Manager, Cyber Resilience Testing

3 days ago


Kuala Lumpur, Malaysia Bank Islam Full time

Req ID: 7531
- Job Description:

- **Duties and Responsibilities**
- As the Manager, Cyber Resilience Testing (CRT) Operations, you will be responsible for leading the strategic planning, execution, and continuous improvement of advanced cyber resilience testing, real-time attack simulations, and threat emulation exercises across the organization. You will set the vision and direction for the Red Team, ensuring that all activities are aligned with organizational objectives and regulatory requirements. Your role includes overseeing the development of testing methodologies, managing team performance, and ensuring that red team operations deliver actionable insights to strengthen the bank’s cyber defense posture. In addition, you will provide leadership and mentorship to the CRT team, fostering a culture of innovation, collaboration, and professional growth. You will collaborate closely with internal stakeholders, including blue teams and business units, to ensure effective knowledge transfer and incident response readiness.

**Key Performance Areas**
- Red Team Program Leadership
- Lead, mentor, and develop the Red Team, ensuring high performance and continuous skills development.
- Oversee the planning and execution of red teaming engagements, including adversary emulation and attack simulations.
- Develop and refine methodologies for threat modeling, attack surface analysis, and vulnerability assessments.
- Ensure timely and high-quality reporting to senior management, including executive summaries, risk assessments, and remediation recommendations.
- Drive continuous improvement of red teaming strategies based on emerging threats, attack techniques, and industry trends.
- Ensure compliance with Bank Negara Malaysia (BNM) RMiT, TIBER-MY, and other relevant regulatory and security frameworks.
- Cyber Security Program Oversight
- Oversee and support information/cyber security programs such as compromised assessment, threat hunting, and cyber drill exercises.
- Champion organization-wide information security education and awareness campaigns.
- Provide expert guidance and training to stakeholders on cyber threats and defensive strategies.
- Track and report on the effectiveness of cybersecurity programs and initiatives.
- Act as the primary point of contact for internal and external stakeholders regarding red team operations.

**Qualification** - Degree in Information Technology or any related fields.

**Years of Experience**
- Minimum 8+ years of experience in offensive security, penetration testing, or red teaming, with at least 4+ years in a leadership role
- 3 years job experience in Financial and Banking sector

**Specific Skills/Knowledge and Certification Required**
- Proven experience in leading red team or offensive security teams.
- Deep expertise in ethical hacking, adversary simulation, and advanced penetration testing.
- Strong knowledge of banking systems, integration, and regulatory requirements.
- Proficiency with tools such as Cobalt Strike, Metasploit, Empire, Mimikatz, Burp Suite, BloodHound, and custom scripts.
- In-depth understanding of network, cloud, web, and mobile security.
- Familiarity with threat hunting, purple teaming, and advanced attack methodologies.
- Strong knowledge of MITRE ATT&CK, TTPs, and modern attack frameworks.
- Industry certifications such as OSCP, OSCE, OSEP, CRTO, CISSP, GIAC (GCPN, GXPN, GCIH), or equivalent are highly preferred.
- Excellent analytical, problem-solving, communication, and leadership skills.
- Ability to communicate technical findings to both technical and non-technical stakeholders.



  • Kuala Lumpur, Malaysia Bank Islam Full time

    Req ID: 7532 - Job Description: - **Duties and Responsibilities** - As the Deputy Manager, Cyber Resilience Testing (CRT) Operations, you will play a critical role in supporting the execution of advanced cyber resilience testing, real-time attack simulations, and threat emulation exercises. Working closely with the Cyber Resilience Testing (CRT) team and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Gentari Full time 120,000 - 180,000 per year

    Changing how we live todayto help secure our future.Join us at Gentari to be part of this exciting, purposeful journey towards a cleaner energy future.Gentarians are passionate about sustainability - our purpose is to solve the world's most pressing sustainable energy needs. Here at Gentari, we move differently. Teams seek out opportunities to work with one...


  • Kuala Lumpur, Malaysia Strato Solutions Sdn Bhd Full time

    Key responsibilities include: - Monitor and triage security alerts and digital forensic - Response and remediate identified threats, coordinate system recovery towards the cyber security incident, and prepare cyber security incident RCA - Design and rollout of information security processes such as Incident Management, Intrusion Detection, and Security...


  • Kuala Lumpur, Malaysia Affin Bank Full time

    Assistant Manager, Cyber Risk Management **Create your future with Affin! You too can make a difference.** Join us at AFFIN, where the open minds meet and be inspired by a shared commitment to great work. Here, you don't just stay at the forefront of the industry - you can make a difference too. **Job Purpose** Ensure the governance and oversight on the...

  • Cyber Practice

    23 hours ago


    Kuala Lumpur, Malaysia Marsh Full time

    **Manager, Cyber Practice (Cyber Insurance)** **What can you expect?** - Join Global Leader in Insurance Broking and Innovative Risk Management Solutions - A team of diverse professionals across the globe, dedicated to helping clients manage some of the world’s most challenging and complex risks awaits - Dedicated learning and development programs **We...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Wizlynx Malaysia Sdn Bhd Full time 900,000 - 1,200,000 per year

    Key RoleAs (Senior) Cyber Security Consultant & Penetration Tester, you will execute a variety of engagements, conducting advanced hands-on penetration testing beyond automated tool validation, which will focus on targets that may include network devices, servers, web and mobile apps, web APIs, wireless infrastructures, IoT devices, and other information...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Hilti Group Full time 90,000 - 120,000 per year

    WHAT'S THE ROLE?You will be part of the Global Cyber Risk, Control & Assurance team and together with your fellow Cyber Risk and Controls Officers you ensure that IT & cyber risks at Hilti are proactively identified, evaluated and managed.This full-time position is available as soon as possible.WHAT YOU'LL DOYou will support the PO IT & Cyber Risk Management...


  • Kuala Lumpur Centre, Kuala Lumpur, Malaysia Hilti (Malaysia) Sdn Bhd Full time 60,000 - 120,000 per year

    What's the role? You will be part of the Global Cyber Risk, Control & Assurance team and together with your fellow Cyber Risk and Controls Officers you ensure that IT & cyber risks at Hilti are proactively identified, evaluated and managed.This full-time position is available as soon as possible.What You'll do You will support the PO IT & Cyber Risk...


  • Kuala Lumpur, Malaysia Forest Interactive Sdn Bhd Full time

    **Internship for IT Cyber Security** MYR 800 + Daily Lunch Meals Kuala Lumpur Forest Interactive is a MSC Status company which enables global wireless solutions for enterprises and merchants who want to benefit from the mobile channel by delivering services aimed at generating revenues, improving business efficiency and proactively managing relationships...

  • Cyber Security Manager

    22 hours ago


    Greater Kuala Lumpur, Malaysia International Consulting & Hiring Solutions (ICHS) Full time

    Cybersecurity Manager$60k to 90k USD gross annual salaryLocation:Tbilisi (Georgia),Panama City (Panama),Kuala Lumpur (Malaysia)Reporting to:Group CTOHybrid (onsite + remote flexibility)Should be able to communicate in EnglishProficiency in Asian languages, particularly Chinese, will be an advantageOur client company is seeking a highly skilled and...