Head of Information Security I TNG

2 weeks ago


Kuala Lumpur, Kuala Lumpur, Malaysia Touch 'n Go Group Full time 150,000 - 250,000 per year

We fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion – LEAP

We are a culture that empowers everyone to innovate and create solutions that will leave a positive impact on our communities and our nation, Touch 'n Go will always be here to inspire our talents to grow as leaders and innovators giving you the power to make a difference.

What would you do?

The Head of Information Security is responsible for the technology risk management function of Touch 'N Go Sdn. Bhd. (TNGSB). Shall be independent from day-to-day technology operations, keep apprised of current and emerging technology risks which could potentially affect TNGSB risk profile and be appropriately certified. Must also oversee the protection of TNGSB' information data and safeguard the company's IT infrastructure, technologies and assets. Responsible for establishing, implementing and overseeing an effective information security management program to ensure the confidentiality, integrity and availability of TNGSB's information assets. Serves as a critical member of the management team, providing strategic input and advice, technical and governance for information security and cybersecurity initiatives.

Governance and Compliance

  • Develop and enforce an enterprise-wide information Security Policy in line with BNM's policies (e.g. Risk Management in Technology, Cyber Resilience Framework, Outsourcing Guidelines, Data Governance).
  • Ensure compliance with regulatory requirements, including the Risk Management in Technology (RMiT) policy document.
  • Formulate appropriate policies for the effective implementation of TRMF and CRF.
  • Enforce compliance with these policies, framework, and other technology related regulatory requirements.
  • Monitor and report on the organisation's information security posture to senior management, the board and regulators.

Strategic Planning and Implementation

  • Formulate and implement a comprehensive Information Security Strategy aligned with TNGSB's business objectives.
  • Develop a robust cybersecurity framework to prevent, detect, and respond to treats and incidents.
  • Oversee the design, implementation and monitoring of security controls for systems, networks and data.

Risk Management

  • Conduct periodic Technology Risk Assessment (TRA) to identify and mitigate information security risks.
  • Ensure effective management of third-party risks related to outsourcing and vendor partnerships, particularly for critical systems and data.
  • Lead initiatives for identifying and addressing vulnerabilities and emerging threats.
  • Oversees and responsible for the Data Governance Framework of the organisation.

Incident Management

  • Establish and maintain an effective Cyber Incident Response Plan (CIRP) in compliance to BNM's guidelines.
  • Ensure the timely detection, reporting and resolution of cybersecurity incidents.
  • Conduct post-incident reviews to strengthen cybersecurity resilience.

Awareness and Training

  • Promote a strong cybersecurity culture across all levels of the organization.
  • Implement regular cybersecurity awareness programs for employees and stakeholders.

Collaboration and Reporting

  • Act as the primary point of contact for regulators on information security matters.
  • Collaborate with the Risk, Compliance and Technology teams to ensure integrated risk management.
  • Provide regular updates and reports to the TNG Management Committee (TMC), Management Audit, Risk and Compliance Committee (MARCC), Board Audit, Risk and Compliance Committee (BARCC) and Board of Directors (BOD).

Who should join us?

  • Candidate with a min. of 10 years of proven IT security experience in a combination of risk management, information security and preferably in financial services industry.
  • Professional certification or qualifications in IT Information Security and Risk, such as CEH/CND/CCISO/CHFI/ ECSS/CTIA /CISSP/ISMS.
  • Proven record of dealing with complex projects and meeting conflicting demands.
  • Strategic thinker and implementor with excellent stakeholder management across divisions, customers, regulators and business partners.
  • Collaborate with industry peers to align with best practices and address shared risks.
  • Experienced with Cloud computing across virtualized environments.
  • Ability to adapt to fast-moving IT landscape and keep pace with latest thinking and new security technologies.
  • Excellent communication skills – providing verbal and written communication that is outstanding to both direct reports and senior management as well as other stakeholders.
  • Flexible and adaptable – capable of changing direction where required and showing flexibility to meet new demands.
  • Form business partnerships that help drive the IT security strategy forward.
  • Able to make decisions that are well informed and timely.
  • Multitasking – able to manage several concurrent projects and priorities demands.

