
DEPT · Skopje
Skopje, Zagreb, Split, hybrid DEPT® is a Growth Invention company built to help the world’s most ambitious brands grow faster. Operating at the intersection of...
Skopje, Zagreb, Split, hybrid
DEPT® is a Growth Invention company built to help the world’s most ambitious brands grow faster. Operating at the intersection of
technology and marketing, our 4,000+ specialists deliver growth invention services across Brand & Media, Experience, Commerce,
CRM, and Technology & Data. We’re 50|50 tech and marketing, partner-led, and first to move. Clients include Google, Lufthansa,
Meta, eBay, and OpenAI. We have been certified B Corp and Climate Neutral since 2021.
We are looking for a motivated Associate Information Security Specialist to join our growing security team in Croatia or North
Macedonia. This role is a career-accelerating entry point for an ambitious professional looking to shape themselves under top-tier
mentorship.
You will work alongside our Information Security Officer to support audits, ISMS related operational tasks, and map our
company-wide AI inventory. In the long term, you will transition into a direct-report role under our returning Global Information
Security Officer, stepping up to take continuous support of our dual ISO 27001 and ISO 42001 compliance lifecycles.
and asset onboarding verification.
ISMS.Online, gathering system metrics from departments across the global organization.
metrics.
Day-to-Day Expectations & Execution
documentation, and operational workflows of our ISMS.
questions and proactively pushing clear updates and awareness reminders out to the organization regarding best practices.
experts and internal engineers, assisting them in executing and tracking technical security measures.
documenting timelines, and assisting the broader response team in quick resolution.
playing a proactive role in keeping data security top-of-mind for our clients.
Using ISO frameworks as a clear starting point, you will help identify how the security team can better support their unique
operational workflows.
security stance. You will organize and prepare evidence packages to support internal audits, external audits, and client due
diligence reviews.
reporting materials that give the executive team clear visibility into our security posture and improvement areas.
automate tedious compliance logging and documentation tasks, helping our lean security team work much more efficiently.
WHAT YOU'll BRING
controls).
engineering and product teams to gather asset information.
celebrate all of our successes together!
training, development and certifications.
We are a Growth Invention company built to help the world’s most ambitious brands grow faster. Operating at the intersection of
technology and marketing, we create what is next by pioneering ideas, acting fast, and moving further because standing still just
is not in our DNA.
We are drawn to people who stay curious, move with intent, and never stop inventing. Our culture runs on three values: better
together, relentlessly curious, and get sh*t done. It is how we work, how we grow, and how we make things that matter.
At DEPT®, you will find the freedom to explore, the space to collaborate, and the trust to make a real impact for our clients, for
each other, and for the world we are helping to build.
At DEPT®, we take pride in creating an inclusive workplace where everyone has an equal opportunity to thrive. We actively seek to
recruit, develop, nurture, and retain talented individuals from diverse backgrounds, with varying skills and perspectives.
Not sure you meet all qualifications? Apply, and let us decide! Research shows that women and members of underrepresented groups
tend not to apply for jobs when they think they may not meet every requirement, when in fact they do. We believe in giving
everyone a fair chance to shine.
We also encourage you to reach out to us and discuss any reasonable adjustments we can make to support you throughout the
recruitment process and your time with us.
Want to know more about our dedication to diversity, equity, and inclusion? Check out our efforts here.
