Head, Cyber Risk Management

Affin Bank Berhad

Kuala Lumpur

On-site

MYR 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Affin Bank Berhad is seeking a Cyber Risk Management lead to oversee technology risk, ensuring compliance with Bank Negara Malaysia and best practices. This role requires a proven leader with at least 8 years of relevant experience in cyber or technology risk, particularly in financial services.

The successful candidate will provide oversight, manage cyber resilience, and engage with senior management on risk matters. Strong analytical and leadership skills are essential for this pivotal position.

Qualifications

  • Minimum 8 years of relevant experience in cyber risk, technology risk, or IT security, preferably in financial services.
  • Professional certifications preferred (e.g., CISSP, CISM, CRISC, CISA).
  • Strong leadership and stakeholder management skills.

Responsibilities

  • Lead oversight of cyber and technology risks across the Group.
  • Ensure compliance with regulatory requirements and frameworks.
  • Oversee risk assessments and incident responses.
  • Serve as trusted advisor for cyber risk matters.
  • Lead and mentor the Cyber Risk Management team.

Skills

Cyber risk frameworks
Risk assessment methodologies
Incident management oversight
Stakeholder management
Analytical thinking

Education

Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Risk Management

Job description

Job Purpose

To lead and oversee the Cyber Risk Management unit under Group Technology Risk Management (GTRM), serving as the Second Line of Defense (2LOD) in providing independent risk oversight on Group Technology (GT), which operates as the First Line of Defense (1LOD). The role is responsible for ensuring that technology and cyber risks across the Group are appropriately identified, assessed, monitored, and mitigated in compliance with internal risk governance frameworks and regulatory requirements, including Bank Negara Malaysia (BNM), Securities Commission Malaysia (SC), and Bursa Malaysia.

Key Responsibilities
  1. Cyber Risk Oversight & Governance: Lead the independent oversight of cyber and technology risks across the Group in line with the Bank’s Enterprise Risk Management Framework. Establish and maintain cyber risk management policies, standards, and frameworks aligned to regulatory expectations and industry best practices. Provide effective advisory to the First Line (Group Technology) on risk identification, mitigation plans, and control effectiveness.
  2. Regulatory Compliance & Engagement: Ensure full compliance with regulatory requirements, including BNM Risk Management in Technology (RMiT), SC guidelines, and Bursa requirements. Act as the central coordination point for regulatory reviews, audits, and submissions relating to cyber and technology risk. Monitor regulatory developments and ensure timely implementation of new requirements across the Group.
  3. Risk Assessment & Monitoring: Oversee the execution of cyber risk assessments, including IT risk assessments, vulnerability management oversight, and cyber resilience reviews. Review and challenge risk and control self‑assessments (RCSAs), key risk indicators (KRIs), and risk reporting provided by the First Line. Ensure material risks are escalated appropriately to senior management and relevant governance committees.
  4. Incident Oversight & Cyber Resilience: Provide oversight of major cyber incidents and ensure appropriate escalation, response, and post‑incident review. Assess the adequacy of incident response, disaster recovery, and business continuity plans from a cyber risk perspective. Ensure lessons learned from incidents are embedded into risk mitigation strategies.
  5. Stakeholder Management & Advisory: Serve as a trusted risk advisor to Group Technology, senior management, and business units on cyber risk matters. Engage with internal stakeholders including Compliance, Internal Audit, and Business Units to ensure a coordinated risk management approach. Present cyber risk insights, issues, and recommendations to senior management committees.
  6. Team Leadership & Capability Building: Lead, develop, and mentor the Cyber Risk Management team to ensure strong technical and risk management capabilities. Drive a culture of risk awareness and accountability across the organisation. Ensure adequate resources, tools, and skillsets are in place to support evolving cyber risk landscape.
Job Requirements
Academic & Professional Qualifications

Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Risk Management, or related discipline. Professional certifications are highly preferred (e.g., CISSP, CISM, CRISC, CISA).

Experience

Minimum 8 years of relevant experience in cyber risk, technology risk, or IT security, preferably within the financial services industry. Proven experience in a leadership role managing cyber risk or technology risk functions.

Technical & Functional Competencies
  • Strong understanding of cyber risk frameworks, IT governance, and security controls.
  • Experience in risk assessment methodologies, cyber threat landscape, and incident management oversight.
  • Ability to challenge technical stakeholders and provide independent risk perspectives.
Behavioural Competencies
  • Strong leadership and stakeholder management skills, with the ability to influence across all levels of the organisation.
  • High level of integrity, professionalism, and sound judgement.
  • Strong analytical thinking, decision‑making, and problem‑solving capabilities.
  • Effective communication and presentation skills, particularly at senior management and Board level.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Technology Risk Management
Manager, Technology Risk Management

CTOS Data Systems • Malaysia

On-site
MYR 180,000 - 300,000
Group Head Information Security, SVP
Group Head Information Security, SVP

RHB Banking Group • Kuala Lumpur

On-site
MYR 320,000 - 520,000
Senior Manager - Technology Risk Management & Advisory
Senior Manager - Technology Risk Management & Advisory

AmBank Group • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Head of Cyber Risk
Head of Cyber Risk

Businesslist • Kuala Lumpur

On-site
MYR 270,000 - 330,000
Career stability
Leadership role
Permanent role
Group Head IT Security
Group Head IT Security

RHB Banking Group • Selangor

On-site
MYR 300,000 - 420,000
Risk Specialist, Cyber Risk Specialist Unit
Risk Specialist, Cyber Risk Specialist Unit

Bank Negara Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 230,000
Senior Manager (CyberSec & Resillience)
Senior Manager (CyberSec & Resillience)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Head of Cyber Risk
Head of Cyber Risk

Michael Page International (Malaysia) Sdn Bhd • Kuala Lumpur

On-site
MYR 270,000 - 330,000
Permanent role
Career stability
Associate Risk Analyst/ Risk Analyst, Cyber Risk Specialist Unit (TCS)
Associate Risk Analyst/ Risk Analyst, Cyber Risk Specialist Unit (TCS)

Bank Negara Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Senior IT Manager (Information Security, Risk & Governance)
Senior IT Manager (Information Security, Risk & Governance)

Alphv Recruit • Kuala Selangor

On-site
MYR 180,000 - 260,000