Our Perks & Benefits:

  • Hybrid and Flexi hours.
  • e-Wallet meal allowance.
  • Unlimited office pantry fruits, snacks and drinks.
  • Mobile and broadband subscription reimbursement.
  • Flexibility to opt dependents coverage (spouse, child, parents or parents-in-law) for outpatient medical benefits.
  • Additional leave including family leave and paid care leave to care for family members.
  • Medical coverage including dental, optometrist, mental care, maternity, registered Traditional Chinese Medicine ("TCM") and Chiropractic.
  • Corporate membership discount and many more to explore.

We believe that you have what it takes to fit into the Touch 'n Go family and help revolutionize the Fintech industry by paving the way to a cashless society. If you're ready to take the next step, apply now

Touch 'n Go is an organization that strives to provide Equal Opportunity Employment, based on merit, qualifications, capabilities, and caliber. It is Touch 'n Go's policy to not discriminate based on age, race, religion, colour or other personal status, identity or characteristics. Fair Opportunity is Our Value and Practice. Please advise us of any accommodations you may need by e-mailing:

Note
: Only shortlisted candidates will be contacted.



  • Kuala Lumpur, Kuala Lumpur, Malaysia Ambition Full time 120,000 - 240,000 per year

    About the Company:Our client is aLeading regional financial institutionwith a growing technology footprint in Malaysia. As part of a larger Asian banking group, the organization is actively investing in digital transformation and innovation to modernize its banking services. With a hybrid working model, agile teams, and close collaboration with group-level...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Mangala Estate Boutique Resort Full time 120,000 - 180,000 per year

    Franky Group of Companies is a diversified business with a strong presence in construction, property development, and various other sectors. We are committed to innovation, excellence, and driving sustainable growth across all our ventures. We are seeking a dynamic and experienced Head of IT to lead our technology initiatives and manage IT transformation...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TNG Digital Full time 120,000 - 360,000 per year

    We fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion – LEAPWe are a culture that empowers everyone to innovate and create solutions that will leave a positive impact on our communities and our nation, Touch 'n Go will always be here to inspire our talents to grow as leaders and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Takaful Malaysia Full time 120,000 - 180,000 per year

    The Head Technology Security is a crucial management role within our technology security section.Leadership and Vision: Provide strategic direction and operational leadership to the technology security team, ensuring alignment with organizational objectives and cybersecurity best practices.Security Strategy Development: Develop and implement comprehensive...


  • Kuala Lumpur, Kuala Lumpur, Malaysia RIAmetric Full time 100,000 - 120,000 per year

    The Head IT Operations is responsible to lead IT Operations Department, consisting of the Cloud, Infrastructure, NAC and Operations Teams. Focused on managing the operation, delivery and continuous improvement of common services across the Group, ensuring that the services are fit for purpose and are delivered to the Group in line with agreed SLAs, schedules...

  • Head of IT Security

    2 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Quintus Search Full time 120,000 - 180,000 per year

    Our client is a growing green energy major and global leader in climate action.As the Head of IT Security, you will lead a thriving, motivated, and supportive competence team. You will participate in or drive different leadership initiatives, like global competence strategy development, talent development, inclusion and diversity, or leaders development.You...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Krisvconsulting Services Full time $120,000 - $200,000 per year

    The Head of Security Engineering will lead the design, implementation, and continuous improvement of the banks security infrastructure. This strategic role is responsible for building secure, scalable systems and ensuring compliance with regulatory frameworks such as Bank Negara Malaysias RMiT, ISO 27001, and NIST. The ideal candidate will drive innovation...


  • Kuala Lumpur, Kuala Lumpur, Malaysia DUG Full time 90,000 - 120,000 per year

    DUG is looking for an Information Security Manager to join our global team. In this role, you'll take ownership of our cybersecurity posture, shaping policies, monitoring for threats, and implementing best practices to protect our data, systems, and users.We operate primarily in a Linux-based environment, so a strong foundation in Linux security is...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Chubb Full time 120,000 - 180,000 per year

    PurposeAre you interested in spearheading cybersecurity excellence in a growth and diverse region? Chubb is seeking a seasoned Information Security Manager to lead our information security initiatives across multiple countries in the APAC region. This is a unique opportunity to make a significant impact by shaping the regional security culture and enabling...


  • Kuala Lumpur, Kuala Lumpur, Malaysia I-TRACING Full time 30,000 - 60,000 per year

    I-TRACING is looking for a new French speaking intern to join our growing team in Kuala LumpurJoin the infrastructure team of a major client, where your missions will include:Creating servers for the client's internal projectsEnsuring the operational maintenance of the virtualization, storage, and log management environmentsImplementing the necessary...