Overview

Head Information Technology Security Jobs in Greater Johor Bahru at Aetosky

Title: Head Information Technology Security

Company: Aetosky

Location: Greater Johor Bahru

Company Description

Aetosky develops secure, sovereign intelligence platforms tailored for defense and dual-use institutions to process and act on multi-source intelligence swiftly and effectively. Our mission is to empower national security, intelligence, and strategic agencies with integrated multi-intelligence capabilities for decisive action in critical operations. Designed for air-gapped and sensitive environments, our platforms excel in real-time operations across domains like battlefield intelligence, infrastructure protection, and disaster response. With a focus on innovative solutions, Aetosky helps clients across Asia Pacific and the Gulf achieve confidence and precision through advanced converged intelligence.

Role Description

Aetosky delivers AI-powered intelligence products to government clients across APAC and the Gulf.

The Group IT Operations Lead is a senior, strategy-owning individual contributor responsible for the group-wide IT operations function. This role establishes and enforces the corporate IT posture across all Aetosky entities – covering endpoint management, device policy, access control, security tooling, and compliance. You will own both the strategy and the execution. You define the standards, implement the tooling, and hold the organisation accountable to them. You report directly to the Group COO.

Key Responsibilities

  • 1. IT Policy & Governance
  • Design, author, and own the Group IT Policy framework – covering acceptable use, device standards, access control, data handling, and incident response
  • Ensure policies are jurisdiction-aware across operating entities.
  • Drive policy awareness and adoption across the organisation; create and deliver periodic IT policy communications and onboarding materials.
  • Maintain a policy review cycle (minimum annual) aligned to threat landscape and business changes.

2. Centralised Device Management (Intune / Microsoft Defender)

  • Own and administer Microsoft Intune as the group-wide MDM/MAM solution – covering Windows, macOS, iOS, and Android endpoints.
  • Configure and enforce Microsoft Defender policies: endpoint protection, threat detection, vulnerability management, and compliance baselines.
  • Define and enforce device enrolment standards, configuration profiles, compliance policies, and conditional access rules.
  • Manage corporate device lifecycle: procurement standards, provisioning, patch management, decommissioning.
  • Ensure zero-trust access principles are applied across device and identity layers.

3. IP Audit Log Monitoring

  • Implement and maintain regular IP audit log review processes – covering egress, access events, anomalous behaviour, and unauthorised connections.
  • Define thresholds, alerting rules, and escalation paths for suspicious activity.
  • Produce periodic audit summaries for leadership review.

4. Microsoft Sentinel – SIEM Operations

  • Implement and operate Microsoft Sentinel as the group SIEM – leveraging native integration with Microsoft 365 Business Premium, Defender, and Entra ID.
  • Define log ingestion sources, analytic rules, alert taxonomy, and incident response playbooks.
  • Own ongoing Sentinel operations: rule tuning, alert triage, false-positive reduction, and incident escalation.
  • Produce periodic security posture reports for leadership review, drawing on Sentinel dashboards and Defender telemetry.

5. Access Control & Identity Management

  • Own corporate identity and access management – Microsoft Entra ID (Azure AD), SSO, MFA enforcement, and conditional access policies.
  • Maintain RBAC standards across corporate systems; conduct periodic access reviews and privilege audits.
  • Define and enforce offboarding procedures to ensure timely deprovisioning across all systems.

6. IT Compliance, Audit Readiness & GitLab Governance

  • Maintain documentation, evidence logs, and control registers sufficient for client due diligence and internal audit.
  • Ensure group IT posture meets requirements relevant to government and defense client procurement – including applicable frameworks (ISO 27001 awareness, client-specific IT requirements).
  • Own GitLab access governance – define and enforce role-based access standards, conduct periodic privilege reviews, and ensure timely deprovisioning on offboarding.
  • Review GitLab audit logs regularly — covering privileged access events, repository activity anomalies, and policy violations — and escalate findings where required.
  • Maintain GitLab access records as part of the broader corporate audit trail, available for internal governance reviews.
  • Coordinate with external vendors for annual penetration testing engagements; own scoping, remediation tracking, and compliance certificate outputs.

7. Cross-Functional Coordination

  • Serve as the primary interface between corporate IT and the Platform Engineering team (Security Engineer dotted-line alignment on policy).
  • Coordinate with the Office Manager on endpoint provisioning and IT support handoffs for the Vietnam development center.
  • Support procurement and vendor management for IT tooling – licensing, renewals, and vendor SLAs.

Nice to Have

  • Experience scoping and managing annual enterprise penetration testing engagements with external vendors.
  • Familiarity with producing IT compliance certificates or evidence packs for government/defense client procurement processes.
  • Exposure to export control or data sovereignty requirements relevant to APAC and Gulf defense markets.
  • Familiarity with GitLab audit log review, access governance, and developer toolchain security posture.

Requirements

Experience

  • 6+ years in IT operations, IT security, or systems administration roles with increasing scope.
  • Demonstrated hands-on experience with Microsoft Intune and Microsoft Defender – configuration, policy enforcement, and ongoing operations.
  • Hands-on experience with Microsoft Sentinel – log ingestion, analytic rule authoring, incident management.
  • Track record of designing and enforcing IT policy in a multi-entity or multi-country environment.
  • Experience working in or directly supporting government, defense, or enterprise technology environments preferred.

Technical Skills

  • Microsoft 365 / Azure / Entra ID — administration and security configuration
  • Intune MDM/MAM — enrolment, compliance policies, conditional access, app protection
  • Microsoft Defender for Endpoint — policy configuration, threat management, reporting
  • Microsoft Sentinel — log ingestion, analytic rules, incident response, dashboard reporting
  • Network fundamentals — IP audit logs, egress monitoring, VPN, access control lists
  • Endpoint security — patch management, vulnerability scanning, hardening baselines

Attributes

  • Operates as a strategic owner, not a ticket-taker — comfortable defining the roadmap and executing it independently.
  • High attention to documentation and audit trail discipline; understands that in defense/government contexts, undocumented controls do not exist.
  • Clear communicator — able to translate technical IT risk into leadership-level language.
  • Commercially aware — understands how IT posture affects client procurement and enterprise sales.

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.