Turn this role into an interview — a resume and cover letter built around what this employer wants.
doit Holdings is seeking a CISO to own information security and technology risk for our regulated investment platform in Malaysia. You will align board-directed cyber strategy with robust risk management and hold oversight of security controls.
You will build and implement the technology risk framework, monitoring, incident response, and certification processes (ISO/IEC 27001), while leading awareness and assurance across the organization.
Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
The CISO will own information security and technology risk for doit Holdings, our regulated investment platform in Malaysia, and will be the person the board names as responsible for technology risk under the Securities Commission's Guidelines on Technology Risk Management. Nothing exists yet. The framework, the controls, the monitoring and the evidence all have to be built, and they have to hold up to an independent assessment before the platform can be registered.
This is a hybrid role. You are expected to work from our local office at least 3 days per week, with the remaining days offering flexibility to work remotely.
Candidates should be based in, or able to work from, the location where the role is advertised.
English is our main working language across global teams. Strong English communication is required.
For strong candidates, we aim to complete the process and make an offer within 1 week from the start of the interview process. Candidates who complete assessments quickly will be prioritized.