Senior Information Security Management Specialist

1 day ago


Malaysia Near Shore Cyber Full time 120,000 - 240,000 per year


SENIOR INFORMATION SECURITY MANAGEMENT SPECIALIST 

Location: Kuala Lumpur, Malaysia (Remote/Hybrid) 

Reports to: Senior Director, Information Security 

Business: Global Data Centers 

ROLE SUMMARY 

Our client, a global data center provider, is hiring a Senior Information Security Management Specialist to own and mature the Information Security Management System (ISMS) across multiple frameworks, including ISO 27001, NIST, PCI DSS, GDPR and NIS2. 

This is a senior governance, risk and compliance role with clear responsibility for ISMS operations, risk management, audit and vulnerability oversight. The successful candidate will use automation and AI‑enabled tools to scale the security program rather than relying on manual effort alone. This is not a SOC analyst role; it is a senior GRC/ISMS leadership position.

KEY RESPONSIBILITIES 
1) Security Governance and ISMS Ownership 

·       Own the ISMS for the data center environment and keep it aligned with ISO 27001, NIST and internal policies 

·       Maintain and continuously improve the security policy, standard and procedure library 

·       Use AI‑assisted tools (policy assistants, regulatory mapping, documentation automation) to speed up updates and improve consistency 

2) Risk Management and Systems Authorization 

·       Lead security risk assessments for key systems, projects and suppliers and maintain a prioritized risk register 

·       Support "authorization to operate" decisions by providing structured risk analysis and evidence against standards and regulations 

·       Use dashboards and AI‑enabled analytics to surface top risks, trends and control gaps for senior leadership 

3) Audit, Certification and Regulatory Gap Assessments 

·       Plan, coordinate and support internal and external audits, including ISO 27001 certification and customer assessments 

·       Run regulatory and framework gap assessments across ISO 27001, NIST, PCI DSS, GDPR, NIS2 and similar regimes, with clear remediation plans 

·       Use automation and AI (for example, document summarization and intelligent sampling) to assemble evidence packs and track findings 

4) Vulnerability and Technical Risk Oversight 

·       Govern the vulnerability management program: define scope, SLAs, escalation and reporting; ensure the process goes beyond scanning and drives real remediation 

·       Partner with infrastructure and application teams to translate technical findings into clear business impact and remediation actions 

·       Use AI‑driven tools to combine vulnerabilities, asset criticality and threat intelligence into risk‑based remediation priorities 

5) Security Awareness and Culture 

·       Own the security awareness agenda: define the annual plan, run targeted campaigns and measure impact via metrics such as phishing results, training completion and policy understanding 

·       Educate teams on safe and compliant use of AI, including data handling, prompt hygiene, shadow AI risk and regulatory alignment 

·       Work with HR, Legal and Engineering to embed security and AI risk expectations into onboarding, objectives and leadership communications 

6) Data and AI Use in Security 

·       Champion responsible use of AI across the security program, ensuring confidentiality, integrity and compliance when using AI tools and platforms 

·       Help define guardrails for enterprise AI use (what data can be shared, how outputs are validated, how misuse is detected and managed) 

·       Evaluate AI‑enabled security products (GRC automation, continuous control monitoring, anomaly detection, etc.) and recommend adoption where they improve effectiveness or efficiency 

7) Stakeholder Engagement and Leadership 

·       Act as a key point of contact for technology, operations, compliance, legal, internal audit and major customers 

·       Present risk posture, audit status and remediation progress in concise, business‑oriented language to senior stakeholders 

·       Mentor junior security and GRC staff, including nearshore and remote team members, to build a strong pipeline of talent 

