M365 Security, Protection

1 week ago


Kuala Lumpur, Kuala Lumpur, Malaysia ISTITUTO MARANGONI Full time
About the Role The Swift End User Services (EUS) Team is accountable for the strategy, design, delivery and operations of all workplace and workforce productivity and collaboration services. The foundational technologies include Microsoft Windows and M365, with the principal services being (a) end user devices, (b) video and voice services, (c) sharing and collaboration, (d) messaging and directory services, and (e) automation and productivity services.

As we continue to expand our digital footprint and migrate to a Zero Trust Security framework, we are committed to ensuring the highest standards of security, protection, and governance for our Microsoft 365 (M365) environment. We are seeking a highly skilled and experienced professional to lead our M365 Security, Protection & Governance efforts.

The M365 Security, Protection & Governance Lead will be responsible for overseeing the security, compliance, and governance of our Microsoft 365 environment. This role involves developing and implementing strategies to protect data, manage risk, ensure regulatory compliance, and establish governance frameworks. The ideal candidate will have a deep understanding of M365 security technologies, compliance requirements, and best practices for data protection and governance.

The ideal candidate will have a deep understanding of M365 security technologies, compliance requirements, and best practices for data protection and governance.

For reference, Swift's strategic productivity, collaboration and intelligence services are predominantly delivered through M365, but also includes offerings from other vendors. The primary M365 data sources include SharePoint, Teams, Exchange, and One-Drive.

The M365 Security, Protection & Governance (Lead Senior Engineer) will report to the Head, EUS Architecture, Engineering and Security Compliance, and in the interim, to the Head, End User Services.

What to Expect?

Primary Responsibilities

Relationship Management

  • Establish strong relationships with vendors and internal partners (information security & protection, legal, privacy and risk partners) focused toward supporting the ongoing evolution of M365 Information Security, Access, Protection & Governance.

Security Management

  • Develop and implement security policies, procedures, and controls for M365.
  • Monitor and respond to security incidents, vulnerabilities, and threats within the M365 environment.
  • Conduct regular security assessments, audits, and penetration testing in collaboration with information security partners
  • Collaborate with IT and security teams to design and enforce secure configurations.

Data Protection

  • Implement data loss prevention (DLP) strategies and technologies
  • Manage encryption, rights management, and data classification solutions.
  • Ensure proper handling of sensitive and confidential information in accordance with data protection laws and regulations.

Compliance & Governance:

  • Establish and maintain compliance with relevant regulations (e.g., GDPR, HIPAA, CCPA).
  • Develop and enforce governance policies for data retention, archiving, and disposal.
  • Create and maintain documentation for compliance audits and reporting.
  • Conduct regular training and awareness programs on compliance and governance.

Risk Management:

  • Identify, assess, and mitigate risks related to the M365 environment.
  • Develop and maintain a risk management framework for M365.
  • Collaborate with stakeholders to prioritize and address risks effectively.

Collaboration & Leadership

  • Lead cross-functional teams to implement security, protection, and governance initiatives.
  • Provide guidance and mentorship to junior team members.
  • Stay updated on the latest M365 features, security trends, and regulatory changes.

Tactical Priorities

  • Review and refine the efficacy of current information security & protection controls across M365 data sources. Examine M365 controls which encourage and enforce best practices. Identify and implement quick wins / low hanging fruit.
  • Perform M365 Security Risk Assessment in collaboration with information security, legal, privacy and risk partners to identify risks and requisite controls, and implement effective processes and technology solutions to automate security controls and automated governance.

Strategic Objectives

  • Develop an M365 Security, Protection & Governance Roadmap, including the evaluation and implementation of effective processes and technology solutions to automate security controls and governance. Implement a monthly forum to govern the efficacy of security controls and address potential / released risks and issues (supported by data, measures, and analytics)
  • Azure Information Protection (AIP) Support the development of a plan to implement and operate AIP. This should include supporting the implementation of (a) an MVP to protect confidential information, and (b) the minimum configuration to avoid inappropriate sharing of confidential information externally.
  • Information Protection User Education Support the refinement of training material around current policies, considering the evolution of collaboration and intelligence services to (a) reinforce individual responsibility, and (b) equip users with the knowledge to do the right thing in M365. Support the development of a roadmap around access control and data tagging responsibilities for end users of M365 data sources.
  • Zero Trust Security Model Support the M365* implementation of a Zero Trust Security Model at Swift including (a) prevention, detection, and response, (b) associated policy refinements, (c) user education, (d) data classification, (e) data inventory, and (f) controls and governance.
  • Legacy Data Management Support the definition of requirements for handling of legacy M365 data, including the development of timelines to automatically restrict access, conditional archiving / data removal. Implement associated controls in M365 to enforce requirements.

What will make you successful?

