Security Governance, Risk and Compliance Lead

2 weeks ago


Kuala Lumpur, Kuala Lumpur, Malaysia Clarks Full time
Security Governance, Risk and Compliance Lead

Clarks Federal Territory of Kuala Lumpur, Malaysia

The Security Governance, Risk and Compliance Lead is responsible for the development and operation of security and IT risk and compliance management activities within Clarks. Working with stakeholders around the business, the role will maintain effective controls to ensure Clarks meets global privacy, financial, and other compliance requirements. A central member of the security team, the role will lead on key control areas such as policy development and review and third-party assurance whilst supporting operational audit and compliance assessments (e.g. PCI DSS, SWIFT, internal and external audits). The role will also assist the Head of Security and IT Risk Management in maintaining the overall IT risk register and in regular risk and security metrics collection, interpretation, and reporting.

Responsibilities

  • Develop, maintain and embed policies relating to core security risk areas, enhanced with standards, guidance, and other supporting documentation where necessary.
  • Design, operate and maintain Clarks' security third-party security assessment framework, utilizing existing toolsets and integrating into buying and procurement processes to ensure a risk-based approach is taken with key security risks being identified and accepted by relevant business areas as necessary.
  • Work with colleagues from Procurement, Sourcing, Operations, Legal, and other areas to ensure appropriate security requirements are embedded within overall procurement frameworks and that appropriate agreements and processes are in place to support this.
  • Work with IT assurance, Finance (including Risk and Internal Audit), and other colleagues to support internal and external reviews of Clarks IT general control and security control environments, sourcing evidence, reviewing output, and making recommendations.
  • Operate assessment programmes for critical security compliance requirements, including PCI DSS and SWIFT. Engage with Technology, business, and project teams where necessary as a subject matter expert in these areas. Monitor compliance landscape to identify emerging requirements that could affect Clarks' business operations.
  • Assist in the support and maintenance of the IT Risk Register, recording and assessing new risks raised from all areas of the business, reviewing existing risks, and using judgement, experience, and relevant industry knowledge to recommend proposed activity to mitigate or remediate risks.
  • Support training and awareness activities relating to security, privacy, and other related areas, assisting in developing relevant tools and materials to embed key messages.
  • Act as an advocate for security across business areas, responding to queries, building relationships, and proactively identifying opportunities to improve Clarks' security posture through affecting change and driving good security behaviours.
  • Assist in the development of relevant management information, metrics, and performance indicators in relation to IT risk management, third-party assurance, compliance, and other security areas.
  • Support the Head of Security, other team members, and senior stakeholders in other tasks and activities commensurate with the profile of the role as necessary.
  • Delivery of effective security policy and related artifacts.
  • Completion of appropriate third-party security assessment activities.
  • Security risks recorded and accepted appropriately.
  • Compliance programmes operating effectively.
  • Functional and security risk metrics designed, delivered, and reported on.

Qualifications

  • Fundamental understanding of privacy and data protection laws and regulations and how they apply to technology environments globally (e.g. GDPR, PIPL, etc.).
  • Understanding of core security concepts and areas: network security, identity and access management, cloud security, cryptography/PKI, data protection, secure code development, threat and vulnerability management, etc.
  • Likely to hold at least one common security certification (CISMP, CISSP, CISA, CISM, etc.) alongside other relevant IT certifications (ITIL, AMP, Prince2, etc.).
  • Experience in large, multinational retail, distribution, or manufacturing organizations and of working with enterprise resource planning systems beneficial.
  • Able to work independently and pivot focus to work on a varied portfolio, blending design of core processes with bespoke review and reactive assessment activities.
  • A passion for advocating effective security practice across the enterprise and inspiring others to embed effective security risk management practices into business processes.
  • Strong interpersonal and collaboration skills enabling the ability to comfortably communicate with key stakeholders, including senior business leaders, product owners, project managers, and business analysts.
  • Effective communication skills with the ability to present, discuss, and distil abstract risk management and security concepts for consumption by peers, leaders, and other stakeholders.
  • Capable of producing detailed and accurate technical documentation as necessary using common tools (e.g. PowerPoint, Visio, project tools, etc.).
  • Ability to coach, mentor, and guide peers and more junior members of the team.
  • Extensive experience within information security management, consultancy, risk management, or audit roles.
  • Familiarity with common security and risk management standards and frameworks: ISO 27001/27002, PCI DSS, NIST, COBIT, etc. and of aligning and assessing organizational alignment to these.
  • Experience of operating third-party security assessment processes would be beneficial.
Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Information Technology

Industries

Retail and Computer and Network Security

#J-18808-Ljbffr

  • Kuala Lumpur, Kuala Lumpur, Malaysia Petron group Full time

    About the RoleWe are seeking an exceptional individual to lead our Information Security Governance, Risk Management, and Compliance (GRC) programs. This is an exciting opportunity to join a rapidly evolving Asian oil company and contribute to its growth.Key Responsibilities:Develop and implement information security policies, procedures, and guidelines.Lead...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Boost Full time

    Information Security Governance, Risk and Compliance, Asst. ManagerBoost WP. Kuala Lumpur, Federal Territory of Kuala Lumpur, MalaysiaResponsibilities:Information Security GovernanceAccountable for the regular review of IT governance, processes and control mechanisms to ensure its relevancy with the business practices, risk management and compliance...

  • IT Governance, Risk

    7 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Petron Malaysia Refining & Marketing Bhd Full time

    IT Governance, Risk & Compliance Analyst"At Petron, we are not just in the business of oil, we are also in the business of fueling lives."Petron Malaysia is an emerging and rapidly evolving Asian oil company. It is part of Petron Corporation which is the leading oil company in the Philippines. Our integrated refining, distribution, and retailing of...

