Home › Companies › Hoffmanagency › IT Manager, APAC
IT Manager, APAC
Hoffmanagency · Kuala Lumpur, 50250, Malaysia · Active · BambooHR
Job facts
| Field | Value |
|---|---|
| Company | Hoffmanagency |
| Title | IT Manager, APAC |
| Normalized title | - |
| Department / team | IT |
| Location | Kuala Lumpur |
| Work model | - |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | BambooHR |
| Posted / first seen | 2026-05-18 / 2026-05-30 |
| Changed / last seen | 2026-05-30 / 2026-06-18 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Hoffmanagency. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through BambooHR. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Kuala Lumpur. | Open |
| Department jobs | Active postings in IT. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Hoffmanagency |
| Source | e86c06e9-fee9-4bae-838d-3040ddb0e358 |
| ATS provider | BambooHR |
Description
You have a passion to lead
Your drive to inspire and guide sets you apart. You thrive on taking responsibility, tackling challenges head-on, and turning obstacles into opportunities. Working closely with a diverse, talented team to deliver innovative solutions energizes you, and you find genuine satisfaction in helping clients achieve their goals.
We’re in search of dynamic IT talent who not only excel in a fast-paced, collaborative environment but also bring creativity, strategic insight, and a good sense of humour to every challenge. If you’re ready to empower internal clients, and drive transformative change, we want to hear from you!
If you like where this story is leading, read on.
The Plot Thickens: Job Description
Security governance and policy management: You will own the lifecycle of our security documentation—regularly reviewing and updating the IT Security Policy, Security Incident Response Procedures, Business Continuity Plan (BCP), Disaster Recovery Plan (DRP), AI Policy oversight, and related documents. You will ensure these frameworks remain current, aligned with evolving threats, and compliant with industry standards and regional regulations such as PDPA and related privacy laws. You will also be responsible for the maintenance, upkeep, and upgrades of security systems, including Microsoft Defender, Symantec, BitLocker, and Microsoft Intune.
Compliance and certifications: You will lead the effort in obtaining and maintaining security-related certifications (e.g., ISO 27001, SOC 2, Cyber Essentials) that strengthen our credibility with clients and partners. This includes coordinating with external auditors, preparing documentation, and driving remediation of any gaps identified during the certification process.
Client security questionnaires and RFP responses: You will serve as the go-to person for responding to client security questionnaires, RFPs, and due diligence requests. By researching and recommending cost-effective security tools and controls, you will ensure our environment meets the requirements our clients expect—without overengineering solutions.
Risk assessment and audit: You will initiate and manage annual information security risk assessments, identifying vulnerabilities across our Microsoft 365 environment, endpoint infrastructure, and third-party integrations. You will coordinate internal and external audits, track findings, and drive remediation plans through to completion.
Security awareness training: You will design, develop, and deliver an annual security awareness training programme for all staff, including on our learning platform – HAcademy. From phishing simulations to policy refreshers, you will foster a security-conscious culture that empowers every team member to be a line of defence.
Vulnerability monitoring and incident response: You will continuously monitor security vulnerability alerts from sources such as vendor advisories, threat intelligence feeds, and our endpoint protection tools. When threats emerge, you will assess their impact, coordinate with the IT team to apply patches or mitigations and escalate per the Incident Response Procedures when necessary.
Security tooling, vendor evaluation, and cybersecurity management: You will research, evaluate, and recommend cost-effective security solutions that address gaps in our environment while meeting client and regulatory requirements. This includes managing cybersecurity vendors and overseeing the integration of security tools into the broader IT ecosystem. You will also contribute to procurement decisions in collaboration with the Regional IT Director and maintain strong vendor relationships to ensure optimal performance and value.
IT support and infrastructure backup: While your primary focus is cybersecurity, you will also serve as a backup for IT support and infrastructure functions. This includes assisting with endpoint troubleshooting, user support escalations, Microsoft 365 administration, and infrastructure tasks during peak periods or when colleagues are unavailable.
