Chief Information Security Officer

Kira Incorporated

Selangor

Hybrid

MYR 200,000 - 320,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

doit Holdings is seeking a CISO to own information security and technology risk for our regulated investment platform in Malaysia. You will align board-directed cyber strategy with robust risk management and hold oversight of security controls.

You will build and implement the technology risk framework, monitoring, incident response, and certification processes (ISO/IEC 27001), while leading awareness and assurance across the organization.

Qualifications

  • At least 8 years in information security, with 5+ years in financial services or a regulated sector.
  • CISSP, CISM or CISA certification is required.
  • Deep knowledge of the SC's Guidelines on Technology Risk Management.
  • Experience in cyber security, operational resilience, cloud and third-party risk.
  • ISO/IEC 27001 implementation through to certification.
  • Degree in computer science / information technology / information security.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor, CRISC or CCSP, or SC/BNM technology examination is useful.
  • Hands-on operating style; able to review controls, run simulations, and close gaps.

Responsibilities

  • Hold board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.
  • Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.
  • Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
  • Own incident response from detection through recovery, including the report to the SC on the day an incident occurs.
  • Take the platform through the independent technology validation that gates registration, and close what it finds.
  • Take ISO/IEC 27001 from scoping through to certification.
  • Deliver the annual cyber security awareness programme across the board, senior management and staff.

Skills

Information security
Cyber security
Cloud security
Regulatory risk
Operational resilience

Education

Degree in computer science / IT / information security

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

The CISO will own information security and technology risk for doit Holdings, our regulated investment platform in Malaysia, and will be the person the board names as responsible for technology risk under the Securities Commission's Guidelines on Technology Risk Management. Nothing exists yet. The framework, the controls, the monitoring and the evidence all have to be built, and they have to hold up to an independent assessment before the platform can be registered.

What you will be doing
  • Hold the board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.
  • Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.
  • Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
  • Own incident response from detection through recovery, including the report to the SC on the day an incident occurs.
  • Take the platform through the independent technology validation that gates registration, and close what it finds.
  • Take ISO/IEC 27001 from scoping through to certification.
  • Deliver the annual cyber security awareness programme across the board, senior management and staff.
What you will need
  • Deep information security background, with at least 8 years in the field including 5 in financial services or another regulated sector.
  • At least one of CISSP, CISM or CISA. This is a requirement. These are the certifications the SC names as acceptable for the external party who assesses technology risk controls, and the officer who owns those controls should not sit below the standard set for the officer who audits them.
  • Deep command of the SC's Guidelines on Technology Risk Management, operationalised rather than restated.
  • Real depth in cyber security, operational resilience, and cloud and third-party risk.
  • ISO/IEC 27001 implementation experience through to certification.
  • A degree in computer science, information technology, information security or a cognate discipline, and able to meet the SC's fit and proper criteria.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor, CRISC or CCSP, or experience of an SC or BNM technology examination, is useful.
  • Hands-on operating style. Able to review the controls, run the simulation and close the gaps personally.
Location

This is a hybrid role. You are expected to work from our local office at least 3 days per week, with the remaining days offering flexibility to work remotely.

Candidates should be based in, or able to work from, the location where the role is advertised.

Language

English is our main working language across global teams. Strong English communication is required.

Interview Process
  1. Introductory conversation
  2. Technical and regulatory deep dive
  3. CEO / final round

For strong candidates, we aim to complete the process and make an offer within 1 week from the start of the interview process. Candidates who complete assessments quickly will be prioritized.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Officer
Compliance Officer

Kira Incorporated • Selangor

Hybrid
MYR 150,000 - 210,000
IT Information Security Management (ISM) / CyberSecurity Officer
IT Information Security Management (ISM) / CyberSecurity Officer

Nationgate Solution (M) Sdn Bhd • Seberang Perai

On-site
MYR 90,000 - 150,000
Senior Executive, IT Governance, Risk and Compliance
Senior Executive, IT Governance, Risk and Compliance

Revenue Group • Selangor

On-site
MYR 90,000 - 130,000
Senior IT Risk & Compliance Specialist
Senior IT Risk & Compliance Specialist

MOL AccessPortal • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Vice President, Cybersecurity Strategy, Governance & Projects
Vice President, Cybersecurity Strategy, Governance & Projects

Bursa Malaysia Berhad • Kuala Lumpur

On-site
MYR 420,000 - 560,000
Head of IT Security
Head of IT Security

Oxydata Software • George Town

On-site
MYR 240,000 - 420,000
CISO @ Assistant General Manager, Information Security
CISO @ Assistant General Manager, Information Security

Aeon Credit Service • Kuala Lumpur

On-site
MYR 60,000 - 120,000
Manager, IT & Cybersecurity Risk
Manager, IT & Cybersecurity Risk

Hong Leong Investment Bank • Petaling Jaya

On-site
MYR 120,000 - 180,000
Assistant General Manager-General Manager, Group Cybersecurity - Technology Governance
Assistant General Manager-General Manager, Group Cybersecurity - Technology Governance

IOI Properties Group • Putrajaya

On-site
MYR 300,000 - 520,000
IT Security Assistant Manager / Manager
IT Security Assistant Manager / Manager

NTT DATA Payment Services • Subang Jaya

On-site
MYR 90,000 - 150,000