mixwork.co

View all job listings

Cybersecurity and Compliance Analyst

Metro Private Limited

Permanent

Hybrid

Rp 20.000.000 - Rp 28.000.000

Job description

About MixWork & Our Client

MixWork is the premier HR outsourcing partner for strategic workforce solutions, empowering brands and global organizations with skilled, dedicated, and professional top-tier regional teams from South East Asia to accelerate their business growth. On behalf of our client, a premier, household-name retail enterprise headquartered in Singapore with a well-established international footprint and a heritage of quality and operational excellence, we are seeking a dedicated professional to join their team as they actively modernize their omni-channel capabilities and leverage a sophisticated regional technology footprint to support their digital and brick-and-mortar operations.


Role Summary

This role is client’s internal security owner for all cybersecurity and compliance matters across the group's Singapore and offshore IT environments. The Cybersecurity & Compliance Analyst manages the client's relationship with the third-party SOC partner, owns security policy and awareness programmes, and supports the Head of IT in his capacity as Data Protection Officer (DPO) under Singapore PDPA and Indonesia UU PDP obligations.


This is not a SOC analyst role. The candidate may not operate a SIEM console directly. Instead, they set security requirements for the SOC partner, review and challenge what the partner reports, and ensure that security posture improvements land across all client’s systems and environments.


Key Responsibilities

1) SOC Partner Management and Incident Response

  • Manage third-party SOC: monitoring scope, escalated alerts, SLA and coverage.
  • Lead containment, coordinate teams, report to Head of IT.

2) Security Policy Ownership

  • Own IT security policies: annual review, Head of IT sign-off.
  • ISO 27001 gap assessments and remediation; SaaS/vendor go/no-go reviews.

3) Security Awareness and Phishing Programme

  • Annual awareness training and records; biannual phishing simulations, metrics, coaching; emerging-threat materials.

4) Identity Governance and Data Protection Compliance

  • Azure RBAC/PIM quarterly access reviews, JIT admin; Entra ID Conditional Access (MFA, device, location); Purview DLP, labels, barriers.
  • Support Head of IT (DPO) on PDPA/UU PDP: DPA register, DPIAs, breaches.

5) Vulnerability Management and Reporting

  • Close CrowdStrike Falcon Spotlight findings by risk; recommend MDM strategy for SG/offshore users.
  • Monthly report: vulnerability ageing, incidents, access reviews, M365 Secure Score.

Job requirements

Required Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.
  • Minimum 4 years of IT security experience with demonstrated responsibility for security policy, compliance, or security operations oversight.
  • Hands-on experience managing or liaising with a third-party SOC or MSSP, including reviewing escalations and challenging vendor output.
  • Working knowledge of Microsoft Azure and Microsoft 365 security controls (Entra ID, Purview, Defender for Endpoint, Conditional Access).
  • Familiarity with ISO 27001 framework: gap assessment, risk register, and control documentation.
  • Good English for written incident reports, policy documentation, and regular communication with the Singapore Head of IT.


Technical Proficiency

a. Core (must be able to operate on day one)

  • Azure Entra ID: Conditional Access policies, PIM, Identity Protection, RBAC access reviews.
  • Microsoft Purview: DLP policy configuration, sensitivity labels, compliance manager.
  • Microsoft Defender for Endpoint: alert triage and endpoint security concepts; familiarity with MDM integration is an advantage.
  • Microsoft 365 security posture: Secure Score interpretation, tenant-level security settings.
  • Security policy drafting and review: structured policy documents aligned to ISO 27001 or NIST CSF.


b. Working Knowledge (enough to review and challenge partner output)

  • SIEM concepts: understanding alert logic, detection rules, and escalation thresholds sufficient to hold a SOC partner accountable.
  • CrowdStrike Falcon Spotlight: vulnerability prioritisation and remediation tracking.
  • Endpoint security concepts: EDR, device compliance baselines, patch management.


Nice to Have

  • SC-200 (Microsoft Security Operations Analyst Associate), AZ-500, CISSP, or CISM certification.
  • Singapore PDPA compliance experience or equivalent data protection regulatory exposure.
  • Experience running phishing simulations with measurable outcomes.
  • SaaS or retail environment security assessment experience.

Benefits

Statutory Provisions & Compliance

  • Full Legal Compliance: Official employment contract managed under MixWork Indonesia, ensuring complete adherence to local labor laws and employment standards.
  • Healthcare & Social Security: Full registration and contributions for both BPJS Kesehatan and BPJS Ketenagakerjaan to ensure comprehensive coverage.
  • Religious Holiday Allowance: Guaranteed annual mandatory Religious Holiday Allowance (THR) paid in accordance with statutory government regulations.


What We Offer

  • Flexible Medical Benefit: Comprehensive healthcare coverage fully inclusive of dental, optical, outpatient care, and wellness treatments to support your overall well-being.
  • Daily Allowances: Competitive transportation and meal allowances to support your operational needs.
  • Workstation Provisioning: High-performance corporate laptop and necessary technical equipment provided.
  • Regional Ecosystem: Access to ongoing global corporate alignment, dedicated HR support, and a stable, creative career trajectory with a premier international brand.


Important Notes

  • Language Requirement: As this is an international role, please note that all screenings and interviews will be conducted exclusively in English.
  • Equal Opportunity Employer: MixWork is committed to creating an inclusive, diverse, and fair workplace culture. We value talent and capability above all else, completely free from discrimination or bias.

Job information

Education

Bachelor Degree (S1)

Experience level

Mid Senior Level

Minimum experience

4 years

Gender

No Qualification

Published date

11 Aug 2026

Powered by

Mekari Talenta