VP, Application security – Group Tech Risk

3 days ago


Kuala Lumpur, Kuala Lumpur, Malaysia AmBank Group Full time
VP, Application Security – Group Tech Risk

The role is expected to perform oversight to ensure effectiveness in IT security control and IT risk management through validation and risk assessments mainly on application security scope.

KEY RESPONSIBILITIES

  • Evaluate the effectiveness of technology and security controls within the application, software delivery life cycle, and IT project management to be in line with RMIT and other regulatory requirements.
  • Review and assess the effectiveness of technology and security controls within the application, software delivery life cycle, and IT project management to be in line with RMIT and other regulatory requirements, e.g., PayNet, SC, and BURSA.
  • Act as technology risk liaison on application security fundamentals for key business and IT projects.
  • Perform application risk assessment identifying information security and technology risks associated with new initiatives/projects/system enhancements with AmBank Group based on industrial standards and advise necessary control considerations to respective stakeholders.
  • Provide oversight on incident management, challenging the effectiveness of security incident root cause analysis and resolution identification.
  • Support and assist in consolidating application classification inventory to develop a means of prioritizing risk mitigation processes.
  • Review risk closure by the first line and validate the documented evidence to ensure proper closure of the risk treatment plan.
  • Perform control evaluation and validation on IT KRI and report status based on KRI threshold matrix to management; review and evaluate entry of new risk and control assessment by the first line and assist in identifying relevant KRI and KCTs associated with risks.
  • Continually identify, track, and assess potential risks/threats (from an application security angle) and recommend improvement efforts to alleviate or mitigate risks.
  • Work with the first line to ensure best practices and conformance to vulnerability guidelines, which includes timely remediation and closure of observations.
  • Ability to execute independent risk assessments on Cloud and Emerging Technology (AI, ML, RPA, etc.).

KEY REQUIREMENTS/SKILLS/EXPERIENCE

  • Candidate must possess at least a Bachelor's Degree, Professional Degree, Computer Science/Information Technology or equivalent.
  • Good to have professional certification preferred (CISSP, CISM, CRISC).
  • At least 8 years of working experience in Information Security or IT Risk, Application Security, preferably in financial services in Malaysia with work experience in penetration testing, vulnerability testing, and static code analysis.
  • Experience and knowledge of web application vulnerabilities and web application business logic flaws and threats.
  • Knowledge of application architectures and technology; including web applications, mobile technology, data encryption, and identity and access management.
  • Understanding of security controls such as Authentication, Authorization, Access Control, Cloud Security, Cryptography, and Network Protocols along with security standards: OWASP Top 10, NIST, and CVE.
  • Working knowledge of operating systems, servers, as well as iOS and Android mobile devices.
  • Knowledge of local regulator/international standard/best practices of security policy, guidelines, etc.
  • Ability to handle multi-tasks and manage multiple projects simultaneously.
Seniority Level

Mid-Senior level

Employment Type

Full-time

Job Function

Information Technology, Accounting/Auditing, and Strategy/Planning

#J-18808-Ljbffr

  • Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Full time

    **Vendor Risk Oversight**We are seeking an experienced professional to join our team as VP of Vendor Risk Oversight. In this position, you will be responsible for leading our vendor risk management activities, ensuring that our vendors and partners meet the highest standards of security and compliance.As a key member of our team, you will work closely with...


  • Kuala Lumpur, Kuala Lumpur, Malaysia AmBank Group Full time

    Job DescriptionAbout the RoleWe are seeking an experienced IT Risk and Compliance Manager to join our team at AmBank Group. In this role, you will be responsible for ensuring the effectiveness of technology and security controls within the application, software delivery life cycle, and IT project management.Evaluate the effectiveness of technology and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia AmBank Group Full time

    Job SummaryAbout the PositionWe are looking for an experienced VP of Cybersecurity - Financial Services to join our team at AmBank Group. As a senior leader, you will be responsible for developing and implementing effective cybersecurity strategies to protect our organization's assets.Develop and implement cybersecurity strategies to protect against emerging...


  • Kuala Lumpur, Kuala Lumpur, Malaysia AmBank Group Full time

    About the RoleSeniority LevelThis position is a mid-senior level role, requiring a strong background in IT Risk and Compliance.Job FunctionThis role is part of the Information Technology, Accounting/Auditing, and Strategy/Planning teams.Employment TypeThis is a full-time position.In this role, you will be responsible for ensuring the effectiveness of...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Finexus Group Full time

    Finexus Group WP. Kuala Lumpur, Federal Territory of Kuala Lumpur, MalaysiaApplication Security EngineerJob Brief:We also provide SaaS (Software as a Service) services which include infrastructure, platform, business processing outsourcing for banking and financial industry.Job Responsibilities:Overseeing overall development, implementation and maintenance...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Finexus Group Full time

    Direct message the job poster from Finexus GroupSenior Talent Acquisition Specialist | IT Recruitment Expert @ Finexus Hiring Top TalentJob Brief:We provide SaaS (Software as a Service) services which include infrastructure, platform, and business processing outsourcing for the banking and financial industry.Job Responsibilities:Overseeing overall...

