Monroe Consulting Group, an Executive Recruitment firm, is partnering with a leading organisation in the Information Technology sector to hire a Head of IT Security and Compliance. This opportunity is based in Sarawak, Malaysia.
Position Overview
This role has to lead the development, implementation, and governance of the organisation's cyber security strategy, ensuring robust protection of critical systems, information assets, and digital operations.
Drive regulatory compliance, risk management, and security resilience while enabling secure and scalable business growth.
Key Responsibilities
1. Cyber Security Strategy & Governance
- Develop and execute cyber security framework, ensuring alignment with industry standards.
- Establish IT security policies, procedures, and governance models to protect critical systems.
- Ensure compliance with ISO 27001, NIST, GDPR, PCI DSS, and applicable industry regulations.
- Conduct regular security audits and risk assessments, identifying vulnerabilities and mitigation strategies.
2. Threat Management & Incident Response
- Oversee real-time threat monitoring, ensuring proactive detection and response.
- Lead incident response teams, managing cyber security breaches and forensic investigations.
- Implement disaster recovery and business continuity plans, ensuring minimal disruption.
- Develop penetration testing and vulnerability management programmes to strengthen security posture.
3. Compliance & Regulatory Adherence
- Ensure IT systems comply with industry, financial, and data protection regulations.
- Manage audit processes, ensuring readiness for regulatory inspections.
- Collaborate with legal and compliance teams to align IT security with corporate policies.
- Maintain documentation and reporting for compliance audits and risk assessments.
4. Identity & Access Management (IAM)
- Implement role-based access controls (RBAC) for secure user authentication.
- Oversee multi-factor authentication (MFA) and encryption protocols.
- Ensure secure on boarding and off boarding of employees and third-party vendors.
5. Vendor & Stakeholder Management
- Manage relationships with security vendors, ensuring SLAs are met.
- Oversee procurement and contract negotiations for cybersecurity solutions.
- Collaborate with cross-functional teams to align security measures with business needs.
6. Team Leadership & Development
- Build and mentor a high-performing cyber security team, fostering innovation and collaboration.
- Provide technical leadership and guidance on security architecture and compliance.
- Ensure continuous training and skill development for IT security staff.
Key Requirements
Qualifications & Experience
- Bachelor's or Master's degree in Cyber Security, Information Technology, or a related field.
- 15+ years of experience in IT security and compliance, with expertise in enterprise security frameworks.
- Proven track record in large-scale IT security management with strict deadlines.
- Experience in vendor negotiations, contract management, and regulatory compliance.
- Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor, CEH, and/or PMP are highly preferred.
Technical / Functional Expertise
- Strong knowledge of ISO 27001, NIST, GDPR, PCI DSS, and industry security regulations.
- Expertise in cyber security governance, risk management, and compliance frameworks.
- Experience in threat monitoring, incident response, and forensic investigations.
- Strong knowledge of Identity and Access Management (IAM), including RBAC, MFA, and encryption protocols.
- Experience with AWS, Azure, and/or Google Cloud security best practices.
- Expertise in penetration testing, vulnerability management, ethical hacking, and threat modelling.
- Proficiency in audit management, regulatory compliance, and security documentation.
- Experience developing disaster recovery and business continuity plans.
Soft Skills & Leadership Competencies
- Strong leadership and team development capabilities.
- Excellent stakeholder, vendor, and contract management skills.
- Strong cross-functional collaboration with legal, finance, compliance, and technology teams.
- Excellent analytical thinking and problem-solving abilities.
- Strong communication and executive reporting skills.
- High attention to detail in security audits, compliance documentation, and risk assessments.
- Ability to develop and execute long-term security strategies aligned with business objectives.