IT Security Governance

GoKardz Technologies

Kuala Lumpur

On-site

MYR 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GoKardz Technologies in Kuala Lumpur is seeking an IT Security professional with 6-10 years of experience in the Financial Services Industry. The role involves reviewing and updating Group IT Security Policies, developing governance processes, and assessing IT risks to ensure compliance with regulatory standards.

The ideal candidate will possess relevant certifications and have strong communication skills to provide security recommendations and promote awareness regarding best practices across the organization.

Qualifications

  • 6-10 years of IT Security related experience in the Financial Services Industry.
  • Possess professional certifications such as ITIL, COBIT, CISSP, CEH and CHFI.
  • Knowledge in compliance assessment, policy development, and industry standards.

Responsibilities

  • Support in reviewing and updating the Group IT Security Policies and Standards.
  • Develop Regional IT Security Governance processes to align with the Bank’s strategy.
  • Assess IT Risk associated with projects to mitigate risks.
  • Provide security recommendations to stakeholders.

Skills

Knowledge in information security
Knowledge of regional FSI regulator requirements
Strong written and verbal communication skills in English
Experience handling training classes
Experience designing security policies

Education

Bachelor Degree in Computer Science majoring in Security, Network or Computer System

Tools

ISO 27001
PCI-DSS
ITIL
COBIT
CISSP
CEH
CHFI

Job description

JOB PURPOSE
  1. Propose and update the Group IT Security Policies and Standards, including Regional & Overseas Units, ensuring that all local regulators’ requirements and industry best practice are captured and adhered to.
  2. Develop Regional IT Security Governance processes to align with the Bank’s strategy and aspirations.
  3. Justify and assess IT Risk associated with projects to ensure that the Confidentiality, Integrity and Availability risks are mitigated to an acceptable level.
  4. Enforce and proactively provide IT security consultancy/advisory services on policies, standards and best practices across the Group.
  5. Interpret regional countries regulatory compliance and enforce it within the Maybank Group based on Intra-Outsourcing arrangement.
  6. Enable the security assessment exercise to be conducted and remediated in a timely manner.
  7. Promote IT Security Processes by conducting IT Security Governance awareness programs for all project teams and MSS teams.
  8. Evaluate change and firewall requests to guarantee conformance to the Bank’s policies and standards.
  9. Safeguard information system assets by identifying and solving potential and actual security problems.
KEY ACCOUNTABILITIES & OUTCOMES

1. Support in reviewing and updating the Group IT Security Policies and Standards

  • Review local IT Security Policies and Standards.
  • Perform gap analysis and engage Regional IT Security representatives to discuss gaps.
  • Provide recommendations of Group IT Security Policies to Unit Heads and Section Heads for review.
  • Produce communications to the enterprise via portal or internal communications if required.

Outcome: Robust, standardized and industry‑standard Group IT Security Policies and Standards.

Challenges: Managing users and outsourcers to provide timely responses; obtaining understanding of regional and overseas units’ regulatory requirements; supporting Group‑wide IT Security Governance processes; proposing policies that suit different local businesses and regulators; conducting research and recommending control measures; presenting governance awareness; supporting various parties to ensure compliance; reviewing existing system security controls; checking non‑compliance against business requirements.

2. Develop Regional IT Security Governance processes

  • Participate in discussions with Regional IT Security representatives to understand current local processes and challenges.
  • Establish streamlined IT Security Governance processes to be used across the Group.
  • Recommend the streamlined process to Unit Heads and Section Heads.

Outcomes: Standardized Group IT Governance Process; effective IT Security Governance across the Group; increased compliance level across the Group.

3. Justify and assess IT Risk associated with projects

  • Enable the IT Risk Management process.
  • Provide active guidance and consultation to the team on IT Security matters.
  • Communicate and discuss with respective parties the associated risk and its mitigation.

Outcomes: Acceptable level of risk exposure to the Bank; proactive assessment and mitigation of risk exposure.

4. Provide security recommendations to stakeholders and support improvement plans

  • Perform assessments to identify potential weaknesses and regulatory breaches.
  • Provide security recommendations to stakeholders to ensure compliance with the Bank’s policies and regulator requirements.
  • Support the proposed improvement plan.