REQUIRED EXPERIENCE AND SKILLS 
·    8–10+ years of experience in information security or cybersecurity with a strong focus on governance, risk and ISMS management 
·       Demonstrated experience running or heavily contributing to an ISO 27001 ISMS (design, implementation, certification or surveillance audits) 
·       Advanced familiarity with: 
·       ISMS operations, audits and gap assessments 
·       Risk registers, mitigation plans and risk reporting 
·       Security awareness and cultural change programs 
·       Proven ability to operate in complex multi‑regulatory environments, ideally with exposure to NIST, PCI DSS, GDPR and NIS2 
·       Practical experience with vulnerability management tools and processes (governance and oversight, not just scanning) 
·       Comfortable using AI‑enabled and automated tools (policy assistants, GRC platforms with AI features, analytics dashboards or security "copilots") 
·       Strong communication skills and the ability to influence senior technical and non‑technical stakeholders 
·       Experience leading or coordinating remote and distributed teams is preferred 
PREFERRED CERTIFICATIONS 

·       ISO/IEC 27001 Lead Auditor or Lead Implementer 

·       One or more of: CISM, CISSP, CISA 

·       Additional credentials in risk, cloud security, or privacy are a plus 



  • Malaysia NodeFlair Full time

    **Job Summary**: **Salary** RM10,000 - RM12,999 / Monthly **Job Type** **Seniority** **Years of Experience** Information not provided Roles and Responsibilities - Understand and imbibe current SOC process - Perform quality assessment on SOC operations being performed as per existing process - Record and deviations identified into tracking...


  • Kuala Lumpur, AIA Digital+ Malaysia AIA Group Full time 120,000 - 240,000 per year

    Are you ready to shape a better tomorrow?AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.If you are hungry and driven to play an active role in shaping a...


  • Malaysia Amazon Data Services Malaysia Sdn. Bhd. Full time

    Completion of tertiary level education - Proficiency with MS Office - Read, write, and speak business level English language - Good report writing skills Amazon Web Services (AWS) is looking to hire a highly motivated, customer-obsessed individual to provide hands-on support to our Data Center Infrastructure Operations across SIN Cluster. (Data Center...


  • Malaysia - KL Eco City FWD Group Full time 120,000 - 180,000 per year

    About FWD GroupFWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD's customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler insurance experience. Established in 2013, the...

  • Senior Lecturer

    1 day ago


    Malaysia Management & Science University Full time 80,000 - 120,000 per year

    RESPONSIBILITIESTeaching & LearningUndertake teaching and teaching-related duties such as design, preparation, and development of teaching materials; conduct classes/lectures, tutorials, and practicals; consultation with students, invigilation, marking, and assessment.Participate and contribute to high-quality programme and curriculum developmentPlan and...

  • Security Analyst

    2 weeks ago


    Malaysia Ensign InfoSecurity Full time

    Ensign is hiring ! Evaluates, tests, monitors and maintains information systems (IS) and cyber security policies, procedures and systems I Creates, implements and oversees identity management systems to meet specific security needs and complex compliance standards | Ensures that IS and cyber security plans, controls, processes, standards, policies and...


  • Bandar Sunway, Selangor, Malaysia Pixlr Group Full time 120,000 - 240,000 per year

    We are seeking an experienced and skilled Senior IT Security Engineer to play a crucial role in safeguarding our organization's information systems and ensuring the confidentiality, integrity, and availability of our digital assets. If you possess strong technical expertise in cybersecurity, hands-on experience with security tools and technologies, and a...


  • Senai, Johor, Malaysia Hirehub Management Full time 80,000 - 120,000 per year

    Company Background:Our client is a worldwide top 50 Electronics Manufacturing Services (EMS) company, delivering improved flexibility, cost efficiency, and innovation power through the value chain. Their HQ is located at Norway, and have a strong local presence in all regions such as, Norway, Sweden, Denmark, Lithuania, Germany, Poland, the Czech Republic,...


  • Kuala Lumpur, MY-AIA Malaysia AIA Group Full time 1,500,000 - 2,500,000 per year

    At AIA we've started an exciting movement to create a healthier, more sustainable future for everyone.As pioneering innovators for over 100 years, we're now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live Healthier,...


  • Malaysia GENO Management Full time

    Position : Technical Sales Support Specialist Salary : Up to RM 5,000 (Exclude Allowances) Location : Desa Aman Puri, Kepong Working Days / Time : 8.30am - 5.30pm / Mon - Fri **Job Scope** - This role requires to use the technical expertise to better connect with the customer by working along with the sales team. It also requires to liaison with the R&D...