Hosting of company website and related resources: You act as both a trainer and advisor to the wider IT team, providing guidance on cybersecurity best practices and key security considerations. In addition, you provide ad hoc support across end-user support and infrastructure needs, stepping in as required to ensure smooth and reliable IT operations.
Attributes of the Protagonist (That’s You)
Detail-oriented and methodical in approach
Team player – your success is my success!
Ownership mindset and accountability
Proactive and vigilant – you spot risks before they become incidents
Passionate about cybersecurity and continuous learning
Strong communicator who can translate technical concepts for non-technical audiences
Resourceful problem-solver with a cost-conscious mindset
Adaptable and willing to step outside your core function when the team needs you
The Hero’s Background: Qualifications
Bachelor’s degree or above in Information Security, Computer Science, Information Technology, or a related field from a reputable university
At least 4 years of experience in IT security, cybersecurity governance, or a related information security role
Solid understanding of security frameworks and standards (e.g., ISO 27001, NIST CSF, CIS Controls)
Experience conducting risk assessments, security audits, and compliance gap analyses
Familiarity with Microsoft 365 security and compliance tools (Microsoft Defender for Office 365, Azure AD / Entra ID, Intune)
Experience responding to client security questionnaires and RFPs in a professional services or agency context
Knowledge of endpoint protection solutions and vulnerability management practices
Understanding of data protection regulations across key operating regions (e.g., GPDR, CCPA, PDPA Singapore, China PIPL, etc.)
Strong documentation and communication skills in English; proficiency in another language such as Chinese would be an advantage due to support of users in China
Relevant certifications are a plus: CISSP, CISM, CompTIA Security+, ISO 27001 Lead Implementer/Auditor, or equivalent
Come join us and be at the forefront of marketing and communications, and work with industry-leading tech brands. We value diverse thinking, inclusion in decision making and embrace ideas that push the boundaries.
We welcome applications from candidates based in Malaysia , with preference given to those who have existing rights to work in country. Should you have any reasonable accommodations, please feel free to indicate in your application to us.
A competitive salary, benefits package and career advancement opportunities will be offered to the successful candidate. We also offer our staff a four-week sabbatical after four years.
We will contact all shortlisted candidates from [email protected] (our HR system).
About Us
We're an integrated communications consultancy that specializes in solving hard problems — the tougher, the better — for tech companies. Headquartered in Silicon Valley, we’ve established a global infrastructure tuned for the tech industry. Toward this end, we operate offices in Boston, Beijing, Hong Kong, Jakarta, Kuala Lumpur, London, Munich, Paris, Portland, San Jose, Seoul, Shanghai, Singapore, Shenzhen, Taipei and Tokyo.
We’re a company that values diversity and inclusion. We’re proud to be an equal opportunity employer. We welcome applications from all individuals irrespective of race, ethnicity, national origin, gender, gender identity, sexual orientation, age, religion, disability status, veteran status or any other characteristic.
For more information, visit https://www.hoffman.com/ and https://www.apac.hoffman.com/ .