Who we are S-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges. We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success. But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day. The role Our Incident Response Technical Leads are a critical part of our Cyber Security division's success. As a Technical Lead, and a subject matter expert, you will deploy your incident response expertise in a senior delivery role across our incident response services. You will work across the full lifecycle of security incidents to help our clients respond and recover, including: * Supporting technical incident response from first contact through to closure: you will be the primary technical resource on response cases, deploying your own expertise, creating tailored strategies for response workstreams, and offering guidance to colleagues on your project team. * Overseeing host- and network-based incident response investigations: including triage, system recovery, technical evidence collection, and forensics, log, malware and root cause analyses. * Technical evidence collection from clients’ environments to prepare for forensic investigations. * Providing containment and recovery advice to Client’s during and after cyber incidents. * Developing and sharing domain expertise: we will support you in growing your cyber expertise, including sharing your expertise with the wider cyber team through internal initiatives and programs. * Occasionally, you may also be required to provide overarching project management support, including coordinating non-technical workstreams, and providing verbal or in-person client updates. * Participating in an on-call rotation with the rest of the global cyber team to provide 24x7x365 client incident coverage. Other features of the role include: * Leadership: As a senior technical lead, you’ll have an opportunity to help lead the rest of the APAC incident response team, act as an escalation point for more junior colleagues, and help ensure work produced by the team meets quality standards. * Variety of casework: no day will be the same. Our team responds to a huge variety of incidents for both public and corporate clients. You will have exposure to both regional and international cyber incidents. * Range of opportunities: you will have opportunities to broaden your security awareness into testing and advisory projects, in addition to deepening your incident response expertise. * Flexible working practices: responding to incidents can be intense, high-pressure work. We are mindful of our team's work/life balance and offer flexible working options to support your wellbeing. We're looking for: * Direct experience working in an Incident Response or Digital Forensics team is strongly preferred, however, candidates with exposure to working with Incident Response teams, or those in roles reflecting aspects of Incident Response will be considered. * Strong domain knowledge across computer systems and networks, including: * Windows systems (e.g. Managing domains services, creating standard build templates, using SCCM, moderate PowerShell capabilities, etc.) * Networking (e.g. managing firewall rules, providing guidance around network segmentation, DNS, etc.) * Virtualisation technologies (e.g. ESXi, Hyper-V, etc.) * Endpoint Detection & Response solutions. * The candidate must be able to demonstrate experience conducting forensic investigations, in particular relating to Windows systems. Additional experience conducting investigations into Linux and MacOS systems is preferred. * Demonstrable understanding of core incident response workstreams, including containment and restoration/recovery is a benefit. * You are comfortable using scripting to solve cyber security problems and ideally be able to demonstrate an interest in doing so, e.g. through your own research projects or prior experience. * A critical and investigative mindset. You should be comfortable solving problems with limited information and guidance, developing proportionate strategies to achieve timely outcomes. * Clear demonstrable knowledge of cyber threat actors, and their tactics, techniques, and procedures. * Strong communication skills. You should be comfortable speaking to people at all levels of an organization, from the board of directors to the technical teams. * It is preferred (but not required) that candidates hold one of the following certifications (or equivalent) GCFE, GCFA, GCIH, GNFA. However, holding any of the following is also beneficial: EnCE, CFSR, CISSP, GREM, CCNA, MCFE, OSCP, Network+ and Security+ * A working proficiency in another language (such as Malay, Tamil, Mandarin, Cantonese, Vietnamese) is also beneficial, although not required. The successful candidate must have permission to work in Malaysia by the start of their employment. OUR BENEFITS We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, including: * 20 days paid holiday each year: in addition to public holidays, as well as 1 additional day of leave for every year you work at S-RM up to a maximum of 5 days. * Flexible working: work a minimum of two days a week in the office and the remainder remotely, choose your hours between 7am and 7pm. * Pension scheme: S-RM contributes to Employees Provident Fund (EPF) in accordance with legislative requirements. * Life Insurance: help someone you love should something happen to you. (Further details coming soon.) * Company-paid private medical and dental insurance. (Further details coming soon.) * Company-paid maternity, paternity and fertility treatment leave. * Employee Assistance Programme: free access to specialist support services, including counselling, as well as an online portal of useful articles, tips and tools. Available 24/7, 365 days a year. The role will be based in our office in Kuala Lumpur. However, we have flexible working arrangements available.
