Job Summary
We are seeking a seasoned Security Manager to design, implement, and govern our cybersecurity program across hybrid (cloud and on-premises) environments within our semiconductor manufacturing facility. The ideal candidate will possess deep hands-on expertise in Microsoft security ecosystems (MDE, MDM), SOC operations, SOX IT compliance, and Singapore's regulatory landscape. You will lead a proactive security posture that safeguards critical intellectual property, manufacturing systems, and corporate infrastructure while ensuring audit readiness and continuous compliance.
Key Responsibilities
Hybrid Infrastructure & Cloud Security
- Deploy, tune, and manage Microsoft Defender for Endpoint (MDE) for advanced threat detection, automated response, and threat hunting.
- Oversee enterprise MDM/UEM solutions (Microsoft Intune or equivalent) to enforce security baselines, conditional access, and compliance for corporate, contractor, and BYOD devices.
- Establish endpoint lifecycle security policies aligned with cleanroom and manufacturing floor operational constraints.
SOC Operations & Incident Response
- Direct or coordinate 24/7 SOC activities, including SIEM/SOAR monitoring, alert triage, threat intelligence integration, and incident containment.
- Develop, test, and maintain incident response playbooks tailored to semiconductor operational realities (high availability, IP sensitivity, supply chain dependencies).
- Conduct post-incident reviews, root cause analysis, and continuous improvement of detection engineering and response workflows
SOX Compliance & Audit Readiness
- Design and enforce IT General Controls (ITGCs) supporting Sarbanes-Oxley (SOX) compliance, including access management, change control, backup/recovery, and financial system security.
- Lead internal/external audit preparation, evidence collection, and remediation tracking. Maintain continuous monitoring and SOX compliance dashboards.
- Partner with Finance, Internal Audit, and External Auditors to ensure transparent, repeatable control environments.
Singapore Policy, Governance & Regulatory Compliance
- Develop and maintain information security policies aligned with Singapore's PDPA, Cybersecurity Act, CSA guidelines, and MAS/TRM (where applicable).
- Ensure data residency, cross-border transfer compliance, and sector-specific regulatory reporting requirements are met.
- Conduct compliance gap assessments, risk assessments, and security awareness programs tailored to Singapore operations and global corporate standards.
Semiconductor-Specific Security & Cross-Functional Leadership
- Collaborate with Engineering, OT, and Supply Chain teams to secure EDA tools, MES, PLM, and vendor remote access while maintaining production uptime.
- Manage third-party and cloud vendor security assessments, SLAs, and continuous monitoring.
- Deliver executive reporting on security KPIs, risk posture, compliance status, and strategic roadmap recommendations.
Qualifications & Requirements
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field. . 7+ years of cybersecurity experience, with at least 3 years in a managerial or lead role.
- Proven experience securing hybrid (cloud + on-prem) environments in manufacturing, semiconductor, or critical infrastructure sectors.
- Hands-on expertise with Microsoft security stack: Defender for Endpoint (MDE), Intune/MDM, Microsoft Sentinel, Entra ID, and Purview/Compliance Manager.
- Demonstrated SOC leadership or coordination experience with SIEM/SOAR platforms, threat hunting, and incident response frameworks.
- Strong working knowledge of SOX ITGC requirements, audit methodologies, and control testing/remediation.
- In-depth understanding of Singapore cybersecurity and data protection regulations (PDPA, CSA Cybersecurity Act, IMDA/CSA codes of practice).
- Certifications preferred: CISSP, CISM, CCSP, Microsoft SC-200/SC-300/MD-102, ISO 27001 Lead Implementer/Auditor.
- Excellent stakeholder management, cross-functional communication, and executive reporting skills.
Preferred Skills
- Familiarity with OT/IT convergence security, network micro-segmentation, and semiconductor tooling ecosystems (EDA, MES, SCADA awareness).
- Experience with Infrastructure-as-Code (IaC) security, cloud workload protection platforms (CWPP), and AI-assisted threat detection.
- Background managing security in 24/7 high-availability manufacturing or cleanroom environments.
- Experience building and maturing compliance programs in multi-jurisdictional or global semiconductor operations.
Please note that only shortlisted candidates will be notified.
EA Licence: 26S3307
Reg No: R26160234