Job Search and Career Advice Platform

Enable job alerts via email!

IT Security Manager

eTeam

Kuala Lumpur

On-site

MYR 90,000 - 120,000

Full time

2 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial services provider in Kuala Lumpur is seeking to hire a specialist to support the Global Head of Third Party Security Risk. This role involves managing third party security risks, performing reviews, and ensuring compliance with regulations. Candidates should possess a Bachelor's degree, strong communication skills, and ideally 5 years of relevant experience in information security or IT auditing. Familiarity with security frameworks is a plus. This position offers an opportunity to engage with stakeholders at all levels in a dynamic environment.

Qualifications

  • 5 years of experience in information security / IT auditing, ideally with Big 4 and/or Banking & Financial services.
  • Experience in third party audits and understanding of auditing standards, compliance, risk assessment, and internal control frameworks.
  • Familiarity with working in a MNC or cross-cultural settings.

Responsibilities

  • Support the Global Head of Third Party Security Risk in delivering security risk programs.
  • Perform third party security reviews and communicate risks to stakeholders.
  • Provide weekly and ad hoc reporting on the status of reviews.
  • Maintain a register of third party security risks.

Skills

Strong communication skills in English
Stakeholder engagement
Time management skills
Ability to draft reports
Strong audit project organisation
Multitasking ability
Knowledge of security frameworks

Education

Bachelor degree or above from an accredited college/university

Tools

Microsoft Office Suite (Word, PowerPoint, Excel, Visio, SharePoint)
Job description
  • The main responsibilities will be to support the Global Head of Third Party Security Risk in delivering the third party security risk program within the Bank.
Strategy
  • The main responsibilities will be to support the Global Head of Third Party Security Risk in delivering the third party security risk program within the Bank.
Business
  • Effectively perform third party security reviews, and ensure quality and timely execution.
  • Make timely and sound judgments, and identify clear solutions from broad, complex or ambiguous situations.
  • Interact with all levels of management within the Bank while performing third party security reviews of service providers across all of the Bank's markets.
  • Effectively communicate the security risks to internal and external stakeholders.
  • Effectively communicate and manage relationships with stakeholders globally.
Processes
  • Diligently provide weekly and ad hoc reporting on status of reviews.
  • Support any training and awareness initiatives relating to third party security risk.
  • Support and assist in third party program improvement initiatives
  • Assist in the development of new/amended processes, innovative ways of working and reviewing risk and control assessments.
  • Assist in the forward planning and prioritisation of vendor assessments or requests from business stakeholders, and resource allocations.
People and Talent

N/A This is not a managerial role

Risk Management
  • Maintain a register of third party security risks and ensure that deficiencies are mitigated.
  • Support the Global Head of TPSR to ensure compliance with relevant regulations covering third party security risk.
  • Monitor and report on third party security risk compliance to stakeholders.
  • Remain current on industry trends and regulatory requirements related to third party information security
Key Roles & Responsibilities
  • Manage a register of third party security risks and ensure that deficiencies are mitigated.
  • Support any training and awareness initiatives relating to third party security risk.
Governance
  • Diligently provide weekly and ad hoc reporting on status of reviews.
Regulatory & Business conduct

(This is mandatory standard wording, please tailor wording in brackets, do not remove)

  • Display exemplary conduct and live by the Group's Values and Code of Conduct.
  • Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Client. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
  • Follow the Leadership of Global Head of TPSR to achieve the outcomes set out in the Bank's Conduct Principles: Fair Outcomes for Clients; Effective Operation of Financial Markets, Financial Crime Prevention; Creating the Right Environment.
  • Effectively and collaboratively identify, elevate, mitigate and resolve risk, conduct and compliance matters.
Key Stakeholders
  • Supply Chain Management
  • Business Functions
Other Responsibilities
  • Embed "Here for Good" and Group's brand and values in the TPSR Team
  • Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures.
QUALIFICATIONS
  • Bachelor degree or above from an accredited college/university in an appropriate field.
  • Strong communication skills in English
  • Ideally 5 years of experience in information security / IT auditing, with Big 4 and/or Banking & Financial services experience
  • Experience in third party audits is a plus, but understanding of auditing standards, compliance, risk assessment and internal control frameworks is a requirement.
  • Familiarity with working in a MNC or cross-cultural setting.
  • Excellent written and interpersonal skills.
  • Strong time management skills.
  • Ability to draft reports that clearly communicate observations and risks would be required.
  • Strong stakeholder engagement skills, and ability to interact at all levels across an organisation.
  • Strong audit project organisation and management skills.
  • Ability to multitask and ensure that all key priorities are delivered as per agreed timelines.
  • Knowledge of security frameworks (e.g. COBIT, ISF, COSO), standards (e.g. ISO, NIST, CIS), information security principles, security architecture and regulatory requirements will be a plus.
  • Competency with Microsoft Office Suite (Word, PowerPoint, Excel, Visio, SharePoint).
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.