ASSOCIATE (FORENSICS LEAD), INCIDENT RESPONSE APAC Who we are S-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges. We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success. But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day. We’re excited you’re thinking about joining us The role Our Incident Response Associates are a critical part of our Cyber Security division's success. As a Forensics Lead on our Incident Response team, you will deploy your expertise in a delivery role across our various incident response services, with a particular focus on forensic investigations into complex cyber incidents. You will work across the full lifecycle of security incidents to help our clients respond and recover, including: * Supporting technical incident response from first contact through to closure: you will be a technical resource on response cases, deploying your own expertise, creating tailored strategies for response workstreams, and offering guidance to colleagues on your project team. You may also be supported by more senior technical team members where appropriate. Overseeing host- and network-based incident response investigations: including triage, system recovery, technical evidence collection, and forensics, log, malware and root cause analyses.. * Developing and sharing domain expertise: we will support you in growing your cyber expertise, including sharing it with the wider team through internal initiatives and programs. * Participating in an on-call rotation to provide 24x7x365 client incident coverage. Other features of the role include: * Variety of casework: no day will be the same. Our team responds to a huge variety of incidents for both public and corporate clients. * Range of opportunities: you will have opportunities to broaden your security awareness into testing and advisory projects, in addition to deepening your incident response expertise. * Flexible working practices: responding to incidents can be intense, high-pressure work. We are mindful of our team's work/life balance and offer flexible working options to support your wellbeing. We're looking for: * Direct experience working in an Incident Response or Digital Forensics team is strongly preferred, however, candidates with exposure to working with Incident Response teams, or those in roles reflecting aspects of Incident Response will be considered. * A fundamental understanding of computer systems and networks, including: * Windows systems (e.g. Managing domains services, creating standard build templates, using SCCM, moderate PowerShell capabilities, etc.) * Networking (e.g. managing firewall rules, providing guidance around network segmentation, DNS, etc.) * Virtualisation technologies (e.g. ESXi, Hyper-V, etc.) * Endpoint Detection & Response solutions. * The candidate must be able to demonstrate experience conducting forensic investigations, in particular relating to Windows systems. Additional experience conducting investigations into Linux and MacOS systems is preferred. * Demonstrable understanding of core incident response workstreams, including containment and restoration/recovery is a benefit. * A critical and investigative mindset. You should be comfortable solving problems with limited information and guidance, developing proportionate strategies to achieve timely outcomes. * Clear demonstrable knowledge of cyber threat actors, and their tactics, techniques, and procedures. * Strong communication skills. You should be comfortable speaking to people at all levels of an organization, from the board of directors to the technical teams. * It is preferred, but not required, that candidates hold one of the following certifications (or equivalent) GCFE, GCFA, GCIH, GNFA. However, holding any of the following is beneficial: EnCE, CFSR, CISSP, GREM, CCNA, MCFE, OSCP, Network+ and Security+ * A working proficiency in another language (such as Malay, Tamil, Mandarin, Cantonese, Vietnamese) is also beneficial, although not required. The successful candidate must have permission to work in Malaysia by the start of their employment. OUR BENEFITS We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, including: * 20 days paid holiday each year: in addition to public holidays, as well as 1 additional day of leave for every year you work at S-RM up to a maximum of 5 days. * Flexible working: work a minimum of two days a week in the office and the remainder remotely, choose your hours between 7am and 7pm. * Pension scheme: S-RM contributes to Employees Provident Fund (EPF) in accordance with legislative requirements. * Life Insurance: help someone you love should something happen to you. * Company-paid private medical and dental insurance. * Company-paid maternity, paternity and fertility treatment leave. Employee Assistance Programme: free access to specialist support services, including counselling, as well as an online portal of useful articles, tips and tools. Available 24/7, 365 days a yea The role will be based in our office in Kuala Lumpur. However, we have flexible working arrangements available.
About F12: F12 was built by uniting IT consulting firms across Canada with a shared vision: to reduce risk and complexity by crafting technology platforms that empower leaders to focus and thrive. We elevate IT conversations from ingredients to outcomes, delivering fully designed solutions with no bad options. If you’re looking for the fast lane into an IT career or want to supercharge your professional development, you’ve come to the right place. At F12, you’ll collaborate with a diverse team and gain exposure to technology services across countless businesses—building a resume rich with experience and accomplishments. Our mission is to elevate our employees by building and retaining an elite team of IT professionals equipped to deliver unmatched service to Canadian business leaders. We value humble service, continuous improvement, and hard work—and we’re looking for like-minded individuals to join us. The Position: We are seeking a highly skilled Senior Cloud, AI, and Security Architect to lead the design, implementation, and governance of secure, scalable, multi‑cloud environments across Azure and AWS. This role blends deep cloud engineering expertise with advanced security and enterprise networking capabilities. You will partner with the Sr Cloud Solution Architect, Cybersecurity, Data, and AI teams to deliver secure-by-design architecture, modern automation, and resilient platforms that support enterprise-scale applications. This position is ideal for a senior technologist who thrives in complex environments, influences cross‑functional teams, and elevates engineering standards across cloud, AI, data, and network domains. Multi‑Cloud Architecture & Engineering * Design, build, and maintain Azure and AWS infrastructure using compute, networking, storage, serverless, and PaaS services. * Architect multi‑cloud solutions that meet enterprise requirements for scalability, security, governance, and cost efficiency. * Maintain reusable cloud