Assistant Manager, Technology Security Operations

Touch 'n Go Group

Kuala Lumpur

Hybrid

MYR 120,000 - 180,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work arrangement
Flexible hours
Unlimited pantry fruits, snacks anddr"

Job summary

Touch ‘n Go Group in Kuala Lumpur is seeking a Technology Risk Manager to own the centralized risk register, drive audits, and oversee IT/cyber remediation. You will coordinate with Internal/External Audit, regulators, and risk owners to ensure timely actions and evidence collection.

The role requires 5+ years in technology risk or related fields, strong analytical and communication skills, and a hybrid work arrangement. Benefits include medical coverage and flexible policies.

Qualifications

  • Bachelor's degree or equivalent in IT, cybersecurity, or risk management.
  • Professional certifications such as CISA, CISM, CRISC, CISSP, CGEIT or ISO 27001 Lead Auditor/Lead Implementer are desirable.
  • Minimum 5 years in Technology Risk Management, Cybersecurity Governance, IT Audit, IT Compliance, or related fields.

Responsibilities

  • Own centralized risk register across technology and cyber domains.
  • Lead risk assessments for IT infrastructure, cloud, and security controls.
  • Coordinate audits and regulatory assessments with multiple stakeholders.
  • Translate findings into actionable remediation plans with owners.
  • Monitor remediation progress and ensure timely closure.
  • Prepare governance reports and dashboards for senior management.

Skills

Stakeholder management
Communication skills
Analytical thinking
Problem-solving
Coordination
Report writing
Presentation skills
Influence across teams
organizational skills

Education

Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Risk Management, or a related discipline
CISA
CISM
CRISC
CISSP
ISO 27001 Lead Auditor/Lead Implementer

Job description

We fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion – LEAP

We are a culture that empowers everyone to innovate and create solutions that will leave a positive impact on our communities and our nation, Touch ‘n Go will always be here to inspire our talents to grow as leaders and innovators giving you the power to make a difference

What would you do:
Technology & Cyber Risk Management
  • Own and maintain the centralized Technology & Cyber Risk Register, ensuring risks are accurately identified, assessed, documented, monitored, and reported
  • Perform risk assessments across IT infrastructure, applications, cloud environments, cybersecurity controls, and technology operations
  • Define and maintain risk ratings, risk ownership, mitigation strategies, compensating controls, and risk acceptance records
  • Ensure technology and cyber risks are managed in accordance with internal governance standards and regulatory requirements, including NACSA Arahan No. 5 and Bank Negara Malaysia's Risk Management in Technology (RMiT) framework
  • Facilitate periodic risk reviews with stakeholders and ensure risk treatment plans are implemented and tracked to completion
  • Identify emerging technology and cyber threats and assess their potential impact on the organization
Audit & Regulatory Coordination
  • Act as the primary liaison and coordinator for all technology and cybersecurity-related audits, reviews, and regulatory assessments
  • Coordinate audit activities involving Internal Audit, External Audit, regulators, and other assurance functions
  • Manage requests for information, evidence collection, documentation reviews, and audit responses
  • Translate audit observations and regulatory findings into actionable remediation plans with clear ownership and accountability
  • Monitor remediation progress and ensure findings are resolved within agreed timelines
  • Maintain comprehensive records and evidence repositories to support audit readiness and regulatory compliance
  • Track all audit and regulatory findings through to formal closure and validation
IT & Cyber Issue Management
  • Establish and maintain a centralized IT & Cyber Issue Register encompassing audit findings, vulnerability assessment results, penetration testing findings, security alerts, operational issues, and control weaknesses
  • Drive the end-to-end issue management lifecycle, including identification, assessment, assignment, tracking, validation, and closure
  • Ensure issue owners are accountable for implementing effective remediation actions within established timelines
  • Monitor remediation Service Level Agreements (SLAs) and escale overdue, high-risk, or unresolved issues to management
  • Validate closure evidence to ensure issues have been effectively remediated and associated risks adequately mitigated
  • Identify recurring issues, systemic weaknesses, and trends to support continuous improvement initiatives
Cross-Functional Coordination
  • Serve as the central coordination point between IT Operations, Security Operations, technology teams, vendors, and service providers
  • Ensure effective collaboration and communication across stakeholders involved in risk mitigation and issue remediation activities
  • Manage cross-functional dependencies and facilitate timely resolution of technology and cybersecurity issues
  • Drive proactive follow-up and governance oversight to prevent issues from being overlooked or delayed
  • Support the resolution of complex issues requiring engagement across multiple functions
Governance, Risk & Compliance (GRC) Enablement
  • Act as the key interface between technical teams and governance functions, including Risk Management, Compliance, and Audit
  • Translate technical findings and cybersecurity concerns into meaningful business risk impacts for management and governance stakeholders
  • Interpret regulatory, risk, and compliance requirements and coordinate implementation activities with technology teams
  • Ensure consistency and traceability across risk registers, issue registers, audit findings, and remediation plans
  • Support governance reviews, risk assessments, policy compliance activities, and control effectiveness reviews
Governance Reporting & Stakeholder Management
  • Prepare and present regular reports and dashboards on technology risks, cybersecurity issues, audit findings, remediation progress, and compliance status
  • Provide meaningful analysis and recommendations to support risk-based decision-making by senior management and governance committees
  • Support risk prioritization, mitigation planning, and risk acceptance discussions
  • Deliver accurate, timely, and consistent reporting to the Head of IT Security, CTO, Risk Committees, and other governance forums
  • .Escalate significant risks, control deficiencies, and remediation delays to appropriate management levels where required
Who should join us:
  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Risk Management, or a related discipline
  • Professional certifications such as CISA, CISM, CRISC, CISSP, CGEIT, or ISO 27001 Lead Auditor/Lead Implementer are highly desirable
  • Minimum 5 years of experience in Technology Risk Management, Cybersecurity Governance, IT Audit, IT Compliance, Information Security, or related disciplines
  • Knowledge of technology risk management and cybersecurity governance pratice
  • Familiarity with NACSA Arahan No. 5, BNM RMiT, ISO 27001, NIST Cybersecurity Framework, and related industry standards
  • Strong stakeholder management and communication skills
  • Excellent analytical, problem-solving, and coordination abilities
  • Strong report writing and presentation skills
  • Ability to influence stakeholders and drive accountability across technical and non-technical teams.
  • Strong organizational skills with the ability to manage multiple priorities simultaneously
  • Hybrid work arrangement and flexi hours.
  • Unlimited office pantry fruits, snacks and drinks.
  • Mobile and broadband subscription reimbursement.
  • Flexibility to opt dependents coverage (spouse, child, parents or parents-in-law) for outpatient medical benefits.
  • Additional leave including family leave and paid care leave to care for family members.
  • Medical coverage including dental, optometrist, mental care, maternity, registered
  • Traditional Chinese Medicine (“TCM”) and Chiropractic.
  • Corporate membership discount and many more to explore.

