
Enable job alerts via email!
A leading executive search firm in Malaysia is seeking a Technology Risk Guardian to ensure proactive identification and management of technology risks. The ideal candidate will have over 8 years of experience in technology risk or IT audit, with strong communication and stakeholder management abilities. This role is crucial for supporting business objectives while safeguarding information assets and compliance with regulatory standards.
To serve as the independent technology risk guardian for the business, ensuring that technology and information security risks are proactively identified, assessed, and managed within the business's risk appetite. This role is critical for building a resilient technology environment that supports business objectives while safeguarding organization's assets and reputation.
Act as an independent second line of defense, providing robust oversight and constructive challenge to technology and security initiatives across the business.
Review and challenge the technology risk-taking activities of IT, security, and business-led technology projects.
Ensure technology risks are properly evaluated before key decisions are made.
Implement and maintain the Group's technology risk management framework within the business, ensuring it is fit-for-purpose.
Develop and monitor key risk indicators (KRIs) and control metrics to provide a clear view of the technology risk posture.
Facilitate risk and control self‑assessments (RCSAs) and manage the technology risk register.
Serve as a trusted advisor to business leaders, translating complex technology risks into actionable business insights.
Provide pragmatic risk guidance on new technologies, major projects, and third‑party engagements.
Bridge the communication gap between technical teams, business leaders, and senior risk committees.
Ensure compliance with internal technology policies, standards, and relevant external regulations (e.g., SOX, GDPR, NYDFS, etc.).
Prepare and deliver clear, concise, and impactful reports on the health of technology risk management to both business leadership and Group-level risk committees.
Bachelor’s degree in Information Technology, Computer Science, or a related field.
Professional certifications such as CRISC, CISA, CISM, CISSP, or CCSP.
Minimum of 8‑10 years of progressive experience in technology risk, IT audit, or information security, with at least 3 years in a senior or leadership capacity.
Proven experience in developing and implementing risk management frameworks.
Deep understanding of IT governance, infrastructure, application security, and project delivery lifecycle.
Exceptional communication and stakeholder management skills, with the ability to articulate risk concepts to both technical and non‑technical audiences.