JOB PURPOSE
- Propose and update the Group IT Security Policies and Standards, including Regional & Overseas Units, ensuring that all local regulators’ requirements and industry best practice are captured and adhered to.
- Develop Regional IT Security Governance processes to align with the Bank’s strategy and aspirations.
- Justify and assess IT Risk associated with projects to ensure that the Confidentiality, Integrity and Availability risks are mitigated to an acceptable level.
- Enforce and proactively provide IT security consultancy/advisory services on policies, standards and best practices across the Group.
- Interpret regional countries regulatory compliance and enforce it within the Maybank Group based on Intra-Outsourcing arrangement.
- Enable the security assessment exercise to be conducted and remediated in a timely manner.
- Promote IT Security Processes by conducting IT Security Governance awareness programs for all project teams and MSS teams.
- Evaluate change and firewall requests to guarantee conformance to the Bank’s policies and standards.
- Safeguard information system assets by identifying and solving potential and actual security problems.
KEY ACCOUNTABILITIES & OUTCOMES
1. Support in reviewing and updating the Group IT Security Policies and Standards
- Review local IT Security Policies and Standards.
- Perform gap analysis and engage Regional IT Security representatives to discuss gaps.
- Provide recommendations of Group IT Security Policies to Unit Heads and Section Heads for review.
- Produce communications to the enterprise via portal or internal communications if required.
Outcome: Robust, standardized and industry‑standard Group IT Security Policies and Standards.
Challenges: Managing users and outsourcers to provide timely responses; obtaining understanding of regional and overseas units’ regulatory requirements; supporting Group‑wide IT Security Governance processes; proposing policies that suit different local businesses and regulators; conducting research and recommending control measures; presenting governance awareness; supporting various parties to ensure compliance; reviewing existing system security controls; checking non‑compliance against business requirements.
2. Develop Regional IT Security Governance processes
- Participate in discussions with Regional IT Security representatives to understand current local processes and challenges.
- Establish streamlined IT Security Governance processes to be used across the Group.
- Recommend the streamlined process to Unit Heads and Section Heads.
Outcomes: Standardized Group IT Governance Process; effective IT Security Governance across the Group; increased compliance level across the Group.
3. Justify and assess IT Risk associated with projects
- Enable the IT Risk Management process.
- Provide active guidance and consultation to the team on IT Security matters.
- Communicate and discuss with respective parties the associated risk and its mitigation.
Outcomes: Acceptable level of risk exposure to the Bank; proactive assessment and mitigation of risk exposure.
4. Provide security recommendations to stakeholders and support improvement plans
- Perform assessments to identify potential weaknesses and regulatory breaches.
- Provide security recommendations to stakeholders to ensure compliance with the Bank’s policies and regulator requirements.
- Support the proposed improvement plan.
Outcomes: Maintenance and enforcement of effective IT Security policies and standards; mitigation of risk exposure.
5. Interpret regional countries regulatory compliance and enforce in the Group
- Gather regional regulatory requirements, policies and guidelines.
- Map to existing BNM requirements and identify gaps.
- Establish draft Regional Compliance Checklist for review.
- Support enforcement of regional regulatory requirements to relevant projects based on scope and criteria.
Outcome: Ensure compliance with respective local regulators’ requirements.
6. Enable timely security assessment and remediation
- Obtain list of in‑scope applications.
- Coordinate with internal and external resources to perform the security assessment.
- Track end results, remediation and provide status updates.
Outcomes: Effective security assessment activity; overall visibility and effective management of major vulnerabilities; mitigation of risk exposure; compliance with regulators’ requirements.
7. Promote IT Security Processes through awareness programs
- Develop IT Security Awareness slides/material.
- Coordinate with audiences.
- Provide assistance for the awareness program.
Outcomes: Effective IT Security Governance process; reduced delay in project implementation due to insufficient documentation.
8. Evaluate change and firewall requests
- Review and assess change and firewall requests.
- Ensure requests comply with the Bank’s policies and standards.
- Approve or reject the request based on assessment.
Outcome: Protect the Bank by ensuring change and firewall requests are in accordance with the Bank’s policies and standards.
9. Safeguard information system assets
- Perform assessment on requests made by users.
- Review information assets to identify potential security weaknesses and mitigate accordingly.
Outcomes: Mitigate risk exposure to an acceptable level; continuous improvement for better protection.
EDUCATION
Minimum Bachelor Degree in Computer Science majoring in Security, Network or Computer System.
EXPERIENCE
6‑10 Years of IT Security related working experience in the Financial Services Industry (FSI)/Banking industry or similar environment.
CERTIFICATIONS/REGULATORY CERTIFICATIONS
Possess professional certifications such as ITIL, COBIT, CISSP, CEH and CHFI.
JOB SPECIFIC SKILLS & COMPETENCIES REQUIRED
- Knowledge in information security, specifically in compliance assessment, policy development and industry standard frameworks such as ISO 27001, PCI‑DSS, etc., preferably gained in the Financial Services sector; experience in service continuity desirable.
- Knowledge of regional FSI regulator requirements and guidelines (MAS, BI, BSP, BNM, PBOC, HKMA, etc.).
- Experience liaising with various stakeholders.
- Strong written and verbal communication skills in English to disseminate security messages and practices, contribute to documentation, and present ideas in business‑friendly language.
- Experience handling training classes; strong presentation and negotiation skills.
- Experience designing enterprise and operational level security policies, standards and processes (e.g., email & internet policy, password management process).
- Knowledge of network components and related protocols, security products/solutions; understanding of vulnerabilities in operating systems, databases and major applications, and ability to mitigate them.