Information Security Officer

Principal Malaysia

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

48 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Principal Financial Group in Malaysia seeks an Information Security Officer to oversee the information security program regionally, aligning with enterprise policies and regulatory obligations. The role partnerships with the PI BISO and local leadership to ensure consistent security practices and effective reporting to management.

The candidate will manage security domains, risk assessments and remediation activities, while driving awareness and collaboration across business units to strengthen

Qualifications

  • Bachelor’s degree in Computer Science, Information Security or related field.
  • 8–10 years of information security experience in regional or multi-site settings.
  • Knowledge of ISO 27001, NIST and COBIT.
  • Experience with information security risk assessment and risk management.
  • Strong communication and stakeholder management skills.
  • CISSP, CISM, CRISC, GIAC or equivalent preferred.

Responsibilities

  • Act as the primary local point of contact for Information Security with senior management and stakeholders.
  • Establish and maintain relationships with local business, technology, risk, compliance, audit and privacy teams.
  • Oversee the Information Security Program in line with enterprise policies and regulatory requirements.
  • Provide governance across security domains including IAM, data protection, vulnerability management and third‑party risk.
  • Identify, assess and report information security risks and remediation needs.
  • Support security audits, regulatory reviews and incident response activities.
  • Promote security awareness and a strong security culture across the organization.
  • Prepare and communicate security updates and metrics to management and boards.

Job description

At Principal, we invest in what matters. And building dedicated teams is where it all begins. We’re drawn to people who bring outstanding perspectives, passion, and expertise to help us advance the financial security and well-being of our customers. We also aim to transform our growing business and drive positive change in the communities where we live and work.

When we invest in you, and you invest in us, great things happen.

We are looking for a Information Security Officer (ISO) who will responsible for overseeing the implementation and management of the information security program, including policies, procedures, standards, and guidelines within a specific region. The ISO actively works with the PI BISO, corporate Information Security team and local leadership to ensure consistency of approach and alignment with overall security objectives and priorities. The Information Security Officer is responsible for communicating to local stakeholders and the PI BISO the state of local compliance with information security policies and procedures, while supporting the organization’s overall cybersecurity posture and regulatory obligations.

What You’ll Do
  • Act as the primary local point of contact for Information Security, partnering with the PI BISO, enterprise Information Security teams, senior management and key stakeholders on security-related matters.
  • Establish and maintain effective relationships with local business, technology, risk, compliance, audit, privacy and regulatory stakeholders to support information security objectives and compliance requirements.
  • Oversee the implementation, governance and continuous improvement of the Information Security Program, ensuring alignment with enterprise policies, standards, industry frameworks and applicable regulatory requirements.
  • Provide governance and oversight across key information security domains, including security operations, identity and access management, data protection, vulnerability management, third-party risk management, security awareness and related cybersecurity controls.
  • Identify, assess, monitor and report information security risks, vulnerabilities, emerging threats and control effectiveness, providing recommendations to strengthen the organization’s security posture and resilience.
  • Support security risk assessments, audits, regulatory reviews and remediation activities, ensuring timely resolution of information security findings and compliance gaps.
  • Coordinate and support the response to security incidents, regulatory inquiries and other cybersecurity matters in partnership with enterprise Information Security, Risk and Incident Response teams.
  • Promote security awareness and foster a strong security culture by supporting employee training, policy adherence and ongoing engagement activities.
  • Support business continuity, disaster recovery and other security-related initiatives and projects, providing guidance to ensure successful implementation.
  • Prepare and communicate information security updates, metrics and reports to management, governance committees and boards, where appropriate.
  • Participate in local risk, audit and governance forums and provide consultation and security guidance to business and technology stakeholders.
Who You Are
  • Bachelor's degree holder in Computer Science, Information Security or a related field.
  • Minimum of 8–10 years of experience in information security, preferably within a regional or multi-site environment.
  • Strong knowledge of security frameworks such as ISO 27001, NIST and COBIT.
  • Experience with information security risk assessment and risk management.
  • Strong understanding of cybersecurity domains including Security Operations, Identity and Access Management (IAM), Data Loss Prevention (DLP), Vulnerability and Patch Management, Asset Management, Security Awareness and Third-Party Risk Management.
  • Experience supporting information security audits, regulatory reviews, control assessments and remediation activities.
  • Excellent communication, stakeholder management and influencing skills, with the ability to collaborate effectively across all levels of the organization.
  • Strong written and presentation skills with the ability to prepare and present information security reports to senior management, governance committees and boards of directors.
  • Ability to work well under pressure, manage competing priorities and respond effectively to tight deadlines.
  • Strong analytical skills with the ability to analyze, interpret and communicate security-related data and trends.
  • Relevant professional certifications such as CISSP, CISM, CRISC, GIAC or equivalent are preferred.
  • Experience in security operations and handling cybersecurity incidents preferred.
Who We Are
Principal Financial Group

is a Fortune 500 global leader in financial services focused on insurance, retirement, and asset management. We have 18,000 employees and 51 million customers around the world with over $714B in assets under management.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer (ISO) Asia-Pacific
Information Security Officer (ISO) Asia-Pacific

GEA Group • Shah Alam

On-site
MYR 243,000 - 485,000
Regional Information Security Leader
Regional Information Security Leader

Principal Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Security Officer (ISO) Asia-Pacific
Information Security Officer (ISO) Asia-Pacific

GEA • Shah Alam

On-site
MYR 150,000 - 230,000
INFORMATION SECURITY OFFICER (CONTRACTUAL)
INFORMATION SECURITY OFFICER (CONTRACTUAL)

PSI INCONTROL SDN BHD • Sungai Buloh

On-site
MYR 90,000 - 130,000
Medical
Education support
Loans
+3
Senior Manager, Information Security
Senior Manager, Information Security

Prudential Assurance Malaysia Berhad • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Manager, Security Innovation
Senior Manager, Security Innovation

Prudential Services Asia • Kuala Lumpur

On-site
MYR 180,000 - 300,000
IT Security Operation Lead_3266
IT Security Operation Lead_3266

Allianz • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Business Information Security Officer (BISO)
Business Information Security Officer (BISO)

dentsu • Kuala Lumpur

On-site
MYR 150,000 - 190,000
Head of Information Security (Technical)
Head of Information Security (Technical)

Secretlab • Petaling Jaya

On-site
MYR 480,000 - 720,000
Information Security C Governance Manager
Information Security C Governance Manager

Senheng Electric (KL) Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000