patterns, landing zones, and reference architectures. * Support containerized workloads across AKS, EKS, ECS, Fargate, App Services, and Lambda. * Data Warehouse Migration to Azure and AWS * Infra and Database Migration to Azure and AWS * Microsoft Azure VMware Solution * Optimize workloads for performance, resilience, and cost (FinOps mindset). * Ensure operational readiness, backups, and disaster recovery across both clouds. Infrastructure as Code (IaC) & Automation * Troubleshoot and maintain IaC using CDK, CDKTF, Terraform, and Bicep. * Develop reusable IaC modules, wrappers, and libraries for consistency and compliance. * Enhance automation pipelines for provisioning, configuration management, and policy enforcement. CI/CD & Modern Application Delivery * Maintain CI/CD pipelines using Azure DevOps, GitHub Actions, and AWS Code Pipeline. * Integrate security scanning, compliance checks, and artifact management into release workflows. * Enable cloud-native development patterns and modern application hosting. Cloud Security * Assess, design, implement, and automate security controls across Azure and AWS. * Develop and maintain cloud security patterns, baselines, and policies-as-code. * Review and approve changes with security implications (IAM roles, policies, SGs, etc.). * Serve as the cloud security SME for IaaS, PaaS, and SaaS implementations. * Ensure alignment with regulatory frameworks (CSA CCM, ISO 27001/27017, NIST CSF). Data Security * Implement and manage DSPM tools to monitor sensitive data exposure. * Establish controls for structured/unstructured data across Snowflake, S3, ADLS, data lakes, and warehouses. * Drive adoption of data-centric security practices. * Implement DLP, data classification, encryption, tokenization, and key management. Network Infrastructure & Cloud Networking * Configure, and troubleshoot routers, switches, firewalls, wireless access points, and cloud networks. * Design and support Azure networking (VNet, NSG, routing, hybrid connectivity). * Lead upgrades, migrations, and integration projects. * Monitor network performance, availability, and reliability. * Implement network security measures in coordination with Cybersecurity teams. Operations, Monitoring & Optimization * Implement end-to-end monitoring, logging, and alerting using Azure Monitor, Log Analytics, CloudWatch, and equivalent tools. * Ensure strong observability through metrics, logs, traces, dashboards, and runbooks. * Manage patching, upgrades, and lifecycle governance for cloud and container workloads. Security Compliance & Governance * Lead cybersecurity risk assessments for cloud, AI/ML, and data platforms. * Provide pragmatic security guidance to enable innovation while managing risk. * Support investigations and remediation of security incidents, including AI model compromise or data breaches. * Collaborate with Information Security, Product, and Engineering teams to assess and mitigate risk. * Information Protection and Governance * Identity and Access Management Required Qualifications * 7–10+ years of experience in cloud engineering, security architecture, or related domains. * Hands-on experience with Azure and AWS in production environments. * Hands-on experience with Fortinet and Paolo Alto Firewalls * Strong proficiency with IaC (Terraform, CDK, Bicep). * Expertise in containers and orchestration (AKS, EKS, ECS, Fargate). * Strong scripting skills (PowerShell, Python, Bash). * Deep knowledge of cloud networking, identity, and security principles. * Experience with CI/CD pipelines and automation frameworks. * Strong understanding of TCP/IP, DNS, DHCP, VPN, VLANs, routing protocols. * Experience with enterprise network infrastructure (routers, switches, firewalls, wireless). * Familiarity with Ruckus One, Strata Cloud Manager, Palo Alto, and ServiceNow. Preferred Qualifications * Azure certifications: AZ‑104, AZ‑305, AZ‑400. * AWS certifications: Solutions Architect Associate/Professional, DevOps Engineer, Security Specialty. * Security certifications: CISSP, CCSP, CCSK. * Experience in regulated industries (finance, banking, insurance). * Knowledge of DSPM tools, DLP, and data governance frameworks. * Familiarity with Snowflake, Databricks, Redshift, Synapse. Core Competencies * Strong analytical and problem-solving skills. * Ability to work autonomously and drive cloud services end-to-end. * Excellent communication and cross-team collaboration skills. * Customer-focused mindset with a passion for enabling high-performing engineering teams. * Ability to mentor junior team members and elevate engineering standards. * Demonstrated ability to influence senior leadership and drive security-first decision-making. * Passion for DevSecOps, MLSecOps, and staying ahead of emerging AI threats. What You Can Expect from Us: We are proud of our forward-thinking, dynamic culture that champions diversity, inclusivity, and a respectful working environment. We also want to make sure that however you get IT done in all parts of your life, we’ve got your back. Our comprehensive total rewards program includes: * Work-Life & Growth: Three weeks vacation plus extra Flex Days, leadership development opportunities, growth coaching, and reimbursements for educational advancement and certifications. * Health & Financial Well-Being: Health Spending Account or RRSP matching, extended health care, dental and vision coverage, disability and life insurance, and an employee assistance program. * Additional Perks: Tuition reimbursement, paid time off, on-site parking, high-class office amenities, and company events. Our Equal Opportunity Commitment: * F12.net practices as an equal opportunity employer in all services locations. We are committed to building and maintaining a workforce diverse in experience, skills and knowledge. The company maintains a strict policy to ensure equal employment opportunities and do not discriminate based on any grounds and elements protected by law. For those requiring assistance with disabilities, information relating to accommodation and accommodation measures will be addressed confidentially. Please notify us in advance if any accommodation needs are required. The above statements are intended to describe the general nature and level of work performed by people assigned to this job classification. They are not intended to be an exhaustive list of all responsibilities and duties required of people assigned to this job classification.