Head of Information Security
4 days ago
The Head of Information Security in the Boost DigiBank is responsible for ensuring the security of the bank's information systems and data, and for managing the bank's overall information security st rategy. The Head of Information Security is typically a high -level executive who reports directly to the Bank's CEO or Board of Directors.
Responsibilities:
Formulate and facilitate the implementation of Technology Risk Management Framework (TRMF) and Cyber Resilience Framework (CRF) which are to be aligned to Enterprise Risk Management Framework;
Work closely with all relevant business divisions, IT and other support functions to put in place appropriate policies & procedures in place to support & complement TRMF and CRF as well as to ensure compliance with BNM guidelines on information technology (IT) risks;
Assess adequacy of IT security & cybersecurity stra tegy including the employment of effective tools to monitor and enable timely detection of anomalous activities;
Responsible for developing and implementing IT Security Assessment (Application, infrastructure, network architecture) and risk management frameworks, policies and including site reviews of branch offices, data centres and vendors
Assess whether enterprise information security architecture and roadmaps are able to support both business and information security objectives and monitor/report on the status of implementation.
Develop appropriate technology risk appetite (tolerance levels) and suitable Key Risk Indicators (KRIs) to effectively monitor technology & cyber risks;
Review & monitor results of penetration testing/vulnerability assessments/IT audits and monitor/report on status of corrective actions taken;
Work closely with System, Network and Application teams for closure of non - compliance issues, which could be identified through periodic IT Security -related reviews / audits and controls
Advise and validate the operational IT Security requirements for any technology projects;
Assess the reasonableness/practicality of expenditures and capital investments pertaining to the implementation of new technologies;
Develop and/or review adequacy of Cy ber Incident Response Plan (CIRP), processes, reporting templates and rules to formalise response to incidents involving cyberattacks or disaster;
Coordinate with relevant stakeholders on forensic investigations, cybercrimes, and/or cyberattacks and incide nt response;
Coordinate threat management and recovery against cyber threats (e.g., malware, phishing, hacking);
Ensure timely reporting IT Security related incidents (cyberattacks, etc.) to senior management, the Board and regulators and participate and c ontribute from a risk assessment perspective as and when required; Head of Information Security (Digital Bank)
Attending to the Board -level Committee to provide independent views to the board and senior management on technology risks at the enterprise level.
Overall, the CISO plays a critical role in ensuring that the bank's information assets are protected from unauthorized access, theft, or damage, and that the bank's customers can trust the security of their financial transactions and personal information.
The Must Have:
• Degree in Information Technology (IT), Computer Science or other related discipline with relevant experience in managing cyber risk in financial market infrastructures, critical national infrastructure, military, security intelligence or equivalent.
• 8+ years of full -time work experience in information security management and/or related functions (such as IT audit and IT Risk Management);
• Professional certification such as CISM, CISA, CSXP, CISSP, CREST, GPEN or equivalent is highly desirable.
• Good understanding of the regulatory frameworks and compliance requirements associated with financial services and thorough understanding of end -to-end IT operations and how IT interfaces with business, risk management and compliance processes and IT Security.
• Must possess excellent interpersonal skills and able to communicate and manage relationship at all levels including senior management, business users, participants, vendors and team members.
• Ability to communicate security risks in business terms to all levels of the organization.
• Knowledge of security metrics and Key Security Risk indicators
-
Head of Information Security I TNG
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Touch 'n Go Group Full timeWe fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion – LEAPWe are a culture that empowers everyone to innovate and create solutions that will leave a positive impact on our communities and our nation, Touch 'n Go will always be here to inspire our talents to grow as leaders and...
-
Head, Information Security Engineering
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Ambition Full time 120,000 - 240,000 per yearAbout the Company:Our client is aLeading regional financial institutionwith a growing technology footprint in Malaysia. As part of a larger Asian banking group, the organization is actively investing in digital transformation and innovation to modernize its banking services. With a hybrid working model, agile teams, and close collaboration with group-level...
-
Head of Technology Security
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Takaful Malaysia Full time 120,000 - 180,000 per yearThe Head Technology Security is a crucial management role within our technology security section.Leadership and Vision: Provide strategic direction and operational leadership to the technology security team, ensuring alignment with organizational objectives and cybersecurity best practices.Security Strategy Development: Develop and implement comprehensive...
-
Head of Information Technology
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia RIAmetric Full time 100,000 - 120,000 per yearThe Head IT Operations is responsible to lead IT Operations Department, consisting of the Cloud, Infrastructure, NAC and Operations Teams. Focused on managing the operation, delivery and continuous improvement of common services across the Group, ensuring that the services are fit for purpose and are delivered to the Group in line with agreed SLAs, schedules...
-
Head of IT Security
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Quintus Search Full time 120,000 - 180,000 per yearOur client is a growing green energy major and global leader in climate action.As the Head of IT Security, you will lead a thriving, motivated, and supportive competence team. You will participate in or drive different leadership initiatives, like global competence strategy development, talent development, inclusion and diversity, or leaders development.You...
-
Information Security Manager
4 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Simplepay Gateway Sdn Bhd Full timeMain purposes of the job:To manage, develop, and maintain the organization's IT security framework, ensuring the integrity, confidentiality, and availability of information assets while meeting regulatory compliance requirements and addressing emerging cyber threats.Responsibilities:Manages cyber-security plan, security infrastructure, security standards and...
-
Information Security Engineer
4 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Bursa Malaysia Full timeCompany DescriptionBursa Malaysia Berhad, one of the largest stock exchanges in Asia, is home to nearly 1,000 listed companies, offering diverse investment options for global and local investors. It includes the Main Board for large-cap companies, the Second Board for medium-sized firms, and the MESDAQ Market for high-growth and technology enterprises. As a...
-
Director, Group Information Security
4 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia FWD Insurance Full timeAbout FWD GroupFWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD's customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler insurance experience. Established in 2013, the...
-
Head of Security Engineering
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Krisvconsulting Services Full time $120,000 - $200,000 per yearThe Head of Security Engineering will lead the design, implementation, and continuous improvement of the banks security infrastructure. This strategic role is responsible for building secure, scalable systems and ensuring compliance with regulatory frameworks such as Bank Negara Malaysias RMiT, ISO 27001, and NIST. The ideal candidate will drive innovation...
-
Information Security Manager
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia DUG Full time 90,000 - 120,000 per yearDUG is looking for an Information Security Manager to join our global team. In this role, you'll take ownership of our cybersecurity posture, shaping policies, monitoring for threats, and implementing best practices to protect our data, systems, and users.We operate primarily in a Linux-based environment, so a strong foundation in Linux security is...