We believe that you have what it takes to fit into the Touch ‘n Go family and help revolutionize the Fintech industry by paving the way to a cashless society.

Touch ‘n Go is an organization that strives to provide Equal Opportunity Employment, based on merit, qualifications, capabilities, and calibre. It is Touch ‘n Go’s policy to not discriminate based on age, race, religion, colour or other personal status, identity or characteristics. Fair Opportunity is Our Value and Practice. Please advise us of any accommodations you may need by e-mailing: careers@touchngo.com.my

Note: Only shortlisted candidates will be contacted.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead, Commercial Development and Growth
Lead, Commercial Development and Growth

Touch 'n Go Group • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Unlimited pantry fruits, snacks &
Mobile & broadband reimbursement
Leave benefits including family & care
Assistant Manager, Product Management
Assistant Manager, Product Management

Touch 'n Go Group • Kuala Lumpur

On-site
MYR 180,000 - 210,000
Hybrid work
Flexible hours
Mobile reimbursement
+4
Head, Sustainability
Head, Sustainability

TNG Digital • Kuala Lumpur

On-site
MYR 260,000 - 460,000
Monthly eWallet allowance
1% employer EPF contribution (years 1–
Office pantry & beverages
+3
Assistant Manager, Legal
Assistant Manager, Legal

Touch 'n Go Group • Kuala Lumpur

Hybrid
MYR 180,000 - 320,000
Unlimited pantry fruits
Mobile and broadband reimbursement
Flexible/hybrid hours
+1
Senior Associate, Product Management
Senior Associate, Product Management

Touch 'n Go Group • Kuala Lumpur

On-site
MYR 90,000 - 140,000
Unlimited pantry fruits snacks & meals
Mobile and broadband reimbursement
Flexible dependent-coverage options
+2
Product Manager - Remittance
Product Manager - Remittance

TNG Digital Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Monthly eWallet allowance
EPF employer contribution 1%
Pantry access
+5
Lead, Settlement Management
Lead, Settlement Management

Touch 'n Go Group • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Unlimited pantry fruits and drinks
Mobile and broadband reimbursement
Flexi working hours
+2
Senior Specialist, Business Project Management Office (Fintech)
Senior Specialist, Business Project Management Office (Fintech)

TNG Digital Sdn Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Medical coverage
Extra leave for family
Monthly lifestyle allowance via TNG eW
+2
Remittance - Head, Compliance
Remittance - Head, Compliance

TNG Digital • Kuala Lumpur

On-site
MYR 400,000 - 800,000
Medical coverage
Lifestyle allowance
Mobile and broadband reimbursement
Specialist, Incident Management
Specialist, Incident Management

TNG Digital • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Medical coverage
Extra leave for family and caregiving
Monthly lifestyle allowance via TNG eW
+2