Chief Information Security Officer

Doit

Petaling Jaya

Hybrid

MYR 300,000 - 520,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

doit Holdings is seeking a CISO who will own information security and technology risk for its regulated investment platform in Malaysia. You will lead the development of risk frameworks, policies, and controls, and oversee security operations including monitoring, vulnerability management, and incident response.

The role requires 8+ years in information security with 5+ in financial services, CISSP/CISM/CISA, and ISO/IEC 27001 implementation expertise.

Qualifications

  • Requires deep information security background with 8+ years in the field, 5+ in a regulated sector.
  • CISSP, CISM or CISA certifications required.
  • Strong understanding of the SC Guidelines on Technology Risk Management.
  • Experience in cyber security, resilience, cloud and third-party risk.
  • ISO/IEC 27001 implementation through to certification.
  • Degree in CS/IT or equivalent.

Responsibilities

  • Oversee day-to-day technology risk and deliver the board's cyber security strategy.
  • Develop and maintain technology risk, cyber security frameworks, policies and risk appetite.
  • Run security operations including monitoring, vulnerabilities, patch management, access control and data protection.
  • Own incident response from detection to recovery and reporting to the SC.
  • Lead the platform through independent technology validation for registration.
  • Drive ISO/IEC 27001 scoping to certification.
  • Deliver annual cyber security awareness across management and staff.

Skills

Information security
Regulatory compliance
Risk management
Cloud security
Security governance

Education

Degree in Computer Science / Information Technology
CISSP
CISM
CISA
ISO/IEC 27001 Lead Implementer
CRISC
Lead Auditor
SC/BNM technology examination experience

Job description

We are focused on reinventing how people spend, save, invest, exchange, travel, and more. Our objective is to build tools that will help people get more from their money and become an expert at ease. We believe AI will help make finance smart, assessible and safe.

We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few. We have teams working around the world, with over 20 nationalities and growing from our offices and remotely. Join us and build a better future for our society.

In 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, it’s the leading insurance platform in Southeast Asia.

The Role

The CISO will own information security and technology risk for doit Holdings, our regulated investment platform in Malaysia, and will be the person the board names as responsible for technology risk under the Securities Commission's Guidelines on Technology Risk Management. Nothing exists yet. The framework, the controls, the monitoring and the evidence all have to be built, and they have to hold up to an independent assessment before the platform can be registered.

What you will be doing
  • Hold the board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.
  • Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.
  • Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
  • Own incident response from detection through recovery, including the report to the SC on the day an incident occurs.
  • Take the platform through the independent technology validation that gates registration, and close what it finds.
  • Take ISO/IEC 27001 from scoping through to certification.
  • Deliver the annual cyber security awareness programme across the board, senior management and staff.
What you will need
  • Deep information security background, with at least 8 years in the field including 5 in financial services or another regulated sector.
  • At least one of CISSP, CISM or CISA. This is a requirement. These are the certifications the SC names as acceptable for the external party who assesses technology risk controls, and the officer who owns those controls should not sit below the standard set for the officer who audits them.
  • Deep command of the SC's Guidelines on Technology Risk Management, operationalised rather than restated.
  • Real depth in cyber security, operational resilience, and cloud and third-party risk.
  • ISO/IEC 27001 implementation experience through to certification.
  • A degree in computer science, information technology, information security or a cognate discipline, and able to meet the SC's fit and proper criteria.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor, CRISC or CCSP, or experience of an SC or BNM technology examination, is useful.
  • Hands‑on operating style. Able to review the controls, run the simulation and close the gaps personally.
Location

This is a hybrid role. You are expected to work from our local office at least 3 days per week, with the remaining days offering flexibility to work remotely.

Candidates should be based in, or able to work from, the location where the role is advertised.

Language

English is our main working language across global teams. Strong English communication is required.

Interview Process

Our process is designed to move fast:

1. Introductory conversation

2. Technical and regulatory deep dive

3. CEO / final round

For strong candidates, we aim to complete the process and make an offer within 1 week from the start of the interview process. Candidates who complete assessments quickly will be prioritized.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Technology Officer
Chief Technology Officer

Doit • Petaling Jaya

Hybrid
MYR 350,000 - 700,000
Chief Executive Officer
Chief Executive Officer

Doit • Petaling Jaya

Hybrid
MYR 250,000 - 800,000
Compliance Officer
Compliance Officer

Doit • Petaling Jaya

Hybrid
MYR 120,000 - 190,000
Strategic CISO: Tech Risk & Compliance Lead
Strategic CISO: Tech Risk & Compliance Lead

Doit • Petaling Jaya

Hybrid
MYR 300,000 - 520,000
Senior Information Security Manager
Senior Information Security Manager

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Founder's Associate
Founder's Associate

Doit • Petaling Jaya

Hybrid
MYR 60,000 - 90,000
Hybrid work model
Malaysia office
Principal Software Engineer
Principal Software Engineer

Doit • Petaling Jaya

Hybrid
MYR 180,000 - 300,000
Lead Software Engineer
Lead Software Engineer

Kira • Petaling Jaya

Hybrid
MYR 180,000 - 360,000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Product Engineer - AI Investing App
Product Engineer - AI Investing App

Doit • Petaling Jaya

Hybrid
MYR 60,000 - 100,000