Head, Security Risk Manager

Averis

Kuala Lumpur

On-site

MYR 180,000 - 360,000

Full time

46 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Averis seeks a senior Technology Risk leader to drive enterprise risk governance in Kuala Lumpur, overseeing cybersecurity, AI governance, OT and data protection, and third-party risk within risk appetite. You will align risk posture with business goals and regulatory expectations.

You will partner with executive management, risk committees, and the board to enable safe digital transformation and resilient operations across the organization.

Qualifications

  • Bachelor's Degree in Information Technology, Cyber Security, Risk Management, Computer Science, or related discipline.
  • Master's Degree is an advantage.

Responsibilities

  • Establish and maintain the Enterprise Technology Risk Management Framework.
  • Lead identification, assessment, monitoring, and reporting of risks across Cybersecurity, AI, OT, EDI, Data Protection, Third-Party Risk, and Digital Transformation.
  • Provide independent technology risk advisory services to executive management and governance forums.
  • Coordinate regulatory compliance activities, audits, certifications, and regulatory reviews.
  • Develop and maintain technology risk dashboards, KRIs, KPIs, and executive reporting.

Skills

Technology risk governance
Cybersecurity
Information security
Regulatory compliance
Executive advisory

Education

Bachelor's Degree in IT/Cyber Security/Risk Management/CS
Master's Degree an advantage

Tools

NIST CSF
COBIT
COSO ERM
Cloud Security (AWS / GCP)

Job description

Lead and continuously enhance the enterprise-wide Technology Risk Management function, providing independent oversight and governance over all technology-related risks including Cybersecurity, Information Security, Artificial Intelligence (AI), Cloud, On-Premise Infrastructure, Operational Technology (OT), Data Protection, Third-Party/Vendor, Digital Transformation, and Emerging Technology risks.

The role ensures technology risks are identified, assessed, prioritized, reported, and managed within the organization's risk appetite while supporting business growth, innovation, operational resilience, regulatory compliance, and digital transformation initiatives.

Act as a strategic advisor to executive management, technology leadership, risk committees, and board-level governance forums on technology risk matters.

Key Responsibilities
Technology Risk Governance
  • Establish and maintain the Enterprise Technology Risk Management Framework.
  • Define technology risk policies, standards, methodologies, risk appetite, and governance processes.
  • Ensure alignment with Enterprise Risk Management (ERM) and Group Risk requirements.
Enterprise Technology Risk Oversight
  • Lead identification, assessment, monitoring, and reporting of risks across:
  • Cybersecurity & Information Security
  • Artificial Intelligence (AI) & Generative AI
  • Operational Technology (OT), IC & IoT
  • Applications & Digital Platforms
  • Data Protection & Privacy
  • Third-Party & Supply Chain Technology Risk
  • Technology Projects & Digital Transformation
  • Business Continuity & Operational Resilience
  • Oversee risk treatment plans and ensure timely remediation of control gaps.
Risk Advisory & Business Partnership
  • Provide independent technology risk advisory services to business and IT stakeholders.
  • Support strategic initiatives, digital transformation, cloud adoption, AI implementation, and technology modernization programs.
  • Challenge risk decisions and ensure alignment with organizational risk appetite.
Regulatory Compliance & Assurance
  • Ensure compliance with applicable regulatory, legal, and industry requirements.
  • Coordinate technology risk assessments, audits, certifications, and regulatory reviews.
  • Monitor remediation of audit findings and compliance gaps.
  • Develop and maintain technology risk dashboards, KRIs, KPIs, and executive reporting.
  • Present technology risk posture, emerging threats, and key issues to management committees and senior leadership.
  • Provide insights and recommendations to support risk-based decision-making.
  • Promote a strong risk-aware culture across business and technology functions.
  • Mentor and guide risk owners, control owners, and technology teams.
  • Lead and develop a high-performing Technology Risk Management capability.
Qualifications & Experience
Education
  • Bachelor's Degree in Information Technology, Cyber Security, Risk Management, Computer Science, or related discipline.
  • Master's Degree is an advantage.
Experience
  • 8 - 10+ years of experience in Technology Risk, Cybersecurity, Information Security, IT Governance, IT Audit, or Enterprise Risk Management.
  • Minimum 5 years in a leadership or management role.
  • Experience in, shared services, manufacturing, industrial, or highly regulated environments is preferred.
Preferred Certifications
  • CRISC
  • CISSP
  • CISM
  • CISA
  • CGEIT
  • CCSP or equivalent Cloud Security certification
Technical Knowledge

Strong understanding of:

  • ISO 27001
  • NIST Cybersecurity Framework
  • COBIT
  • ISO 31000 / COSO ERM
  • Cloud Security (AWS, Aliyun, Google Cloud (Optional))
  • AI & Generative AI Governance
  • OT/ICS Security
  • Third-Party Risk Management
  • Data Protection & Privacy Regulations
  • Business Continuity & Operational Resilience
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, Technology Risk Management
Manager, Technology Risk Management

CTOS Data Systems • Malaysia

On-site
MYR 180,000 - 300,000
Risk, Integrity & Cybersecurity
Risk, Integrity & Cybersecurity

Private Advertiser • Shah Alam

On-site
MYR 180,000 - 300,000
Head of Technology and Operational Risk
Head of Technology and Operational Risk

Kerry Consulting • Kuala Lumpur

On-site
MYR 350,000 - 650,000
Information Security C Governance Manager
Information Security C Governance Manager

Senheng Electric (KL) Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
IT Governance & Compliance Lead
IT Governance & Compliance Lead

Genting Energy • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Assistant Manager - IT (Compliance)
Assistant Manager - IT (Compliance)

Genting Energy • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Head, Cyber Risk Management
Head, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Assistant General Manager/General Manager, Group Cybersecurity & Technology Governance
Assistant General Manager/General Manager, Group Cybersecurity & Technology Governance

IOI Properties Group Berhad • Putrajaya

On-site
MYR 300,000 - 600,000
Health insurance
Manager, AI Risk Operations, Group Risk
Manager, AI Risk Operations, Group Risk

Maybank • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Head of Technology and Operational Risk Audit (SVP)
Head of Technology and Operational Risk Audit (SVP)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 300,000 - 600,000