Full job record
| Job ID | acac5dd09b59ba6192999610019912c7f5d566e3 |
| Org ID | 5f41286f-c247-479f-bbba-29f693c80047 |
| Source ID | e86c06e9-fee9-4bae-838d-3040ddb0e358 |
| Board ID | e86c06e9-fee9-4bae-838d-3040ddb0e358 |
| Provider | bamboohr |
| Provider Job Key | 269 |
| Title | IT Manager, APAC |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Kuala Lumpur, 50250, Malaysia |
| Department | IT |
| Team | — |
| Employment Type | full_time |
| Workplace Type | — |
| Remote Policy | — |
| Country | — |
| Region | — |
| City | Kuala Lumpur |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://hoffmanagency.bamboohr.com/careers/269 |
| Apply URL | https://hoffmanagency.bamboohr.com/careers/269 |
| First Seen At | 2026-05-30 06:09:47Z |
| Last Seen At | 2026-06-18 10:38:13Z |
| Last Checked At | 2026-06-18 10:38:13Z |
| Last Changed At | 2026-05-30 06:09:47Z |
| Inactive At | — |
| Source Posted At | 2026-05-18 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=bamboohr/board=hoffmanagency/date=2026-06-18/2026-06-18T10-38-10-213Z-1bffcbdb4119b9fded0cf859a721397133e5637457da51a1d6f1c00d93ffbd19.json |
Event Fields
{
"content_hash": "82eae06e1e7a37180c6cb65f0520afa3a921e8973c7ba18ba9e070aa0549ac78",
"source_hash": "3dc89929340b24cf495a2551d8a070398d6af34324bc6b35458e72fc6f0b09a5",
"last_changed_at": "2026-05-30T06:09:47.818Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Kuala Lumpur, 50250, Malaysia",
"city": "Kuala Lumpur",
"region": null,
"country": null,
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-18T10:38:13.575Z",
"launch_scope": {
"reason": "bamboohr_production_catalog",
"included": true,
"location": {
"raw": "Kuala Lumpur, 50250, Malaysia",
"city": "Kuala Lumpur",
"region": null,
"country": null,
"is_remote": false,
"confidence": 0.8
},
"countries": []
},
"remote_policy": null,
"salary_period": null,
"workplace_type": null,
"salary_currency": null
}Extensions
{}Native Structured
{
"list_job": {
"id": "269",
"isRemote": null,
"location": {
"city": "Kuala Lumpur",
"state": null
},
"atsLocation": {
"city": null,
"state": null,
"country": null,
"province": null
},
"departmentId": "19555",
"locationType": "2",
"jobOpeningName": "IT Manager, APAC",
"departmentLabel": "IT",
"employmentStatusLabel": "Regular-Full Time"
},
"detail_errors": [],
"detail_job_opening": {
"location": {
"city": "Kuala Lumpur",
"state": null,
"postalCode": "50250",
"addressCountry": "Malaysia"
},
"datePosted": "2026-05-18",
"atsLocation": {
"city": null,
"state": null,
"country": null,
"countryId": null
},
"description": "<p><span style=\"font-weight: bold\">You have a passion to lead</span> </p>\n<p>Your drive to inspire and guide sets you apart. You thrive on taking responsibility, tackling challenges head-on, and turning obstacles into opportunities. Working closely with a diverse, talented team to deliver innovative solutions energizes you, and you find genuine satisfaction in helping clients achieve their goals. </p>\n<p> </p>\n<p>We’re in search of dynamic IT talent who not only excel in a fast-paced, collaborative environment but also bring creativity, strategic insight, and a good sense of humour to every challenge. If you’re ready to empower internal clients, and drive transformative change, we want to hear from you! </p>\n<p> </p>\n<p>If you like where this story is leading, read on. </p>\n<p> </p>\n<p><span style=\"font-weight: bold\">The Plot Thickens: Job Description</span> </p>\n<ul>\n<li><span style=\"font-weight: bold\">Security governance and policy management: </span>You will own the lifecycle of our security documentation—regularly reviewing and updating the IT Security Policy, Security Incident Response Procedures, Business Continuity Plan (BCP), Disaster Recovery Plan (DRP), AI Policy oversight, and related documents. You will ensure these frameworks remain current, aligned with evolving threats, and compliant with industry standards and regional regulations such as PDPA and related privacy laws. You will also be responsible for the maintenance, upkeep, and upgrades of security systems, including Microsoft Defender, Symantec, BitLocker, and Microsoft Intune.