Role Summary
Responsible for establishing and enforcing IT security, compliance, and governance standards across the company. This role will focus on strengthening endpoint security, access control, and IT operational policies to support a growing multi-store environment and protect the organization against security risks.
Key Responsibilities:
- Develop, implement, and enforce IT security policies and governance frameworks to ensure compliance and risk mitigation.
- Set up and manage identity and access management systems (e.g., Active Directory) to control user access securely.
- Ensure all employees comply with IT asset policies (e.g., mandatory use of company-issued laptops, VPN, and endpoint protection).
- Lead and manage IT support operations for both head office and stores, ensuring SLA adherence and high service quality.
- Establish and maintain IT SOPs for onboarding/offboarding, device management, and incident handling.
- Conduct periodic IT audits and security assessments to identify vulnerabilities and strengthen controls.
- Oversee network and endpoint security, ensuring proper patch management and protection against external and internal threats.
- Build and maintain disaster recovery and business continuity plans.
- Mentor and manage the IT support and security team to deliver reliable, compliant, and secure IT services.
Requirements:
- Minimum 5 years of experience in IT infrastructure, security, and support, with at least 2 years in a managerial role.
- Strong expertise in IT security, governance, and compliance (ISO 27001 or similar is a plus).
- Hands-on experience with identity and access management systems such as Active Directory.
- Proficient in endpoint management, device provisioning, and IT asset lifecycle management.
- Familiar with networking, VPNs, and zero-trust security practices.
- Experience building IT SOPs, SLAs, and compliance frameworks.
- Strong leadership, problem-solving, and communication skills.
Preferred Qualifications:
- Experience in retail or F&B multi-branch environments.
- Familiarity with cloud security and hybrid infrastructure.
- Background in implementing security compliance for regulated environments.