  • Bachelor's degree in Computer Science, Information Security, or a related field (Master's degree preferred).
  • Professional certifications such as CISSP, CISM, Microsoft Certified: Security, Compliance, and Identity Fundamentals, or equivalent.
  • 10+ years of experience in information security, with significant experience in managing M365 environments.
  • Proven expertise in M365 security technologies, including Microsoft Defender, Azure AD, Conditional Access, and Information Protection.
  • Strong understanding of data protection laws, regulatory compliance frameworks, and governance best practices.
  • Excellent leadership, strategic thinking, and communication skills.
  • Ability to work effectively with cross-functional teams and manage complex projects.

You may want to reach out to the recruiter for more information via LinkedIn; Victor Ooi , Senior Talent Acquisition.

What we offer

We put you in control of career

We give you a competitive package

We help you perform at your best

We help you make a difference

We give you the freedom to be yourself

We give you the freedom to be yourself. We are creating an environment of unique individuals – like you – with different perspectives on the financial industry and the world. An environment in which everyone's voice counts and where you can reach your full potential regardless of age, background, culture, colour, disability, gender, nationality, race, religion , or veteran/military status.


#J-18808-Ljbffr

  • Kuala Lumpur, Kuala Lumpur, Malaysia Power IT Services Full time

    Qualifications: Need to have a deep understanding and knowledge of Mobility & Security (E.g. MS Defender, MS End Point Manager etc.) and Collaboration Technology (e.g. Exchange, SharePoint, Teams) Core understanding of secure remote working solutions, including cloudbased virtual desktop solutions Digital Workplace security, e.g. data loss prevention,...

  • Security Officer

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Shapadu security Sdn Bhd Full time

    Job descriptionWe are looking for a competent Security Officer to undertake the surveillance of our premises and protection of our staff and visitors. You will be responsible for detecting any suspicious behavior and preventing vandalism, thefts or other criminal behavior.The goal is to help the company in maintaining excellent working conditions by keeping...


  • Kuala Lumpur, Kuala Lumpur, Malaysia HERCULES SECURITY SDN BHD Full time

    Monitor and patrol designated areas to ensure the safety and security of the premises and its occupants. Enforce access control procedures by checking identification, permits, and authorizations of individuals entering the premises.Prevent unauthorized entry and potential security breaches by maintaining a strong physical presence and vigilance.Respond...

  • Security Supervisor

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia EMPIRE EAGLE SECURITY SDN BHD Full time

    Security guard supervisors monitor and oversee the activities of guards who protect properties from vandalism acts and theft. They assign areas to be patrolled by guards on a regular basis, transfer the individual caught trespassing to police custody and develop safety plans and drills for the buildings and employees under their supervision.To be excellent...


  • Kuala Lumpur, Kuala Lumpur, Malaysia JAC Malaysia Full time

    Location: Kuala Lumpur Specialisation:Business Process Outsourcing & Global Business ServiceSalary: MYR16,800 (Daily) Reference: CR/ Contact details: Rebecca Lourdes Job published:March 06, :31Have experience with full administrator access rights in managing Active Directory (Azure/On-prem) and M365 (E3 & E5 License) Support existing backend infrastructure...


  • Kuala Lumpur, Kuala Lumpur, Malaysia SoftwareOne Full time

    Job Function:Field Sales The role:At SoftwareOne we are looking for Sales Professionals that model a positive mindset and remain curious in all activities that they are involved in. Professionals that seek to maintain a joint-venture relationship with our customers, partners and internal support teams. Professionals who have a curious mindset and a hunger...

  • M365 Administrator

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Optimum Solutions (Singapore) Pte Ltd Full time

    Requirements: Minimum 3 years of handson work experience with Mobile Device Management (MD) solutions such as Microsoft Intune, VMware Workspace One (previously known as AirWatch), etc. Extensive background working handson capacity with Microsoft Intune, Teams, OneDrive and/or SharePoint. Exposure to Microsoft 365 technologies spanning across wide range of...

  • SOC Analyst

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia IT Business Solutions Sdn Bhd Full time

    Microsoft M365 E5 Security Scope of Servicesi. End point security for managed devices (E.g. Intune, Defender for end point)iv. Identity and access management.v. Privileged identity and access management. (E.g. Defender for identity)vi. Cloud security. (E.g. Defender for Cloud)vii. Information protection and data loss prevention. (E.g. Purview)viii. M365 data...

  • Solution Architect

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Kloudynet Technologies Sdn. Bhd. Full time

    Responsibilities:Collaborate with clients, stakeholders, and cross functional teams to understand business objectives, technical requirements, and constraints.Design and architect end to end solutions that address complex business challenges and integrate seamlessly with existing systems and infrastructure.Create comprehensive solution blueprints, technical...


  • Kuala Lumpur, Kuala Lumpur, Malaysia JAC Malaysia Full time

    Location: Kuala Lumpur Specialisation:Business Process Outsourcing & Global Business ServiceSalary: MYR 84, ,000 (Annual) Reference:PR/ Contact details: Shuya Looi Job published: March 11, :48Responsibilities: Learn and understand Local IT Infrastructure and security process for affiliate companies. Strong communication skills with HQ Technical Support and...