Outcomes: Maintenance and enforcement of effective IT Security policies and standards; mitigation of risk exposure.

5. Interpret regional countries regulatory compliance and enforce in the Group

  • Gather regional regulatory requirements, policies and guidelines.
  • Map to existing BNM requirements and identify gaps.
  • Establish draft Regional Compliance Checklist for review.
  • Support enforcement of regional regulatory requirements to relevant projects based on scope and criteria.

Outcome: Ensure compliance with respective local regulators’ requirements.

6. Enable timely security assessment and remediation

  • Obtain list of in‑scope applications.
  • Coordinate with internal and external resources to perform the security assessment.
  • Track end results, remediation and provide status updates.

Outcomes: Effective security assessment activity; overall visibility and effective management of major vulnerabilities; mitigation of risk exposure; compliance with regulators’ requirements.

7. Promote IT Security Processes through awareness programs

  • Develop IT Security Awareness slides/material.
  • Coordinate with audiences.
  • Provide assistance for the awareness program.

Outcomes: Effective IT Security Governance process; reduced delay in project implementation due to insufficient documentation.

8. Evaluate change and firewall requests

  • Review and assess change and firewall requests.
  • Ensure requests comply with the Bank’s policies and standards.
  • Approve or reject the request based on assessment.

Outcome: Protect the Bank by ensuring change and firewall requests are in accordance with the Bank’s policies and standards.

9. Safeguard information system assets

  • Perform assessment on requests made by users.
  • Review information assets to identify potential security weaknesses and mitigate accordingly.

Outcomes: Mitigate risk exposure to an acceptable level; continuous improvement for better protection.

EDUCATION

Minimum Bachelor Degree in Computer Science majoring in Security, Network or Computer System.

EXPERIENCE

6‑10 Years of IT Security related working experience in the Financial Services Industry (FSI)/Banking industry or similar environment.

CERTIFICATIONS/REGULATORY CERTIFICATIONS

Possess professional certifications such as ITIL, COBIT, CISSP, CEH and CHFI.

JOB SPECIFIC SKILLS & COMPETENCIES REQUIRED
  1. Knowledge in information security, specifically in compliance assessment, policy development and industry standard frameworks such as ISO 27001, PCI‑DSS, etc., preferably gained in the Financial Services sector; experience in service continuity desirable.
  2. Knowledge of regional FSI regulator requirements and guidelines (MAS, BI, BSP, BNM, PBOC, HKMA, etc.).
  3. Experience liaising with various stakeholders.
  4. Strong written and verbal communication skills in English to disseminate security messages and practices, contribute to documentation, and present ideas in business‑friendly language.
  5. Experience handling training classes; strong presentation and negotiation skills.
  6. Experience designing enterprise and operational level security policies, standards and processes (e.g., email & internet policy, password management process).
  7. Knowledge of network components and related protocols, security products/solutions; understanding of vulnerabilities in operating systems, databases and major applications, and ability to mitigate them.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead IT Security Policy | Up to RM14K
Lead IT Security Policy | Up to RM14K

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Manager, Network Security Operations
Manager, Network Security Operations

Hong Leong Bank Berhad • Selangor

On-site
MYR 120,000 - 180,000
Cloud Security Governance & Compliance Lead
Cloud Security Governance & Compliance Lead

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Group Head of IT Security
Group Head of IT Security

MindMerge Consulting • Kuala Lumpur

On-site
MYR 400,000 - 480,000
Group Head Information Security, SVP
Group Head Information Security, SVP

RHB Banking Group • Kuala Lumpur

On-site
MYR 320,000 - 520,000
Department Head, IT Security, Information Technology & Services
Department Head, IT Security, Information Technology & Services

Agrobank • Kuala Lumpur

On-site
MYR 300,000 - 520,000
Cloud Technical Security Governance
Cloud Technical Security Governance

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Manager, Cyber Risk Specialist Unit | Tech. & Cyber Supervision
Manager, Cyber Risk Specialist Unit | Tech. & Cyber Supervision

Bank Negara Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting Pte Ltd • Kuala Lumpur

On-site
MYR 179,000 - 223,000