Information Security Manager – APAC
1 day ago
Purpose
Are you interested in spearheading cybersecurity excellence in a growth and diverse region? Chubb is seeking a seasoned Information Security Manager to lead our information security initiatives across multiple countries in the APAC region. This is a unique opportunity to make a significant impact by shaping the regional security culture and enabling business to thrive securely.
As Information Security Manager, you will be responsible for safeguarding Chubb's operations by leading the countries cybersecurity mandate, fostering a strong security culture, and ensuring compliance with security standards. This role covers a portfolio of multiple country business and requires strong relationship management and influencing skill, as well as in-depth security knowledge and understanding of the regional cyber regulatory landscape.
The incumbent will be a senior member of the APAC RISO Information Security team, part of Global Information Security (GIS).
Responsibilities
Ability to drive and support the GIS agenda consistently across a growing, highly complex geography and diverse working culture is critical success criteria for the role.
Strategy and Program Leadership
- Lead the Information security program across assigned countries
- Ensure implementation of CISO priorities owned by business CIOs & delivery teams, acting as escalation point
- Embed security into business requirements
- Provide transparency & insights to the GIS leadership on program deployment and security strategy requirements
Security Governance
- Chair monthly meetings to review the GIS program status, risk exposure, and support CIO & COO to drive risk mitigation plan
- Represent GIS in quarterly business reviews, enterprise risk management committees and country board meetings
- Review risk and performance indicators, CIO scorecards and act as escalation point to drive the risk to appetite
Transformation & Integration, M&A
- Lead security planning and resourcing to scale and support business growth
- Provide leadership and security expertise to Business executive on integration programs and M&A activities
Issue and Exception Management
- Review and challenge control deviations, perform risk assessments and provide remediation recommendations
- Ensure new issues and exceptions align with the GIS Cyber Governance framework
- Review and challenge issue remedial plans, engage owners for risk-based remediation and escalate overdue issues for rectification
Security Risk assessment
- Ensure new technology initiatives and changes are built with security by design in collaboration with security architecture and technical security teams
- Provide security advisory support to assist business and technology comply with GIS security policies and standards
- Identify thematic and systematic security risks in business process, application and infrastructure
- Perform risk assessment and provide recommendation for mitigation
- Liaise with business and technology leadership to drive the remedial plan
- Provide update to GIS management for the remedial plan and progress
Stakeholder Management
- Maintain effective relationships with senior business leaders and partners (CIO, COO, CRO, President, Business executives)
- Influence executives to support cyber security risk management improvements
- Raise awareness of Cyber threats, ensuring adequate coverage for business' information security program
Regulatory, audit and client engagement
- Identify cyber and information security requirements applicable to the Business in partnership with Legal & Compliance function
- Perform gap assessment against new cyber regulations. Engage GIS domain SME as appropriate to define action plans
- Lead audit, client and regulatory cyber engagements
Incident Response
- Oversee, support and report on business security incidents in collaboration with Global SOC, the Privacy function, and the regional executive teams.
Qualifications
- Bachelor's degree in computer science, Information Systems, or a related field (preferred).
- Professional certifications such as CISSP, CISM, or equivalent (preferred).
- Familiarity with the insurance industry (preferred)
- Extensive experience (10+ years) in information security, with expertise in implementing and leading security programs across geographic portfolios.
- Strong knowledge of industry standards and frameworks (e.g., ISO 27001, NIST CSF, ISF SoGP).
- Proven ability to influence senior stakeholders and align country, regional, and global security requirements.
- A self-starter with strong interpersonal skills and the ability to work independently and in a matrixed format.
- Strong verbal and written communication and presentation skills, including providing technical information effectively with non-technical audiences.
- Experience with APAC regulatory compliance requirements related to information and cybersecurity, including familiarity with regional frameworks, standards, and regulations
- Technical expertise in application security, infrastructure security, and vulnerability management.
-
Information Security Manager
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia DUG Full time 90,000 - 120,000 per yearDUG is looking for an Information Security Manager to join our global team. In this role, you'll take ownership of our cybersecurity posture, shaping policies, monitoring for threats, and implementing best practices to protect our data, systems, and users.We operate primarily in a Linux-based environment, so a strong foundation in Linux security is...
-
Information Security Specialist
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia LiveWell Full time 90,000 - 120,000 per yearJob Summary:Lead access services team and manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:• Manage identity services related to accounts, roles, and...
-
Information Security Specialist
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia Zurich Insurance Full time 50,000 - 100,000 per yearJob Summary:Lead access services team and manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:Manage identity services related to accounts, roles, and access...
-
Senior Information Security Analyst
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia LiveWell Full time 90,000 - 120,000 per yearJob Summary:Manage the organization Identity and Access Management (IAM) operation services for APAC. Ensure secure & timely access to systems and resources. Collaborate with global teams, drive IAM projects and new initiatives towards success.Key Responsibilities:• Manage identity services related to accounts, roles, and access privileges. • ...
-
Kuala Lumpur, Kuala Lumpur, Malaysia Tri Wind Technology Sdn Bhd Full time 80,000 - 120,000 per yearPosition Overview:The IT Security Administrator (ITSA) is responsible for ensuring the security and integrity of the organization's IT infrastructure by managing and administering user accounts, access permissions, and various IT systems. The ITSA plays a critical role in protecting sensitive information and maintaining compliance with security policies.Key...
-
Senior IT Security Engineer
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia TechLab Security Sdn Bhd Full time 120,000 - 180,000 per yearJob SummaryWe are seeking an experienced Senior Cybersecurity Engineer to lead and manage daily Security Operations (SecOps) activities. The role involves hands-on management of endpoint security, firewalls, email security, and WAF, as well as leading cybersecurity enhancement projects across the organization.The ideal candidate is a technically strong and...
-
APAC Technology GRC Manager
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia Chubb Full time 900,000 - 1,200,000 per yearJob DescriptionThe APAC Technology GRC Manager will be part of the APAC GRC team. You will be responsible for managing the governance and management of risk and controls across Asia Pacific region.The role will be part of a broader team ambition which seeks to ensure APAC Technology comply with all their obligations. This position will require strong...
-
Head, Information Security Engineering
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia Ambition Full time 120,000 - 240,000 per yearAbout the Company:Our client is aLeading regional financial institutionwith a growing technology footprint in Malaysia. As part of a larger Asian banking group, the organization is actively investing in digital transformation and innovation to modernize its banking services. With a hybrid working model, agile teams, and close collaboration with group-level...
-
Kuala Lumpur, Kuala Lumpur, Malaysia Appnovation Full time 120,000 - 240,000 per yearAbout UsAppnovation is a global, full-service digital partner that combines Strategy, Experience & Design, Engineering and Managed Services. We build digital solutions that deliver real impact today and serve as foundations for future growth. Bold ambition. Practical action. Endless possibilities.As a member of the IT team, the Sr. Associate, IT (Security)...
-
Security Engagement Specialist
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia AVEVA Full time 800,000 - 1,200,000 per yearAVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life – such as energy, infrastructure, chemicals and minerals – safely, efficiently and more sustainably.We're the first software business in the world to have our sustainability targets validated by the SBTi, and...