Information Security Manager

EPOS

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EPOS in Kuala Lumpur, Malaysia seeks an experienced information security leader to develop and oversee the information security strategy and frameworks aligned with ISO 27001, NIST, and other applicable standards. You will establish policies, advise senior management, and report security KPIs while coordinating with the group security team.

The role requires hands-on leadership in security operations, risk management, governance, and incident response across multiple domains, including IAM, data

Qualifications

  • 10 years in information security / cyber security operation, and risk management.
  • Previous experience as information security lead or similar roles.
  • Familiarity with regulatory requirements and standards (e.g. ISO27001, PCI DSS, NIST).
  • Experience leading implementation and operations of security domains.
  • Strong technical foundation in cybersecurity, application security, data security, and incident response.
  • Fluent in English; Mandarin a plus.
  • Able to independently strategise, plan and execute information security programs.

Responsibilities

  • Develop, maintain, and oversee the information security function, strategy and frameworks - in alignment with ISO 27001, NIST, etc.
  • Establish, maintain and enforce security policies, standards, and procedures.
  • Serve as SME on information security and advise senior management.
  • Report security posture/KPIs to senior management.
  • Align with group Ant International security policies and standards.
  • Collaborate with Ant International security team on risk assessments, security tests, and governance activities.
  • Own end-to-end security incident response and data breach management.
  • Lead security operations across domains: infrastructure, SOC, application, data, IAM, etc.
  • Deliver security awareness programs and trainings.

Skills

Information security
Security operations
Incident response
Risk management
Governance & compliance
Security architecture
Security engineering
Application security
Data security
IAM

Tools

EDR
DLP
VAPT tools
Vulnerability management

Job description

  • Develop, maintain, and oversee the information security function, strategy and frameworks - in alignment with applicable standards such ISO 27001, NIST, etc.
  • Establish, maintain and enforce security policies, standards, and procedures;
  • Key subject matter expert on information security, provide relevant information security advise to senior management
  • Reporting of security posture/KPIs to senior management
  • Ensure alignment and adherence to group Ant International security policies and standards
  • Collaborate and work with Ant International security team on relevant security risk assessments, security testings, and governance activities
2. Industry & Regulatory Standards
  • Ensure compliance with applicable information security standards where required (e.g. PCI DSS, ISO27001, etc.)
  • Primary liaison on information security for external auditors, external assessors, regulators (where relevant)
  • Execute information security risk management program
  • Ensure proper implementation of information security controls to mitigate security threats/risks
  • Ensure proper monitoring of security risks, vulnerabilities, findings - and ensure timely & effective remediation
4. Security incident response & recovery
  • Own and manage the end-to-end response to security incidents and data breaches, including coordination, escalation, investigation, containment, and reporting - in collaboration with required stakeholders
5. Lead security operations and implementation of relevant security domains.
  • Able to lead and execute security engineering initiatives
  • Plan and develop security architecture & framework,
  • Lead and execute security operations (required to be hands on technically)
  • Security operations including (but not limited to):
  • Infrastructure/Network/Cybersecurity
  • SOC Security Monitoring and Security Incident Response
  • Security Engineering
  • Application Security (including Application Security Testings, VAPT, Vulnerability Management)
  • Data & Endpoint Security (including EDR, DLP)
  • Identification & Access Management
  • Information security governance, risk management, compliance operations
  • Third Party Security Risk Management
6.Security Culture & Awareness
  • Deliver security awareness programs and foster a security-conscious culture.
  • Security trainings and examinations for relevant stakeholders
Candidate Profile
Experience & Background
  • 10 years in information security / cyber security operation, and risk management
  • Previous experience as information security lead or similar roles
  • Familiarity with relevant technology/cybersecurity regulatory requirements and standards will be beneficial (e.g. BNM RMiT, MAS TRM, ISO27001, PCI DSS, NIST, etc.)
  • Experience leading implementation and operations of security domains will be a plus
  • Strong technical foundation in cybersecurity, application security, data security, and incident response
Certifications
  • CISM, CISSP preferred.
  • Able to independently strategise, plan and execute information security programs
  • Technically apt for security operations, security engineering, security architecture hands-on work
  • Fluent in written/spoken English. Mandarin is a plus.
  • Project & Risk Management: Demonstrated ability to lead complex security projects, handle incident response, and information security initiatives in regulated environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

FIRMUS • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting Pte Ltd • Kuala Lumpur

On-site
MYR 179,000 - 223,000
IT Security Engineer
IT Security Engineer

ITIC MIMOS • Kuala Lumpur

On-site
MYR 60,000 - 120,000
Security Engineer
Security Engineer

Mission Consultancy Services • Kuala Lumpur

On-site
MYR 80,000 - 120,000
IT Security Governance
IT Security Governance

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Manager Security Operation Centre
Manager Security Operation Centre

GoKardz Technologies • Kuala Lumpur

On-site
MYR 120,000 - 150,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Security Project Engineer
Security Project Engineer

ADI Resourcing • Kuala Lumpur

On-site
MYR 78,000 - 156,000
Junior Security Solutions Consultant
Junior Security Solutions Consultant

UniQ Consulting & Services Sdn Bhd • Petaling Jaya

On-site
MYR 60,000 - 120,000