  • Security Assistant

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Hotel Grand Continental Kuala Lumpur Full time

    a. STAND-IN FOR C.S. OFFICER WHEN HE IS AWAY ON DUTY OR ON LEAVE.b. RESPONSIBLE TO C.S. OFFICER FOR ALL MATTERS PERTAINING TO SECURITY AND ENSURE THAT ALL INSTRUCTIONS ARE PASSED DOWN TO ALL SECURITY PERSONNEL FOR INFORMATION AND NECESSARY ACTIONS.c. STAND-IN FOR N.D. OFFICER WHEN HE IS OFF OR ON LEAVE TO ENSURE THE ENTIRE HOTEL PREMISES AND ITS VICINITY ARE...

  • Security Assistant

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Hotel Grand Continental Kuala Lumpur Full time

    a. STAND-IN FOR C.S. OFFICER WHEN HE IS AWAY ON DUTY OR ON LEAVE.b. RESPONSIBLE TO C.S. OFFICER FOR ALL MATTERS PERTAINING TO SECURITY AND ENSURE THAT ALL INSTRUCTIONS ARE PASSED DOWN TO ALL SECURITY PERSONNEL FOR INFORMATION AND NECESSARY ACTIONS.c. STAND-IN FOR N.D. OFFICER WHEN HE IS OFF OR ON LEAVE TO ENSURE THE ENTIRE HOTEL PREMISES AND ITS VICINITY ARE...

  • Security Analyst

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Prometric Full time

    Key Responsibilities Implement security measures to protect systems, networks and data. Stay uptodate on cybersecurity intelligence, including tools, techniques, and hacker methodologies. Prevent data and/or intellectual property loss and service interruptions by understanding and using technologies and processes that will effectively protect the network....


  • Kuala Lumpur, Kuala Lumpur, Malaysia Park Hyatt Kuala Lumpur Full time

    SummaryYou will be responsible for the efficient running of the department in line with Hyatt International's Corporate Strategies and brand standards, whilst meeting associate, guest and owner expectations. The Director of Security is responsible to develop, implement, monitor and evaluate the hotel's safety and security procedures, including fire safety,...

  • Patrolling Officer

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia SAIFORCE SECURITY SERVICES SDN BHD Full time

    Security managers ensure security for people, such as customers and employees, and company assets either fixed, movable, machines, vehicles, and real state. A They ensure safety and security by enforcing security policies, keeping track of different events, implementing security protocols, creating emergency response procedures, conducting security...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Michael Page Full time

    About Our Client Banking SHared Service Centre that designs and builds enterprise softwares. Job DescriptionNetwork Security product Web Application Firewall, Endpoint Detection and Response, Network IPS, Network APT, NAC.Provide day-to-day operation support for any network security request/incident/hands-on/enhancement.Responsible for the...

  • Security Officer

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Hotel Grand Continental Kuala Lumpur Full time

    a. STAND-IN FOR C.S. OFFICER WHEN HE IS AWAY ON DUTY OR ON LEAVE.b. RESPONSIBLE TO C.S. OFFICER FOR ALL MATTERS PERTAINING TO SECURITY AND ENSURE THAT ALL INSTRUCTIONS ARE PASSED DOWN TO ALL SECURITY PERSONNEL FOR INFORMATION AND NECESSARY ACTIONS.c. STAND-IN FOR N.D. OFFICER WHEN HE IS OFF OR ON LEAVE TO ENSURE THE ENTIRE HOTEL PREMISES AND ITS VICINITY ARE...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Avows Technologies Sdn Bhd Full time

    1)Provide expert support and resolve complex issues revolving around Microsoft 365 functionalities, including but not limited to: Exchange Online (EXO), SharePoint Online (SPO), Azure Entra ID and Cloud Security configurations.2) Design and develop SharePoint solutions, including custom web parts, workflows, and integrations. Collaborate with stakeholders to...


  • Kuala Lumpur, Kuala Lumpur, Malaysia iPay88 Full time

    Roles & Responsibilities: Assist in monitoring and conduct indepth analysis of security systems and networks to promptly identify and respond to any potential breaches or unauthorised access attempts, ensuring the utmost protection of sensitive data and information. Assist in conducting vulnerability assessments, penetration testing, and analysis of threats,...

  • Marketing Executive

    1 week ago


    Kuala Lumpur, Kuala Lumpur, Malaysia SAIFORCE SECURITY SERVICES SDN BHD Full time

    Marketing assistants support all the efforts and operations carried out by marketing managers and officers. They prepare reports in relation to the marketing operations needed by other departments, especially account and financial divisions. They ensure that resources needed by the managers to perform their job are in place. ÂTo be an excellent total...