</li>\n</ul>\n<ul>\n<li><span style=\"font-weight: bold\">Compliance and certifications: </span>You will lead the effort in obtaining and maintaining security-related certifications (e.g., ISO 27001, SOC 2, Cyber Essentials) that strengthen our credibility with clients and partners. This includes coordinating with external auditors, preparing documentation, and driving remediation of any gaps identified during the certification process.</li>\n</ul>\n<ul>\n<li><span style=\"font-weight: bold\">Client security questionnaires and RFP responses: </span>You will serve as the go-to person for responding to client security questionnaires, RFPs, and due diligence requests. By researching and recommending cost-effective security tools and controls, you will ensure our environment meets the requirements our clients expect—without overengineering solutions.</li>\n</ul>\n<ul>\n<li><span style=\"font-weight: bold\">Risk assessment and audit: </span>You will initiate and manage annual information security risk assessments, identifying vulnerabilities across our Microsoft 365 environment, endpoint infrastructure, and third-party integrations. You will coordinate internal and external audits, track findings, and drive remediation plans through to completion.</li>\n</ul>\n<ul>\n<li><span style=\"font-weight: bold\">Security awareness training: </span>You will design, develop, and deliver an annual security awareness training programme for all staff, including on our learning platform – HAcademy. From phishing simulations to policy refreshers, you will foster a security-conscious culture that empowers every team member to be a line of defence.</li>\n</ul>\n<ul>\n<li><span style=\"font-weight: bold\">Vulnerability monitoring and incident response: </span>You will continuously monitor security vulnerability alerts from sources such as vendor advisories, threat intelligence feeds, and our endpoint protection tools. When threats emerge, you will assess their impact, coordinate with the IT team to apply patches or mitigations and escalate per the Incident Response Procedures when necessary.</li>\n</ul>\n<ul>\n<li><span style=\"font-weight: bold\">Security tooling, vendor evaluation, and cybersecurity management: </span>You will research, evaluate, and recommend cost-effective security solutions that address gaps in our environment while meeting client and regulatory requirements. This includes managing cybersecurity vendors and overseeing the integration of security tools into the broader IT ecosystem. You will also contribute to procurement decisions in collaboration with the Regional IT Director and maintain strong vendor relationships to ensure optimal performance and value.</li>\n<li><span style=\"font-weight: bold\">IT support and infrastructure backup: </span>While your primary focus is cybersecurity, you will also serve as a backup for IT support and infrastructure functions. This includes assisting with endpoint troubleshooting, user support escalations, Microsoft 365 administration, and infrastructure tasks during peak periods or when colleagues are unavailable.</li>\n<li><span style=\"font-weight: bold\">Hosting of company website and related resources:</span> You act as both a trainer and advisor to the wider IT team, providing guidance on cybersecurity best practices and key security considerations. In addition, you provide ad hoc support across end-user support and infrastructure needs, stepping in as required to ensure smooth and reliable IT operations.</li>\n</ul>\n<p> </p>\n<p><span style=\"font-weight: bold\">Attributes of the Protagonist (That’s You)</span> </p>\n<ul>\n<li>Detail-oriented and methodical in approach</li>\n</ul>\n<ul>\n<li>Team player – your success is my success!