Assistant Manager, Cyber Risk Management

5 hours ago


Kuala Lumpur, Malaysia Affin Bank Full time

Assistant Manager, Cyber Risk Management

**Create your future with Affin You too can make a difference.**

Join us at AFFIN, where the open minds meet and be inspired by a shared commitment to great work. Here, you don't just stay at the forefront of the industry - you can make a difference too.

**Job Purpose**

Ensure the governance and oversight on the effectiveness of technology risk management for Affin Group. This function will be responsible to assist CISO organisation for maintaining a strong technology risk management culture, manage and support the technology risks program on identify, assess, measure, monitor, control and report on significant technology risks.

**Responsibilities**
- Manage and support to perform regular IT/Cyber risk monitoring and reporting. Prepare and analyse technology risk for the Banking Group.
- Manage and support technology risk metrics, including management cybersecurity dashboard and reporting.
- Manage and support to prepare and provide timely and accurate reporting on Technology Risk (including Cyber Risk) related matters to Head, Cyber Risk Management and Head, Technology Risk/CISO.
- Conduct independent assessment review to identify, assess and evaluate potential and emerging IT and Cyber threats as well as strategy to reduce, mitigate or transfer the IT and cyber risk.
- Provide advisory, guidance and recommendation on aspects related to technology risks, particularly in the area of information security and controls, and ensure compliance with the internal IT policies & procedures, as well as regulatory guidelines.
- Manage and support the technology risk awareness and training program. Work closely with business continuity management team and Technology Services (IT) team in defining/updating the issue management, as well as crisis management and communication processes.
- Work with Technology Services team to ensure relevant regulatory, banking industry and IT best practices are in place or incorporated into the existing policy, procedures and standards. Monitor and report compliance status of the policies, frameworks and other technology-related regulatory requirements; drive and engage with Technology Services on Cyber Drill, Red Team Exercise and other cyber related activities on improving the cyber resilience and cyber incident response time.
- Provide assistance and support to first-line of defense on the establishment of Technology Risk awareness and training program.
- Keep abreast on the latest technology and the emerging Technology threat landscape.
- Support Head, Cyber Risk Management and Head, Technology Risk/CISO in overseeing the effective implementation of technology risk management at entities level.

**Job Requirements**
- Degree in IT, IS or Computing and/or other relevant domains.
- Minimum of 5 years working experience in IT/Cyber Security with hands-on technical experience and 2-3 years working experience in IT risk management, Cyber risk management, information security or IT audit for financial services industry.
- Professional certification such as CISM, CEH, CRISC, CISSP is an added advantage.
- Possess good knowledge and experience with IT governance and control, information security and information technology risk management.
- Solid experience in undertaking technical security assessments of IT solutions.
- Familiar with Bank Negara Malaysia regulatory requirements related to Technology Risk.
- Strong analytical, influencing and problem resolution skills.
- Ability to engage regulators during inspection.
- Good written and communication skills, and ability to interact with senior management, as well as different stakeholders from different divisions and departments.
- Ability to work and collaborate with people across seniority and cultures.
- Ability to work independently with minimum supervision.

Job ID JR101062


  • Cyber Practice

    5 hours ago


    Kuala Lumpur, Malaysia Marsh Full time

    **Manager, Cyber Practice (Cyber Insurance)** **What can you expect?** - Join Global Leader in Insurance Broking and Innovative Risk Management Solutions - A team of diverse professionals across the globe, dedicated to helping clients manage some of the world’s most challenging and complex risks awaits - Dedicated learning and development programs **We...

  • Cyber Risk Analyst

    4 days ago


    Kuala Lumpur, Malaysia S&P Global Full time

    **About the Role**: **Grade Level (for internal use)**: 08 S&P Global Corporate **About the Role**: Cyber Risk Analyst This role helps reduce the cyber risk posed by third parties and protects S&P Global brands against possible attacks against our information assets by threat actors via backdoor created by our vendors. Primary responsibilities will include...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Hilti Group Full time 90,000 - 120,000 per year

    WHAT'S THE ROLE?You will be part of the Global Cyber Risk, Control & Assurance team and together with your fellow Cyber Risk and Controls Officers you ensure that IT & cyber risks at Hilti are proactively identified, evaluated and managed.This full-time position is available as soon as possible.WHAT YOU'LL DOYou will support the PO IT & Cyber Risk Management...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Gentari Full time 120,000 - 180,000 per year

    Changing how we live todayto help secure our future.Join us at Gentari to be part of this exciting, purposeful journey towards a cleaner energy future.Gentarians are passionate about sustainability - our purpose is to solve the world's most pressing sustainable energy needs. Here at Gentari, we move differently. Teams seek out opportunities to work with one...


  • Kuala Lumpur Centre, Kuala Lumpur, Malaysia Hilti (Malaysia) Sdn Bhd Full time 60,000 - 120,000 per year

    What's the role? You will be part of the Global Cyber Risk, Control & Assurance team and together with your fellow Cyber Risk and Controls Officers you ensure that IT & cyber risks at Hilti are proactively identified, evaluated and managed.This full-time position is available as soon as possible.What You'll do You will support the PO IT & Cyber Risk...


  • Kuala Lumpur, Malaysia AMK Technology Sdn Bhd Full time

    What You’ll Do - Manage and execute **cybersecurity risk assessments** and **audit management processes.**: - Ensure organizational compliance with **ISO 27001** and other regulatory frameworks. - Identify, evaluate, and mitigate security risks across enterprise systems. - Work with stakeholders to strengthen controls and improve audit readiness. -...


  • Kuala Lumpur, Malaysia Affin Bank Full time

    Director, IT Risk Management **Create your future with Affin! You too can make a difference.** Join us at AFFIN, where the open minds meet and be inspired by a shared commitment to great work. Here, you don't just stay at the forefront of the industry - you can make a difference too. **Position Objective** - Responsible for the preparation and review of...


  • Kuala Lumpur, Malaysia Hong Leong Bank Full time

    If you are looking to excel and make a difference, take a closer look at us Functional _(job responsibilities):_ Cyber Incident Management - Being the point of contact to drive all cyber incidents managed by CERT - Create incident reports - Oversee all aspects of incident management process from evaluation to resolution - Coordinate the activities of...


  • Kuala Lumpur, Malaysia Bank Islam Full time

    Req ID: 7532 - Job Description: - **Duties and Responsibilities** - As the Deputy Manager, Cyber Resilience Testing (CRT) Operations, you will play a critical role in supporting the execution of advanced cyber resilience testing, real-time attack simulations, and threat emulation exercises. Working closely with the Cyber Resilience Testing (CRT) team and...


  • Kuala Lumpur, Malaysia Bank Islam Full time

    Req ID: 7278 - Job Description: **Summary** A Cyber Incident Response Manager plays a pivotal role in safeguarding an organization's digital assets by leading efforts to detect, analyze, and respond to cybersecurity incidents. This position is crucial in minimizing the impact of security breaches and ensuring swift recovery. **Duties and...