Group Head IT Security

RHB Banking Group

Selangor

On-site

MYR 300,000 - 420,000

Full time

12 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RHB Banking Group seeks a senior IT Security leader to formulate and execute a comprehensive Group IT Security strategy across the organisation and regional offices, ensuring a secure, resilient IT environment that meets regulatory requirements and supports business goals.

The role provides governance, incident readiness, security architecture oversight, and risk management, advising the Board and regulators, while driving a risk-based security program and leading budget, vendor relations, and

Qualifications

  • Master's or bachelor's degree in CS/IT or related discipline.
  • Professional certifications CISSP, CISM, CISA or ISMS-related certification.
  • Minimum 10–15 years IT/security experience, with at least 10 years in a senior leadership role.
  • Proven experience engaging Boards, regulators, and senior executives on cyber security matters.
  • Strong leadership, stakeholder management and communication skills.

Responsibilities

  • Define and evolve the Group IT Security strategy, roadmap, and target maturity model.
  • Provide independent IT security and risk advisory to the Group CTO, Senior Management, Board and regulators.
  • Establish, maintain and enforce Group IT Security policies, standards, and frameworks.
  • Champion security culture across technology and business stakeholders.
  • Oversee IT security risk identification, assessment, treatment and reporting.
  • Act as primary liaison for regulators, auditors and assessors; remediate audit issues.
  • Oversee cyber security operations, threat monitoring, detection, and response.
  • Ensure security-by-design for new systems and major changes (VA/PT).
  • Govern regional offices’ security controls and alignment with Group standards.
  • Lead IT Security budget, vendor relations, and talent development.

Skills

Leadership
Strategic IT security
Regulatory compliance
Board communication
Risk management

Education

Master's or Bachelor's Degree in Computer Science / Information Technology or related discipline
CISSP
CISM
CISA
ISMS / Information Security Management certification