</li>\n</ul>\n<ul>\n<li>Ownership mindset and accountability</li>\n</ul>\n<ul>\n<li>Proactive and vigilant – you spot risks before they become incidents</li>\n</ul>\n<ul>\n<li>Passionate about cybersecurity and continuous learning</li>\n</ul>\n<ul>\n<li>Strong communicator who can translate technical concepts for non-technical audiences</li>\n</ul>\n<ul>\n<li>Resourceful problem-solver with a cost-conscious mindset</li>\n</ul>\n<ul>\n<li>Adaptable and willing to step outside your core function when the team needs you</li>\n</ul>\n<p> </p>\n<p><span style=\"font-weight: bold\">The Hero’s Background: Qualifications</span> </p>\n<ul>\n<li>Bachelor’s degree or above in Information Security, Computer Science, Information Technology, or a related field from a reputable university</li>\n</ul>\n<ul>\n<li>At least 4 years of experience in IT security, cybersecurity governance, or a related information security role</li>\n</ul>\n<ul>\n<li>Solid understanding of security frameworks and standards (e.g., ISO 27001, NIST CSF, CIS Controls)</li>\n</ul>\n<ul>\n<li>Experience conducting risk assessments, security audits, and compliance gap analyses</li>\n</ul>\n<ul>\n<li>Familiarity with Microsoft 365 security and compliance tools (Microsoft Defender for Office 365, Azure AD / Entra ID, Intune)</li>\n</ul>\n<ul>\n<li>Experience responding to client security questionnaires and RFPs in a professional services or agency context</li>\n</ul>\n<ul>\n<li>Knowledge of endpoint protection solutions and vulnerability management practices</li>\n</ul>\n<ul>\n<li>Understanding of data protection regulations across key operating regions (e.g., GPDR, CCPA, PDPA Singapore, China PIPL, etc.)</li>\n<li>Strong documentation and communication skills in English; proficiency in another language such as Chinese would be an advantage due to support of users in China</li>\n<li>Relevant certifications are a plus: CISSP, CISM, CompTIA Security+, ISO 27001 Lead Implementer/Auditor, or equivalent</li>\n</ul>\n<p> </p>\n<p>Come join us and be at the forefront of marketing and communications, and work with industry-leading tech brands. We value diverse thinking, inclusion in decision making and embrace ideas that push the boundaries. </p>\n<p> </p>\n<p>We welcome applications from candidates based in <span style=\"font-weight: bold\">Malaysia</span>, with preference given to those who <span style=\"font-weight: bold\">have existing rights </span>to work in country. Should you have any reasonable accommodations, please feel free to indicate in your application to us.</p>\n<p> </p>\n<p>A competitive salary, benefits package and career advancement opportunities will be offered to the successful candidate. We also offer our staff a four-week sabbatical after four years. </p>\n<p> </p>\n<p>We will contact all shortlisted candidates from <a href=\"mailto:[email protected]\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: bold\">[email protected] </span></a>(our HR system). </p>\n<p> </p>\n<p><span style=\"font-weight: bold\">About Us </span></p>\n<p>We're an integrated communications consultancy that specializes in solving hard problems — the tougher, the better — for tech companies. Headquartered in Silicon Valley, we’ve established a global infrastructure tuned for the tech industry. Toward this end, we operate offices in Boston, Beijing, Hong Kong, Jakarta, Kuala Lumpur, London, Munich, Paris, Portland, San Jose, Seoul, Shanghai, Singapore, Shenzhen, Taipei and Tokyo.</p>\n<p> </p>\n<p>We’re a company that values diversity and inclusion. We’re proud to be an equal opportunity employer. We welcome applications from all individuals irrespective of race, ethnicity, national origin, gender, gender identity, sexual orientation, age, religion, disability status, veteran status or any other characteristic. </p>\n<p> </p>\n<p>For more information, visit <a href=\"https://www.hoffman.com/\" target=\"_blank\" rel=\"noopener noreferrer\">https://www.hoffman.com/</a> and <a href=\"https://www.apac.hoffman.com/\" target=\"_blank\" rel=\"noopener noreferrer\">https://www.apac.hoffman.com/</a>.</p>",
"compensation": null,
"departmentId": "19555",
"locationType": "2",
"seekPromoted": false,
"jobCategoryId": "18457",
"jobOpeningName": "IT Manager, APAC",
"departmentLabel": "IT",
"jobOpeningStatus": "Open",
"minimumExperience": "Experienced",
"jobOpeningShareUrl": "https://hoffmanagency.bamboohr.com/careers/269",
"employmentStatusLabel": "Regular-Full Time"
}
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/acac5dd09b59ba6192999610019912c7f5d566e3?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/5f41286f-c247-479f-bbba-29f693c80047JSONGET https://api.bluedoor.sh/job-postings/v1/sources/e86c06e9-fee9-4bae-838d-3040ddb0e358JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/acac5dd09b59ba6192999610019912c7f5d566e3/eventsJSON