About the Role
We are looking for an IT & Security Lead to own all IT operations and information security for our market office.
We consider only candidates with an existing right to work in the country where the role is based. Visa sponsorship is not available for this position.
The role demands equally deep practical expertise in both IT operations and information security.
Responsibilities
Own and operate the full information security control baseline for the market: vulnerability management, endpoint hardening, EDR/XDR, identity security, email and phishing defence, and security awareness
Serve as first responder for security incidents: detection, triage, containment, evidence preservation, escalation, and post-incident review
Own the office network end-to-end: routing and switching, VLAN segmentation, NGFW, IDS/IPS, VPN, Wi-Fi, and ISP relationships
Administer Microsoft 365, Entra ID, and MDM: identity lifecycle, conditional access, MFA, device compliance, and onboarding/offboarding
Serve as the primary IT support contact for the GCC market, owning ticket resolution, endpoint provisioning, and service quality
Manage local vendors, procurement, and the IT asset register across the full lifecycle
Operate IT and security controls required by the market's financial regulator and data protection law, and maintain audit-ready evidence
Lead a small local IT team and/or managed-service partners; drive local IT projects and office expansions
Report security posture, risks, and remediation progress to the Head of Cloud & Operations / CCO and the global Security function
Requirements
6–8+ years of progressive IT operations experience, including 2–3 years as the primary IT decision-maker for a site or market
Hands-on information security experience weighted equally with operations: EDR, vulnerability and patch management, hardening baselines, email and phishing defence, security log and alert triage
Incident response experience as a responder: detection, triage, containment, evidence preservation, escalation, and post-incident review
Hands-on network engineering and security: routing and switching, VLAN design, NGFW administration (Fortinet, Palo Alto, Cisco, or equivalent), IDS/IPS, site-to-site and remote-access VPN, Wi-Fi controller deployments
Strong Microsoft 365 and Entra ID administration: identity lifecycle, conditional access, MFA, Exchange Online, SharePoint, Intune/MDM
Endpoint management and hardening across Windows and macOS: imaging, patch cadence, disk encryption, EDR agents, configuration baselines
Practical experience with a recognised security control framework (ISO 27001, SOC 2, NIST CSF, or CIS Controls) and producing control evidence for audit
Experience in a regulated environment — financial services, fintech, banking, or insurance — with direct exposure to audit and compliance
People leadership experience: direct reports, contractors, or managed-service teams
Professional working proficiency in English plus the primary business language of the market
Preferred
Security certifications: CompTIA Security+, CySA+, GCIH, ISO 27001 Lead Implementer, CISSP, or CISM
Networking certifications: CCNA/CCNP, CompTIA Network+, or Fortinet NSE
Microsoft certifications: SC-200, SC-300, MD-102, MS-102, or AZ-104
SIEM/SOAR experience: Microsoft Sentinel, Splunk, or Elastic
Familiarity with local financial regulatory frameworks (BNM RMiT, MAS TRM, HKMA TM-G-1, or equivalent) and applicable data protection law
Cloud administration and security at an operations level: AWS or GCP
Scripting for automation: PowerShell, Bash, or Python
Experience standing up an office and its security baseline from scratch as the first IT hire in a market