· Strong project management skills for managing multiple products, testing, and reporting.· Experience in Network, Windows, and Linux security.· Basic programming/scripting skills· Strong analytical skills· Strong communication skills· Must be willing to participate in, and be able to pass, a comprehensive background check.· Experience in Vulnerability Management including configuring, running, and analysing scans (Nessus preferred)· Experience in Web Vulnerability Management (OWASP Top 10, CWE Top 25)· Experience in SIEM configuration, analysis, and reporting.· Experience with IPS/IDS and Data Loss Prevention tools, configuration, and analysis.· Experience with threat analysis and reporting.· Must be able to take occasional customer facing calls to discuss customer requirements including customer audits where needed.· Participate in tooling requirements, and fully integrate business lines into any new tooling processes.· Understanding of CVEs, and risk priority

Desirable skills· Community recognised security certificates CEH, CISM, SANS (GSEC, GCIA, GCED, GCIH), CISSP· Exposure to or knowledge of compliance standards such as FedRAMP, ISO 27001, SOC2/3, Cyber Essentials

 

Behavioral

  • Ambitious - Drive, Planning & Execution
  • Adventurous - Flexibility & Resilience and Savvy Thinking
  • Community - Collaboration & Communication

#LI-Hybrid

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0
Category: Leadership Jobs

Tags: Agile Application security Audits CEH CISM CISSP Cloud Compliance FedRAMP GCED GCIA GCIH GSEC IDS IPS ISO 27001 Linux Monitoring Nessus OWASP Pentesting Product security SANS Scripting SIEM SOC 2 Strategy Vulnerability management Windows

Region: Asia/Pacific
Country: Malaysia

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.