Job description

  • Set the overall direction by formulating and executing a comprehensive Group IT Security strategy for RHB Banking Group (including regional offices), ensuring a secure, resilient, and risk-minimised IT environment that supports business objectives and complies with all applicable regulatory, legal and industry requirements
  • The role is accountable for Group-wide cyber security governance, technology controls, incident readiness, and security culture, while providing strategic advisory to the Board, senior management and regulators
Overall Responsibility
  • Set the overall direction by formulating and executing a comprehensive Group IT Security strategy for RHB Banking Group (including regional offices), ensuring a secure, resilient, and risk-minimised IT environment that supports business objectives and complies with all applicable regulatory, legal and industry requirements
  • The role is accountable for Group-wide cyber security governance, technology controls, incident readiness, and security culture, while providing strategic advisory to the Board, senior management and regulators
Key Responsibilities
2.1 Strategy, Governance & Leadership
  • Define, own and continuously evolve the Group IT Security strategy, roadmap, and target maturity model, aligned with business priorities and regulatory expectations
  • Provide independent, strategic IT security and risk advisory to the Group CTO, Senior Management, Board and relevant committees to enable informed risk-based decisions
  • Establish, maintain and enforce Group IT Security policies, standards, and frameworks, ensuring consistent adoption across Head Office and regional offices
  • Champion and cultivate a strong security and compliance culture across technology and business stakeholders
2.2 Risk Management & Regulatory Compliance
  • Ensure Group compliance with all applicable regulatory, statutory and supervisory requirements related to information security and technology risk
  • Oversee IT security risk identification, assessment, treatment, and reporting, ensuring clear visibility of residual risk to senior stakeholders
  • Act as the primary technology security liaison for regulators, auditors, and independent assessors, including audit issue remediation and closure
2.3 Cyber Security Operations & Incident Management
  • Provide executive oversight of cyber security operations, including threat monitoring, detection, hunting and response capabilities
  • Serve as the primary control and escalation point for significant cyber and information security incidents, ensuring timely decision-making, communication, and recovery
  • Ensure a robust, tested, and continuously improved Cyber Incident Response Plan, supported by 24x7 Security Operations Centre (SOC) capabilities
2.4 Security Architecture & Technology Controls
  • Ensure the design, implementation and effectiveness of defence-in-depth security controls across network, endpoint, application, identity and data layers
  • Provide strategic oversight of security capabilities including (but not limited to):
    • Network and perimeter security (firewalls, IPS, WAF, NAC)
    • Endpoint and workload protection (EDR, XDR, anti-malware)
    • Identity and access management (IGA, SSO, PAM)
    • Data protection (DLP, encryption, MDM)
    • Threat detection and response platforms (SIEM, SOAR)
  • Act as the security gatekeeper for new systems and major changes, ensuring security-by-design through architecture review, assurance, and testing (VA/PT)
2.5 Regional & Group Oversight
  • Provide governance, oversight and assurance to ensure regional offices’ security controls, operations, and maturity are aligned with Group standards and risk appetite
  • Drive consistency while accommodating justified local regulatory or operational requirements
2.6 Financial, Vendor & Talent Management
  • Accountable for IT Security budget planning and optimisation, ensuring effective use of CAPEX and OPEX to support strategic priorities
  • Maintain strong relationships with security principals, vendors, and partners to stay abreast of emerging threats, technologies, and industry trends
  • Lead resource planning, succession, and talent development, building a high-performing and future-ready IT Security organisation
Key Interfaces
  • Board and Board Committees
  • Group CTO and Senior Management
  • CISO
  • Group Technology Leadership and Architecture Committees
  • Regulators, auditors and external assessors
  • Regional CIO / Technology Heads
Requirements (Qualification / Experience / Skills)
4.1 Education & Professional Certifications
  • Master's Degree or Bachelor's Degree in Computer Science, Information Technology, or related discipline
  • Professional certifications (mandatory / strongly preferred):
    • CISSP
    • CISM
    • CISA
    • ISMS / Information Security Management related certification
4.2 Experience
  • Minimum 10 – 15 years of IT / Information Security experience, preferably within the Financial Services Industry
  • At least 10 years in a senior leadership or management role overseeing enterprise-wide security functions
  • Proven experience engaging Boards, regulators, and senior executives on technology risk and cyber security matters
4.3 Skills & Competencies
  • Strong enterprise-level understanding of IT security, cyber risk, and regulatory compliance
  • Excellent leadership, stakeholder management, and communication skills
  • Strong analytical, decision-making, and problem-solving capabilities
  • Ability to balance security, compliance, and business enablement in a complex, regulated environment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Group Head Information Security, SVP
Group Head Information Security, SVP

RHB Banking Group • Kuala Lumpur

On-site
MYR 320,000 - 520,000
Group Head of IT Security
Group Head of IT Security

MindMerge Consulting • Kuala Lumpur

On-site
MYR 400,000 - 480,000
IT Security Governance
IT Security Governance

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Head, Cyber Risk Management
Head, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Department Head, IT Security, Information Technology & Services
Department Head, IT Security, Information Technology & Services

Agrobank • Kuala Lumpur

On-site
MYR 300,000 - 520,000
Group IT Security Leader: Strategy, Risk & Cyber Defense
Group IT Security Leader: Strategy, Risk & Cyber Defense

RHB Banking Group • Selangor

On-site
MYR 300,000 - 420,000
Junior Security Solutions Consultant
Junior Security Solutions Consultant

UniQ Consulting & Services Sdn Bhd • Petaling Jaya

On-site
MYR 60,000 - 120,000
Associate Manager, Tech & Cyber Risk (Governance Risk & Compliance)
Associate Manager, Tech & Cyber Risk (Governance Risk & Compliance)

Permodalan Nasional Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Executive, Cybersecurity & IT Governance
Senior Executive, Cybersecurity & IT Governance

Asia Recruit (Permanent, Contract, & Executive Recruitment) • Shah Alam

On-site
MYR 80,000 - 120,000
Information Security Manager
Information Security Manager

EPOS • Kuala Lumpur

On-site
MYR 120,000 - 180,000