Head of IT Security and Compliance

Monroe Consulting Group

Kuching

On-site

MYR 250,000 - 500,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Monroe Consulting Group, a leading Executive Recruitment firm, partners with a top IT organisation to hire a Head of IT Security and Compliance based in Sarawak, Malaysia. This role leads cyber security strategy, governance, and regulatory compliance across critical systems and data protection programs.

The ideal candidate will drive risk management, incident response, IAM, and vendor relationships while enabling secure business growth and resilience in a dynamic technology environment.

Qualifications

  • Bachelor's or Master's degree in Cyber Security, IT, or related field.
  • 15+ years of IT security and compliance experience with enterprise scope.
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor preferred.

Responsibilities

  • Lead cyber security strategy, governance, and policy development.
  • Ensure compliance with ISO 27001, NIST, GDPR, PCI DSS, and regs.
  • Oversee threat monitoring, incident response, and disaster recovery planning.
  • Manage IAM, RBAC, MFA, and secure onboarding/offboarding.
  • Coordinate audits, vendor risk, and regulatory inspections.
  • Mentor security team and align security with business needs.

Skills

Strategic leadership
Cyber security governance
Regulatory compliance
Risk management
Incident response
IAM & access controls
Vendor & contract management
Security architecture
Security audits & testing

Education

Bachelor's/Master's in Cyber Security or IT

Tools

AWS
Azure
GCP

Job description

Monroe Consulting Group, an Executive Recruitment firm, is partnering with a leading organisation in the Information Technology sector to hire a Head of IT Security and Compliance. This opportunity is based in Sarawak, Malaysia.

Position Overview

This role has to lead the development, implementation, and governance of the organisation's cyber security strategy, ensuring robust protection of critical systems, information assets, and digital operations.
Drive regulatory compliance, risk management, and security resilience while enabling secure and scalable business growth.

Key Responsibilities
1. Cyber Security Strategy & Governance
  • Develop and execute cyber security framework, ensuring alignment with industry standards.
  • Establish IT security policies, procedures, and governance models to protect critical systems.
  • Ensure compliance with ISO 27001, NIST, GDPR, PCI DSS, and applicable industry regulations.
  • Conduct regular security audits and risk assessments, identifying vulnerabilities and mitigation strategies.
2. Threat Management & Incident Response
  • Oversee real-time threat monitoring, ensuring proactive detection and response.
  • Lead incident response teams, managing cyber security breaches and forensic investigations.
  • Implement disaster recovery and business continuity plans, ensuring minimal disruption.
  • Develop penetration testing and vulnerability management programmes to strengthen security posture.
3. Compliance & Regulatory Adherence
  • Ensure IT systems comply with industry, financial, and data protection regulations.
  • Manage audit processes, ensuring readiness for regulatory inspections.
  • Collaborate with legal and compliance teams to align IT security with corporate policies.
  • Maintain documentation and reporting for compliance audits and risk assessments.
4. Identity & Access Management (IAM)
  • Implement role-based access controls (RBAC) for secure user authentication.
  • Oversee multi-factor authentication (MFA) and encryption protocols.
  • Ensure secure on boarding and off boarding of employees and third-party vendors.
5. Vendor & Stakeholder Management
  • Manage relationships with security vendors, ensuring SLAs are met.
  • Oversee procurement and contract negotiations for cybersecurity solutions.
  • Collaborate with cross-functional teams to align security measures with business needs.
6. Team Leadership & Development
  • Build and mentor a high-performing cyber security team, fostering innovation and collaboration.
  • Provide technical leadership and guidance on security architecture and compliance.
  • Ensure continuous training and skill development for IT security staff.
Key Requirements
Qualifications & Experience
  • Bachelor's or Master's degree in Cyber Security, Information Technology, or a related field.
  • 15+ years of experience in IT security and compliance, with expertise in enterprise security frameworks.
  • Proven track record in large-scale IT security management with strict deadlines.
  • Experience in vendor negotiations, contract management, and regulatory compliance.
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor, CEH, and/or PMP are highly preferred.
Technical / Functional Expertise
  • Strong knowledge of ISO 27001, NIST, GDPR, PCI DSS, and industry security regulations.
  • Expertise in cyber security governance, risk management, and compliance frameworks.
  • Experience in threat monitoring, incident response, and forensic investigations.
  • Strong knowledge of Identity and Access Management (IAM), including RBAC, MFA, and encryption protocols.
  • Experience with AWS, Azure, and/or Google Cloud security best practices.
  • Expertise in penetration testing, vulnerability management, ethical hacking, and threat modelling.
  • Proficiency in audit management, regulatory compliance, and security documentation.
  • Experience developing disaster recovery and business continuity plans.
Soft Skills & Leadership Competencies
  • Strong leadership and team development capabilities.
  • Excellent stakeholder, vendor, and contract management skills.
  • Strong cross-functional collaboration with legal, finance, compliance, and technology teams.
  • Excellent analytical thinking and problem-solving abilities.
  • Strong communication and executive reporting skills.
  • High attention to detail in security audits, compliance documentation, and risk assessments.
  • Ability to develop and execute long-term security strategies aligned with business objectives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Cyber Security and Compliance Officer
Chief Cyber Security and Compliance Officer

Monroe Consulting Group • Kuching

On-site
MYR 250,000 - 500,000
Group Head of IT Security
Group Head of IT Security

MindMerge Consulting • Kuala Lumpur

On-site
MYR 432,000 - 528,000
Cybersecurity Project Manager
Cybersecurity Project Manager

Prometric • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Executive, Cybersecurity & IT Governance
Senior Executive, Cybersecurity & IT Governance

Asia Recruit (Permanent, Contract, & Executive Recruitment) • Shah Alam

On-site
MYR 80,000 - 120,000
Head of IT Security
Head of IT Security

Oxydata Software Sdn Bhd • Kuala Lumpur

On-site
MYR 300,000 - 420,000
Head of IT Security
Head of IT Security

Oxydata Software • Penang

On-site
MYR 360,000 - 480,000
Head of IT Security
Head of IT Security

Oxydata Software • Kuala Lumpur

On-site
MYR 300,000 - 420,000
Head of IT Operations and Infrastructure Management
Head of IT Operations and Infrastructure Management

Monroe Consulting Group • Kuching

On-site
MYR 300,000 - 540,000
6412 - IT Security Manager
6412 - IT Security Manager

Agensi Pekerjaan Minde Group Sdn Bhd • Penang

On-site
MYR 180,000 - 270,000
Junior Security Solutions Consultant
Junior Security Solutions Consultant

UniQ Consulting & Services Sdn Bhd • Petaling Jaya

On-site
MYR 60,000 - 120,000