Group Head of IT Security

MindMerge Consulting

Kuala Lumpur

On-site

MYR 432,000 - 528,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

MindMerge Consulting is seeking a senior leader to define and execute the Group IT Security strategy in Kuala Lumpur, Malaysia. The role encompasses governance, risk management, and cyber security operations, ensuring compliance and an optimal IT environment across regional offices.

The ideal candidate will have a strong background in information security, at least 10 – 15 years of relevant experience, and advanced certifications. The position offers a competitive salary of up to MYR 480,000 per annum, plus allowances and bonuses.

Qualifications

  • Master’s Degree or Bachelor’s Degree in a related discipline.
  • Minimum 10 – 15 years of IT / Information Security experience.
  • Strong enterprise level understanding of IT security and cyber risk.

Responsibilities

  • Define and execute Group IT Security strategy and roadmap.
  • Oversee IT security risk identification, treatment, and reporting.
  • Champion a strong security and compliance culture across teams.

Skills

Leadership
Stakeholder Management
Cyber Security
Regulatory Compliance
Analytical Skills

Education

Master’s Degree or Bachelor’s Degree in Computer Science, Information Technology, or related discipline

Tools

CISSP
CISM
CISA
ISMS

Job description

Kuala Lumpur, Malaysia | Posted on 06/10/2026

  • Specialisation IT Audit / Security / Cybersecurity; IT Infrastructure, Comms, Security
  • Salary Basic up to MYR480,000 per annum; plus allowances & bonuses
  • Country Malaysia
Job Description
Overall Responsibility
  • Set the overall direction by formulating and executing a comprehensive Group IT Security strategy for the Group (including regional offices), ensuring a secure, resilient, and risk minimised IT environment that supports business objectives and complies with all applicable regulatory, legal and industry requirements.
  • The role is accountable for Group wide cyber security governance, technology controls, incident readiness, and security culture, while providing strategic advisory to the Board, senior management and regulators.
Key Responsibilities

1. Strategy, Governance & Leadership

  • Define, own and continuously evolve the Group IT Security strategy, roadmap, and target maturity model, aligned with business priorities and regulatory expectations.
  • Provide independent, strategic IT security and risk advisory to the Group CTO, Senior Management, Board and relevant committees to enable informed risk based decisions.
  • Establish, maintain and enforce Group IT Security policies, standards, and frameworks, ensuring consistent adoption across Head Office and regional offices.
  • Champion and cultivate a strong security and compliance culture across technology and business stakeholders.

2. Risk Management & Regulatory Compliance

  • Ensure Group compliance with all applicable regulatory, statutory and supervisory requirements related to information security and technology risk.
  • Oversee IT security risk identification, assessment, treatment, and reporting, ensuring clear visibility of residual risk to senior stakeholders.
  • Act as the primary technology security liaison for regulators, auditors, and independent assessors, including audit issue remediation and closure.

3. Cyber Security Operations & Incident Management

  • Provide executive oversight of cyber security operations, including threat monitoring, detection, hunting and response capabilities.
  • Serve as the primary control and escalation point for significant cyber and information security incidents, ensuring timely decision making, communication, and recovery.
  • Ensure a robust, tested, and continuously improved Cyber Incident Response Plan, supported by 24x7 Security Operations Centre (SOC) capabilities.

4. Security Architecture & Technology Controls

  • Ensure the design, implementation and effectiveness of defence in depth security controls across network, endpoint, application, identity and data layers.
  • Provide strategic oversight of security capabilities including (but not limited to):
    • Network and perimeter security (firewalls, IPS, WAF, NAC)
    • Endpoint and workload protection (EDR, XDR, anti‑malware)
    • Identity and access management (IGA, SSO, PAM)
    • Data protection (DLP, encryption, MDM)
    • Threat detection and response platforms (SIEM, SOAR)
  • Act as the security gatekeeper for new systems and major changes, ensuring security by design through architecture review, assurance, and testing (VA/PT).

5. Regional & Group Oversight

  • Provide governance, oversight and assurance to ensure regional offices’ security controls, operations, and maturity are aligned with Group standards and risk appetite.
  • Drive consistency while accommodating justified local regulatory or operational requirements.
  • Accountable for IT Security budget planning and optimisation, ensuring effective use of CAPEX and OPEX to support strategic priorities.
  • Maintain strong relationships with security principals, vendors, and partners to stay abreast of emerging threats, technologies, and industry trends.
  • Lead resource planning, succession, and talent development, building a high performing and future ready IT Security organisation.
Requirements
  • Master’s Degree or Bachelor’s Degree in Computer Science, Information Technology, or related discipline
  • Professional certifications (strongly preferred): CISSP, CISM, CISA, ISMS or Information Security Management related certification.
  • Minimum 10 – 15 years of IT / Information Security experience.
  • At least 10 years in a senior leadership or management role overseeing enterprise wide security functions.
  • Proven experience engaging Boards, regulators, and senior executives on technology risk and cyber security matters.
  • Strong enterprise level understanding of IT security, cyber risk, and regulatory compliance.
  • Excellent leadership, stakeholder management, and communication skills.
  • Strong analytical, decision making, and problem solving capabilities.
  • Ability to balance security, compliance, and business enablement in a complex, regulated environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Group Head Information Security, SVP
Group Head Information Security, SVP

RHB Banking Group • Kuala Lumpur

On-site
MYR 320,000 - 520,000
Group Head IT Security
Group Head IT Security

RHB Banking Group • Selangor

On-site
MYR 300,000 - 420,000
Senior Executive, Cybersecurity & IT Governance
Senior Executive, Cybersecurity & IT Governance

Asia Recruit (Permanent, Contract, & Executive Recruitment) • Shah Alam

On-site
MYR 80,000 - 120,000
Head of IT Security
Head of IT Security

Quintus Search • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Manager / Associate Director – Cybersecurity Practice
Senior Manager / Associate Director – Cybersecurity Practice

Accenture Southeast Asia • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Senior IT Manager (Information Security, Risk & Governance)
Senior IT Manager (Information Security, Risk & Governance)

Alphv Recruit • Kuala Selangor

On-site
MYR 180,000 - 260,000
Lead IT Security Policy | Up to RM14K
Lead IT Security Policy | Up to RM14K

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Cybersecurity Project Manager
Cybersecurity Project Manager

Prometric • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Group IT Security Leader: Strategy, Risk & Incidents
Group IT Security Leader: Strategy, Risk & Incidents

MindMerge Consulting • Kuala Lumpur

On-site
MYR 400,000 - 480,000
Senior Manager/ Manager - IT Audit
Senior Manager/ Manager - IT Audit

Genting Plantations Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000