  • VP of Cybersecurity

    3 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia AmBank Group Full time

    About the JobAmBank Group OverviewAmBank Group is a leading financial institution in Malaysia, providing a wide range of financial products and services to individuals and businesses. We are committed to delivering exceptional customer service and building long-term relationships with our customers.Job DescriptionWe are seeking an experienced Application...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Nuyew Tech Academy Full time

    Company OverviewNuyew Tech Academy was launched by our Founder and CEO Jonathan to inspire the next generation of Tech Talent. Our mission is to provide the very best education and employment opportunities to people of all backgrounds and ages looking to enter the Tech Industry.About UsOur core expertise lies in delivering Fast Track Career Programmes that...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tech Titan Group - Titan Guard and Tech Titan Distribution Full time

    About the PositionWe are seeking a Cybersecurity Systems Engineer to join our team at Tech Titan Group - Titan Guard and Tech Titan Distribution. As a Cybersecurity Systems Engineer, you will be responsible for providing technical support to customers, working cooperatively with team members to arrive at issue resolution, and contributing to the improvement...


  • Kuala Lumpur, Kuala Lumpur, Malaysia PureSoftware Ltd Full time

    Application Security ExpertWe are seeking an experienced Application Security Expert to join our team at PureSoftware Ltd. In this role, you will be responsible for identifying and mitigating security risks associated with our applications.Key Responsibilities:Conduct application security testing and vulnerability assessments.Collaborate with development...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Planex Technology Sdn Bhd Full time

    Job Description:We are seeking an experienced Application Security Expert to join our team at Planex Technology Sdn Bhd.About the Role:We will provide training and guidance to developers on secure coding practices, common vulnerabilities (such as those listed in the OWASP Top 10), and how to avoid them.The ideal candidate should have a strong understanding...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Nuyew Tech Academy Full time

    Nuyew Tech Academy | Full-Time/Part-TimeCyber Security Trainee (Career Accelerator with Employment Guarantee)Kuala Lumpur, Malaysia | Posted on 11/03/2025Country MalaysiaPostal Code 50000About UsThe Nuyew Tech Academy was launched by our Founder and CEO Jonathan to inspire the next generation of Tech Talent and is based on a passion to provide the very best...

  • VP of Technology

    2 weeks ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Hiredly X Full time

    This job is for a VP of Technology at an AI company. You might like this job because you'll lead innovative tech strategies, mentor a talented team, and even code when needed. It's a dynamic role perfect for a hands-on leader passionate about technologyWe are seeking a strategic, innovative, and experienced technology leader to take on the role of VP of...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TIME's group Full time

    In this fixed-term contract role, you will be responsible for managing technology and security risks across Dentsu international markets. You will work closely with the business to embed our security risk management process and support the growth and adoption of technology and security risk management processes. The ideal candidate has 2-3 years of...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Hytech Full time

    2 days ago Be among the first 25 applicantsTalent Acquisition Business Partner - Hytech l Hiring for IT Tech and Non-Tech TalentsAbout The Role:As a Software Security Architect, you will evaluate both applications and systems architecture from a security perspective, offering expert guidance to the team.Your responsibilities will include designing,...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TIME's group Full time

    Dentsu's commitment to protecting clients' brands and data drives the need for a Technology & Security Risk Analyst. As part of our global Technology & Security Risk team, you will implement risk management processes in newly acquired entities and support ongoing technology and security risk management. Key responsibilities include embedding our security...


  • Kuala Lumpur, Kuala Lumpur, Malaysia MNRB Group Full time

    An IT Security Threat and Identity Analyst provides technical assistance with the detection, analysis and supporting the gaps mitigation on infrastructure and application vulnerabilities with the Group. A hands-on technical specialist and security monitoring analyst, the Analyst handles complex and detailed technical work necessary to establish and maintain...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TIME's group Full time

    Technology & Security Risk Analyst (Fixed Term Contract)Dentsu is the network designed for what's next, helping clients predict and plan for disruptive future opportunities and create new paths to growth in the sustainable economy. Taking a people-centered approach to business transformation, we use insights to connect brand, content, commerce and...

  • Business Risk Expert

    2 hours ago


    Kuala Lumpur, Kuala Lumpur, Malaysia FRG | Financial Risk Group Full time

    Are you ready to start your career in risk management consulting? Join FRG | Financial Risk Group and become part of a dynamic team that empowers organizations worldwide to manage risk effectively.We are seeking talented professionals with a strong background in business, actuarial science, analytics, statistics, financial mathematics, computer science,...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TIME's group Full time

    This role offers an exciting opportunity to join Dentsu's global Technology & Security Risk team as a Technology & Security Risk Analyst. Your primary responsibility will be to implement our risk management processes in a newly acquired entity, ensuring effective and proportionate management of technology and security risks. You will work closely with...