Oxydata Software Sdn Bhd established since 2012, helping regional enterprises drive digital transformation through Agentic AI Services, AI Automation & Integration, Data Engineering, AI Training, and IT Managed Services. We are a lean, high-impact team where engineers work directly on cutting-edge AI products serving enterprise clients across Malaysia and the region
We are seeking an experienced Head of IT Security to lead the cybersecurity function for a global manufacturing organisation.
Head of IT Security
Location: Penang, Malaysia
Work Mode: Onsite
Employment type: Permanent
Experience Level: 10+ years
Work Eligibility: Applicants must have the legal right to work in Malaysia. Visa sponsorship is not available for this position.
Responsibilities
- Lead the Information Security and Cybersecurity function, setting strategic direction and governance frameworks.
- Develop and implement cybersecurity strategies, roadmaps, policies, and standards.
- Oversee security operations including SOC, vulnerability management, threat management, security monitoring, and incident response.
- Take ownership of major cybersecurity incidents and crisis management, including containment, recovery, stakeholder communication, and post-incident improvement.
- Drive cyber resilience and enhance operational security capabilities across the organisation.
- Assess and improve security across networks, identity, endpoints, cloud, applications, and operational/manufacturing environments.
- Lead ISO/IEC 27001 compliance and certification-readiness activities, and apply relevant frameworks such as ISO 27001 and NIST CSF.
- Manage cybersecurity risks related to third parties, vendors, and supply chains.
- Manage and mature SOC / MSSP capabilities.
- Lead and develop cybersecurity teams, manage vendors, security tools, and budgets.
- Present cybersecurity risks, incidents, KPIs, and recommendations to senior and executive management.
Requirements
Must-have:
- Bachelor's degree in any related discipline.
- Applicants must have the legal right to work in Malaysia. Visa sponsorship is not available for this position.
- CISSP, CISM, CRISC, GICSP, ISO 27001 Lead Implementer / Lead Auditor, or other relevant cybersecurity certifications.
- Minimum 10 years of Information Security / Cybersecurity experience.
- At least 3 years in a senior cybersecurity leadership role such as Head of Security, Security Director, Deputy CISO, or Senior Security Manager.
- Extensive experience in Security Operations / SOC and Incident Response.
- Proven experience leading major cybersecurity incidents or cyber crisis management.
- Experience in cyber resilience, vulnerability/threat management, cybersecurity risk, and regulatory compliance.
- Strong practical knowledge of ISO/IEC 27001.
- Good knowledge of NIST Cybersecurity Framework (NIST CSF).
- Experience developing cybersecurity strategies, policies, and security roadmaps.
- Experience managing cybersecurity teams, vendors, and service providers.
Nice-to-have:
- Cybersecurity experience within manufacturing, industrial, energy, utilities, logistics, or critical infrastructure.
- OT / ics / scada cybersecurity exposure.
- Knowledge of IEC 62443.
- OT network segmentation or industrial security monitoring experience.
- Experience managing SOC / MSSP providers.
- Experience working within a multinational/global organisation.
- Azure / Microsoft 365 security exposure.
- Third-party and supply-chain cybersecurity experience.
- Previous interim or contract cybersecurity leadership experience.
- Bahasa Malaysia or Mandarin language capability is advantageous but not mandatory.
Why Join Us
- Join a global leader in manufacturing and play a pivotal role in shaping the organisation's cybersecurity landscape.
- Opportunity to drive impactful change, work with a talented team, and ensure the highest standards of security in a dynamic, international environment.