Overall, this position's main responsibility is for managing & development of our Cyber Security posture, focusing on technological control. Technical hands-on is needed & must understand about cloud technologies stack
Key ResponsibilitiesList key responsibilities of this position that are required daily.
- Monitor & continuously evaluate current technical configuration in our cyber security controls such as WAF and Endpoint Security, etc in order to effectively prevent & detect the cyber threats
- Create / Assisting OKR / KPI setting for cyber security team
- Be primary point of contact for cyber security incident management
- Technically develop our SIEM to proactively detect & identify incoming threats
- Technically develop DLP (Data Leakages Prevention) strategy & execution
- Project Management for cyber security team (Ensuring timeline & good deliverables)
- Work closely with information security governance team related SOP’s / Policies development to ensure our security posture meet their key results
- Assisting the implementation of ISO 27001 program (Retaining certification & culture maturity fit)
- Drive strategy & Organization development for cyber security team to help CIS department in achieving their goals
- Should have vast experience minimum 4 years in relevant field (IT Security / SOC Engineer / Information Security / DevSecOps
- Understanding in ISO 27001 security control & risk management concept
- Hands-on / experience with SIEM (Security Incident Event Monitoring) technologies
- Hands-on / experience Device Fingerprint Technologies, Fraud Detection System (Plus point)
- Hands-on / experience with database query (Plus point)
- Have a strong analytical skill with good communication and interpersonal skills
- Nice to have certifications: CISSP / CISM / CISA / CCSP / CCSK / AWS Cloud Security / CEH / CND (Plus point)
- Hands-on / experience in penetration testing (Black, White, Grey box) process & tooling
- Hands-on / experience in Web Application Firewall & Endpoint Security Technologies
- Skills in office tools (excel, presentation, visio or cloud document utility tools)
Skills Required
- Minimum 4 years experience in IT Security / SOC / Information Security / DevSecOps
- Hands-on experience with SIEM (Security Incident Event Monitoring) technologies
- Hands-on experience with Web Application Firewall (WAF) and Endpoint Security technologies
- Understanding of ISO 27001 security controls and risk management concepts
- Hands-on experience in penetration testing (black/white/grey box) processes and tooling
- Hands-on experience designing and implementing DLP (Data Loss/Leakage Prevention) strategy
- Experience with device fingerprint technologies and fraud detection systems
- Experience with database querying (SQL)
- Strong analytical, communication, and interpersonal skills
- Familiarity with cloud technologies (cloud security experience, e.g., AWS Cloud Security)
- Nice-to-have certifications: CISSP, CISM, CISA, CCSP, CCSK, AWS Cloud Security, CEH, CND
- Proficiency with office and documentation tools (Excel, presentation tools, Visio or cloud document utilities)
What We Do
Evermos is a connected commerce platform that empowers local brands and underserved communities by providing a distribution network and commerce services containing products that comply with sharia principles. As a one-stop platform, Evermos provides comprehensive services and a reseller network equipped with various training to support reseller success regardless of gender, educational background, geographic location, or income level.






