IT SECURITY & INFRASTURCTURE ENGINEER

Duties & Responsibilities

1. Team Support & Technical Escalation

  • Act as the primary technical escalation point for complex infrastructure, security, and network incidents.
  • Oversee the diagnosis, troubleshooting, and resolution of hardware, software, and network problems, including budgetary control, problem resolution, and information security.
  • Ensure proper documentation of issues, solutions, and system changes in the ticketing system.
  • Coordinate system updates, patches, and new technology deployments across the organisation.
  • Administer disaster recovery plans and ensure the organisation remains functional in adverse scenarios.
  • Determine the rationale and methods for upgrading company network software with each vendor release.
  • Maintain a comprehensive understanding of network architecture and client/server technology.
  • Monitor system performance and analyse recurring issues to prevent future incidents.
  • Track and report on KPIs such as response times, ticket closure rates, and resolution metrics.
  • Coordinate team task schedules and provide regular updates to the IT Manager.

2. Infrastructure & System Administration

  • Install, configure, maintain, and support all IT hardware, infrastructure, network equipment, and related services.
  • Oversee server and workstation maintenance, patching, monitoring, and administration.
  • Administer virtualisation platforms, including VMware and equivalent technologies.
  • Manage Microsoft Active Directory, clustering technologies, and SAN/NAS storage subsystems.
  • Administer SQL databases, including backup, recovery, maintenance, and performance monitoring.
  • Support retail hardware, including POS devices across the outlet network.
  • Review system diagnostics regularly and assess the functionality and efficiency of all IT systems.
  • Evaluate and implement system and network software upgrades aligned with business needs and vendor releases.

3. Cloud Infrastructure – AWS & GCP

  • Own and administer AWS and GCP environments, including IAM, compute, storage, networking, and security services across both platforms.
  • Deploy and govern AWS security services, including GuardDuty, Security Hub, CloudTrail, Config, Inspector, and WAF.
  • Manage GCP Security Command Center, Cloud IAM, VPC, firewall rules, and AWS administration.
  • Provision all cloud resources via Terraform IaC and maintain infrastructure-as-code for all cloud environments.
  • Monitor cloud costs across both platforms, set budget alerts, and optimise spending monthly.
  • Own cloud disaster recovery, including multi-region failover design, RTO/RPO targets, backup scheduling, and quarterly restore testing.
  • Deliver monthly cloud health and cost reports.

4. Security Management & Cybersecurity

  • Monitor all servers, networks, cloud environments, and endpoints for security issues and suspicious activity.
  • Investigate security breaches and cybersecurity incidents within two hours and maintain a structured incident response log.
  • Design and maintain Trend Micro Vision One playbooks to automate threat response and reduce MTTR.
  • Conduct regular vulnerability scans, track and remediate findings within agreed SLAs, and produce monthly reports for the IT Manager.
  • Perform penetration testing to proactively identify and address system weaknesses, and document findings and remediation.
  • Apply CIS/NIST hardening baselines to all operating systems, servers, and cloud infrastructure.
  • Develop and enforce company-wide IT security best practices across all platforms.
  • Work with the security team to perform tests, uncover network vulnerabilities, and fix detected issues promptly.

5. Firewall & Network Security Administration

  • Administer all firewall platforms, including Palo Alto PAN-OS, Fortinet FortiGate, SonicWall, and Cisco Meraki.
  • Manage and maintain firewall policies, review logs daily, and conduct quarterly rule reviews and clean-up with formal reporting.
  • Manage VPN and remote access, including user provisioning, access reviews, and security configuration.
  • Administer LAN/WAN infrastructure, including the configuration of VLANs, switches, and routers, and optimise network performance.
  • Ensure information security compliance and enforce best practices across all network operations.

6. Business Continuity & Disaster Recovery

  • Administer and test disaster recovery plans to ensure organisational continuity under adverse conditions.
  • Maintain backup, restoration, and recovery procedures for all critical systems and infrastructure.
  • Co-lead DR drills, coordinate execution, conduct quarterly recovery testing, and update DR runbooks based on findings.

7. Lark Platform, Bot Development & Automation

  • Own Lark user administration, DLP policies, backup, data retention, and quarterly security hardening audits.
  • Design and build Lark Bots for infrastructure monitoring alerts, security incident notifications, and IT approval workflows.
  • Write Python scripts for security automation, webhook triggers, and bot backend logic.
  • Build and maintain a centralised monitoring dashboard covering server health, network status, firewalls, and cloud environments.

8. Process Management, Vendor & Reporting

  • Develop and maintain IT support procedures, documentation, and knowledge base articles.
  • Identify areas for process improvement and implement strategies to enhance operational efficiency.
  • Collaborate with IT leadership to design and enforce IT policies and security protocols.
  • Develop positive vendor relationships, escalate and resolve advanced issues, and ensure service continuity and SLA compliance.
  • Monitor emerging network and security technologies and deliver quarterly technology updates to the IT Manager and leadership.
  • Ensure compliance with organisational standards and applicable regulatory requirements.

Job Requirements


•Minimum 2 years hands-on experience in IT infrastructure, security, or network engineering
•Working knowledge of AWS or GCP — IAM, compute, networking, and security services
•Experience administering firewall platforms — Palo Alto, Fortinet, SonicWALL, or Cisco Meraki
•Hands-on experience with Windows Server 2019 and above — patching, monitoring, administration
•Proficiency in virtualisation technologies such as VMware or equivalent
•Experience with Microsoft Active Directory, clustering, and SAN/NAS storage
•Familiarity with SQL database backup, recovery, and maintenance
•Experience with network administration — VLAN, VPN, LAN/WAN architecture
•Strong analytical and troubleshooting skills
•Excellent communication and ability to document procedures clearly Good to Have
•Experience managing both AWS and GCP cloud platforms
•Hands-on Terraform or CloudFormation (IaC) experience
•TrendMicro Vision One or comparable EDR/XDR platform experience
•Lark platform administration experience
•Python or scripting for automation or bot development
•Experience supporting retail hardware (POS devices)
•Penetration testing or vulnerability assessment experience
•CIS or NIST hardening framework knowledge
•Experience in a retail, F&B, or multi-site operational environment
•Comprehensive understanding of network architecture and client/server technology

  Min. Education:  Degree

  Industry:  Retail / Wholesale Trading / Property

  Spoken Language:  Malay, English

  Written Language:  Malay, English