Job Description
Leadership:
- Lead and mentor team of security specialist and SMEs to ensure effective execution of security assurance activities
Strategy and Planning:
- Develop, implement, and maintain a comprehensive security assurance strategy tailored to companies operating environment, risk profile, industry and regulatory standard
- Collaborate with senior management to establish security objectives aligned with the digital bank's business goals
Regulatory Compliance:
- Stay current with local regulations and guidelines issued by our bank client and other relevant authorities pertaining to cybersecurity, data privacy, and financial industry security
- Perform periodic review and provide assurance to risk management committees and boards on the bank's security practices and policies and its alignment with our bank client's requirements and industry best practices
Thematic Assessments and Review:
- Independent security assessments, penetration testing, lead red team and compromise assessments to evaluate the effectiveness of security controls
- Collaborate with internal and external auditors to support in providing compliance with regulatory requirements
Technical Assessments:
- Strong understanding on Cloud, DevOps, Application Security, and related control landscape.
- Good to have prior experience in conducting and reviewing Penetration Tests as well configuration reviews
Vendor and Third-Party Security:
- Evaluate and manage the security practices of third-party vendors and partners, ensuring they meet local regulatory expectations on thematic basis
Requirements
- Bachelors Degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Relevant certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), OSCP or industry-specific certifications related to with a focus on the financial industry in Malaysia
- 10 years of work experience with a minimum of 3 years experience onassessing and/or implementing local cybersecurity regulations, guidelines, and standards, including those issued by our bank client and NIST
- Proficiency in security tools, technologies, and risk assessment methodologies
- Excellent communication skills, including the ability to communicate effectively with regulators and senior management
- Strong leadership and collaboration abilities in cross-functional and multicultural environments
- Analytical mindset with the ability to tailor security strategies