  • IT Governance, Risk

    3 weeks ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Petron Malaysia Full time

    "At Petron, we are not just in the business of oil, we are also in the business of fueling lives."Petron Malaysia is an emerging and rapidly evolving Asian oil company. It is part of Petron Corporation which is the leading oil company in the Philippines. Our integrated refining, distribution, and retailing of world-class petroleum products help meet the...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Link Compliance Full time

    About Link ComplianceWe are a leading provider of digital meeting solutions designed to streamline governance processes for boards and executive teams.Our platform offers secure, paperless meeting management tools that enhance collaboration, improve decision-making efficiency, and ensure compliance.


  • Kuala Lumpur, Kuala Lumpur, Malaysia GREAT EASTERN Full time

    Job DescriptionThis Technology Risk and Compliance Lead position is responsible for managing technology-related risks and ensuring compliance with regulatory requirements. The successful candidate will have a strong background in risk management, IT governance, and compliance.The ideal candidate will be able to develop and implement effective risk management...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Life and Careers Full time

    Job Summary:We are seeking a Compliance and Governance Professional to join our team at Standard Chartered Life and Careers. As a key member of our Compliance and Governance function, you will play a crucial role in ensuring the bank's compliance with relevant laws and regulations.The ideal candidate will have a strong background in financial services, with...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Mizuho Bank (Malaysia) Berhad Full time

    Risk Analysis and Governance LeadMizuho Bank (Malaysia) Berhad is seeking a highly skilled Risk Analysis and Governance Lead to join our team. In this role, you will be responsible for analyzing and assessing risks across various business units, identifying areas for improvement, and implementing effective governance structures.Key Responsibilities:Analyze...


  • Kuala Lumpur, Kuala Lumpur, Malaysia GREAT EASTERN Full time

    About Us">GREAT EASTERN is a leading insurer in Asia, with over a century of experience serving customers in Singapore and Malaysia. Our commitment to excellence and customer satisfaction has earned us a reputation as a trusted brand.">Job Overview">We are seeking a skilled professional to join our Risk Management team as an IT Risk Governance Lead. In this...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Boost Full time

    IT Security Governance DirectorWe are seeking an experienced IT Security Governance Director to join our team at Boost. In this role, you will be responsible for leading the platform security incident response process, ensuring timely and effective resolution of security incidents and breaches, and coordinating with internal and external teams to contain,...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Zurich 56 Company Ltd Full time

    Job Description">We are seeking a highly skilled Global Information Security Governance Specialist to join our team in Singapore or Malaysia.The successful candidate will be responsible for supporting information security governance initiatives and activities across APAC business units, maintaining the regional Information Security, Risk and Compliance...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Dentsu Aegis Network Full time

    Company OverviewDentsu Aegis Network is a global network designed for what's next, helping clients predict and plan for disruptive future opportunities and create new paths to growth in the sustainable economy.We take a people-centered approach to business transformation, using insights to connect brand, content, commerce, and experience, underpinned by...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Life and Careers Full time

    Company OverviewAt Standard Chartered Life and Careers, we're committed to delivering exceptional service and driving growth through innovation and collaboration. With a strong presence in over 70 markets across Asia, Africa and the Middle East, we offer a diverse range of products and services that meet the evolving needs of our clients.We're passionate...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Life and Careers Full time

    We are looking for a Compliance and Risk Professional to join our team at Standard Chartered Life and Careers. As a key member of our organization, you will play a critical role in ensuring the compliance of our business with regulatory requirements.Job DescriptionThe Compliance and Risk Professional will be responsible for managing business analysis and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Life and Careers Full time

    We are seeking a highly experienced Risk Governance Specialist to join our team at Standard Chartered Life and Careers. As a key member of our organization, you will play a vital role in ensuring the effective management of risk across our business.Job DescriptionThe Risk Governance Specialist will be responsible for driving process effectiveness measures by...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tungsten Automation Full time

    Job DescriptionAbout Tungsten AutomationTungsten Automation is a leading provider of cloud-based solutions, helping businesses navigate the complexities of governance, risk management, and compliance. We're committed to delivering innovative technology that empowers our clients to achieve their goals with confidence.Key ResponsibilitiesWe are seeking a...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Touch 'n Go Group Full time

    We are looking for a Risk and Compliance Lead to join our team at Touch 'n Go Group.Job DetailsThe successful candidate will be responsible for evaluating the effectiveness and efficiency of technology internal controls in accordance with regulatory expectations and best practices. This includes Risk Management in Technology (RMiT), Information Security,...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Randstad Malaysia Full time

    About Job DescriptionContribute to IT GovernanceDevelop, implement, and maintain robust IT governance, risk, and compliance (GRC) policies, frameworks, and standard operating procedures in alignment with industry best practices and regulatory requirements.Collaborate with internal stakeholders to promote a unified approach to information security across the...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Dentsu Aegis Network Full time

    About this OpportunityThis is a fantastic opportunity to join a dynamic and innovative team that is committed to protecting our clients' brands and data. You will be part of our global Technology & Security Risk team and report to the Head of Technology & Security Risk.Main ResponsibilitiesImplement our risk management processes into a newly acquired entity...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tungsten Automation Full time

    About This RoleCompany OverviewTungsten Automation is a leader in cloud-based solutions, providing businesses with the tools they need to navigate the complexities of governance, risk management, and compliance. Our team is passionate about delivering innovative technology that empowers our clients to achieve their goals.Key Job DutiesWe are seeking a highly...