Information Security Manager – APAC

1 day ago


Kuala Lumpur, Kuala Lumpur, Malaysia Chubb Full time 120,000 - 180,000 per year

Purpose

Are you interested in spearheading cybersecurity excellence in a growth and diverse region? Chubb is seeking a seasoned Information Security Manager to lead our information security initiatives across multiple countries in the APAC region. This is a unique opportunity to make a significant impact by shaping the regional security culture and enabling business to thrive securely.

As Information Security Manager, you will be responsible for safeguarding Chubb's operations by leading the countries cybersecurity mandate, fostering a strong security culture, and ensuring compliance with security standards. This role covers a portfolio of multiple country business and requires strong relationship management and influencing skill, as well as in-depth security knowledge and understanding of the regional cyber regulatory landscape.

The incumbent will be a senior member of the APAC RISO Information Security team, part of Global Information Security (GIS).

Responsibilities

Ability to drive and support the GIS agenda consistently across a growing, highly complex geography and diverse working culture is critical success criteria for the role.

Strategy and Program Leadership

  • Lead the Information security program across assigned countries
  • Ensure implementation of CISO priorities owned by business CIOs & delivery teams, acting as escalation point
  • Embed security into business requirements
  • Provide transparency & insights to the GIS leadership on program deployment and security strategy requirements

Security Governance

  • Chair monthly meetings to review the GIS program status, risk exposure, and support CIO & COO to drive risk mitigation plan
  • Represent GIS in quarterly business reviews, enterprise risk management committees and country board meetings
  • Review risk and performance indicators, CIO scorecards and act as escalation point to drive the risk to appetite

Transformation & Integration, M&A

  • Lead security planning and resourcing to scale and support business growth
  • Provide leadership and security expertise to Business executive on integration programs and M&A activities

Issue and Exception Management

  • Review and challenge control deviations, perform risk assessments and provide remediation recommendations
  • Ensure new issues and exceptions align with the GIS Cyber Governance framework
  • Review and challenge issue remedial plans, engage owners for risk-based remediation and escalate overdue issues for rectification

Security Risk assessment

  • Ensure new technology initiatives and changes are built with security by design in collaboration with security architecture and technical security teams
  • Provide security advisory support to assist business and technology comply with GIS security policies and standards
  • Identify thematic and systematic security risks in business process, application and infrastructure
  • Perform risk assessment and provide recommendation for mitigation
  • Liaise with business and technology leadership to drive the remedial plan
  • Provide update to GIS management for the remedial plan and progress

Stakeholder Management

  • Maintain effective relationships with senior business leaders and partners (CIO, COO, CRO, President, Business executives)
  • Influence executives to support cyber security risk management improvements
  • Raise awareness of Cyber threats, ensuring adequate coverage for business' information security program

Regulatory, audit and client engagement

  • Identify cyber and information security requirements applicable to the Business in partnership with Legal & Compliance function
  • Perform gap assessment against new cyber regulations. Engage GIS domain SME as appropriate to define action plans
  • Lead audit, client and regulatory cyber engagements

Incident Response

  • Oversee, support and report on business security incidents in collaboration with Global SOC, the Privacy function, and the regional executive teams.

Qualifications

  • Bachelor's degree in computer science, Information Systems, or a related field (preferred).
  • Professional certifications such as CISSP, CISM, or equivalent (preferred).
  • Familiarity with the insurance industry (preferred)
  • Extensive experience (10+ years) in information security, with expertise in implementing and leading security programs across geographic portfolios.
  • Strong knowledge of industry standards and frameworks (e.g., ISO 27001, NIST CSF, ISF SoGP).
  • Proven ability to influence senior stakeholders and align country, regional, and global security requirements.
  • A self-starter with strong interpersonal skills and the ability to work independently and in a matrixed format.
  • Strong verbal and written communication and presentation skills, including providing technical information effectively with non-technical audiences.
  • Experience with APAC regulatory compliance requirements related to information and cybersecurity, including familiarity with regional frameworks, standards, and regulations
  • Technical expertise in application security, infrastructure security, and vulnerability management.


  • Kuala Lumpur, Kuala Lumpur, Malaysia DUG Full time 90,000 - 120,000 per year

    DUG is looking for an Information Security Manager to join our global team. In this role, you'll take ownership of our cybersecurity posture, shaping policies, monitoring for threats, and implementing best practices to protect our data, systems, and users.We operate primarily in a Linux-based environment, so a strong foundation in Linux security is...


  • Kuala Lumpur, Kuala Lumpur, Malaysia LiveWell Full time 90,000 - 120,000 per year

    Job Summary:Lead access services team and manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:•    Manage identity services related to accounts, roles, and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Zurich Insurance Full time 50,000 - 100,000 per year

    Job Summary:Lead access services team and manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:Manage identity services related to accounts, roles, and access...


  • Kuala Lumpur, Kuala Lumpur, Malaysia LiveWell Full time 90,000 - 120,000 per year

    Job Summary:Manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:•    Manage identity services related to accounts, roles, and access privileges. •  ...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tri Wind Technology Sdn Bhd Full time 80,000 - 120,000 per year

    Position Overview:The IT Security Administrator (ITSA) is responsible for ensuring the security and integrity of the organization's IT infrastructure by managing and administering user accounts, access permissions, and various IT systems. The ITSA plays a critical role in protecting sensitive information and maintaining compliance with security policies.Key...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TechLab Security Sdn Bhd Full time 120,000 - 180,000 per year

    Job SummaryWe are seeking an experienced Senior Cybersecurity Engineer to lead and manage daily Security Operations (SecOps) activities. The role involves hands-on management of endpoint security, firewalls, email security, and WAF, as well as leading cybersecurity enhancement projects across the organization.The ideal candidate is a technically strong and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Chubb Full time 900,000 - 1,200,000 per year

    Job DescriptionThe APAC Technology GRC Manager will be part of the APAC GRC team. You will be responsible for managing the governance and management of risk and controls across Asia Pacific region.The role will be part of a broader team ambition which seeks to ensure APAC Technology comply with all their obligations. This position will require strong...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Ambition Full time 120,000 - 240,000 per year

    About the Company:Our client is aLeading regional financial institutionwith a growing technology footprint in Malaysia. As part of a larger Asian banking group, the organization is actively investing in digital transformation and innovation to modernize its banking services. With a hybrid working model, agile teams, and close collaboration with group-level...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Appnovation Full time 120,000 - 240,000 per year

    About UsAppnovation is a global, full-service digital partner that combines Strategy, Experience & Design, Engineering and Managed Services. We build digital solutions that deliver real impact today and serve as foundations for future growth. Bold ambition. Practical action. Endless possibilities.As a member of the IT team, the Sr. Associate, IT (Security)...


  • Kuala Lumpur, Kuala Lumpur, Malaysia AVEVA Full time 800,000 - 1,200,000 per year

    AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life – such as energy, infrastructure, chemicals and minerals – safely, efficiently and more sustainably.We're the first software business in the world to have our sustainability targets validated by the SBTi, and...