

Cybersecurity & Compliance Analyst
MixWork Pte. Ltd
- South Jakarta, Indonesia32, 5, RT09/RW05, Jalan Fachrudin, Kampung Bali Kel., Tanah Abang, South Jakarta, DKI Jakarta, IndonesiaSouth JakartaDKI JakartaIndonesiaIndonesia
- IDR 18,000,000.00 - IDR 23,000,000.00 / monthIDR180000002300000018000000MONTH
- Full timeFULL_TIME
Posted 3 hours ago and deadline of application is on 30 Aug
Recruiter was hiring 3 hours ago
2026-08-17T09:38:53.287294+00:002026-08-30T17:00:00+00:00Job Description
Key Responsibilities
SOC Partner Management and Incident Response
- Manage client’s third-party SOC partner relationship: set monitoring requirements, review escalated alerts, challenge the partner's findings where necessary, and ensure SLA compliance.
- Receive and act on escalated security incidents from the SOC partner: direct containment actions, coordinate with affected teams, and produce incident reports for the Head of IT.
- Conduct periodic reviews of the SOC partner's detection coverage and reporting quality; recommend adjustments to monitoring scope and escalation thresholds.
Security Policy Ownership
- Own client’s IT security policy library: review policies at least annually, update them when systems or regulatory obligations change, and obtain sign-off from the Head of IT.
- Conduct ISO 27001 gap assessments against client’s current security controls; track findings, assign remediation owners, and monitor closure.
- Support SaaS and vendor security assessments: review new tools for data handling risks and provide a structured go / no-go recommendation to the Head of IT before onboarding.
Security Awareness and Phishing Programme
- Design, schedule, and deliver client’s annual security awareness training programme for all staff; maintain training records.
- Plan and execute biannual phishing simulation exercises; measure click-through and submission rates, report outcomes, and run follow-up coaching for high-risk users.
- Produce targeted awareness materials for specific risk areas (e.g. ransomware, social engineering, AI tool misuse) as new threats emerge.
Identity Governance and Data Protection Compliance
- Manage Azure RBAC and Privileged Identity Management (PIM): conduct quarterly access reviews, enforce just-in-time admin activation, and remediate over-privileged accounts.
- Configure and maintain Conditional Access policies in Azure Entra ID: MFA enforcement, device compliance requirements, and location-based access controls.
- Manage Microsoft Purview: DLP policies, sensitivity labels, information barriers, and compliance reports relevant to PDPA and UU PDP data handling requirements.
- Support the Head of IT (DPO) with PDPA compliance: maintain the Data Processing Agreement register, assist with DPIAs for new SaaS systems, and support data breach investigation and notification procedures.
Vulnerability Management and Reporting
- Review vulnerability findings surfaced by CrowdStrike Falcon Spotlight across client’s endpoints; prioritise remediation based on risk, and track closure with asset owners.
- Assess client’s current endpoint device estate and produce a recommendation to the Head of IT on Mobile Device Management (MDM) strategy, covering risk exposure, scope of enforcement, and implementation approach for both Singapore and offshore users.
- Produce monthly security posture reports: open vulnerabilities and ageing, incident summary, access review outcomes, and Secure Score trends across Microsoft 365.
Nice to Have
- SC-200 (Microsoft Security Operations Analyst Associate), AZ-500, CISSP, or CISM certification.
- Singapore PDPA compliance experience or equivalent data protection regulatory exposure.
- Experience running phishing simulations with measurable outcomes.
- SaaS or retail environment security assessment experience.
Minimum Qualifications
Required Qualifications & Experience
- Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.
- Minimum 4 years of IT security experience with demonstrated responsibility for security policy, compliance, or security operations oversight.
- Hands-on experience managing or liaising with a third-party SOC or MSSP, including reviewing escalations and challenging vendor output.
- Working knowledge of Microsoft Azure and Microsoft 365 security controls (Entra ID, Purview, Defender for Endpoint, Conditional Access).
- Familiarity with ISO 27001 framework: gap assessment, risk register, and control documentation.
- Good English for written incident reports, policy documentation, and regular communication with the Singapore Head of IT.
Technical Proficiency
Core (must be able to operate on day one)
- Azure Entra ID: Conditional Access policies, PIM, Identity Protection, RBAC access reviews.
- Microsoft Purview: DLP policy configuration, sensitivity labels, compliance manager.
- Microsoft Defender for Endpoint: alert triage and endpoint security concepts; familiarity with MDM integration is an advantage.
- Microsoft 365 security posture: Secure Score interpretation, tenant-level security settings.
- Security policy drafting and review: structured policy documents aligned to ISO 27001 or NIST CSF.
Working Knowledge (enough to review and challenge partner output)
- SIEM concepts: understanding alert logic, detection rules, and escalation thresholds sufficient to hold a SOC partner accountable.
- CrowdStrike Falcon Spotlight: vulnerability prioritisation and remediation tracking.
- Endpoint security concepts: EDR, device compliance baselines, patch management.
Perks and Benefits
Paid Sick Leave
Gym Membership
Transportation Allowances
Medical, Prescription, Dental, or Vision Plans
Other
- Flexible Medical Benefit: Comprehensive healthcare coverage fully inclusive of dental, optical, outpatient care, and wellness treatments to support your overall well-being.
- Daily Allowances: Competitive transportation and meal allowances to support your operational needs.
- Workstation Provisioning: High-performance corporate laptop and necessary technical equipment provided.
- Regional Ecosystem: Access to ongoing global corporate alignment, dedicated HR support, and a stable, creative career trajectory with a premier international brand.
Required Skills
- Network Security
- Information security
Licenses and Certifications
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional
Jobs Summary
- Job Level
- Associate / Supervisor
- Job Category
- IT and Software
- Educational Requirement
- Bachelor's degree graduate
- Office Address
- AXA Tower, Kuningan city, Axa Tower, Jl. Prof. DR. Satrio, RT.14/RW.4, Kuningan, Karet Kuningan, Kecamatan Setiabudi, Kota Jakarta Selatan, Daerah Khusus Ibukota Jakarta 12940, Indonesia
Feel secure when applying: look for the verified icon and always do your research on a company. Avoid and report situations when employers require payment or work without compensation as part of their application process.
About MixWork Pte. Ltd
MixWork is the premier integrated workforce solutions platform that builds and manages high performing, professional remote teams for global brands. With decades of experience in HR and corporate advisory, we provide Employer of Record (EOR), Business Process Outsourcing (BPO), and Talent Sourcing services from our offices in Singapore and Jakarta. Scale rapidly and efficiently while we handle the compliance, payroll, and day-to-day people management that operational excellence requires.