Turn this role into an interview — a resume and cover letter built around what this employer wants.
TMF Group in Malaysia seeks a local information security and security continuity specialist to service ISMS, BCP, ERP, and physical security. You will act as the main contact for security matters, ensuring compliance with ISO 27001 and related standards while coordinating initiatives across the organisation.
You will support audits, manage incident reporting, and collaborate with asset owners on risk assessments, training staff, and aligning local plans with global standards.
Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
This role serves as the local point of contact for all information security, business continuity, emergency response, and physical security matters. The position ensures compliance with global frameworks, ISO standards, and local regulations while coordinating security initiatives across the organisation.
1. Information Security (ISMS)
Act as the local point of contact for all information security matters.
Ensure compliance with TMF’ s global Information Security Management Framework and underlying policies, procedures, and standards.
Ensure compliance with ISO 27001 and ISAE 3402 standards.
Support internal and external audits related to information security.
Follow up on the closure of the corrective and preventive action plan for the reported non-conformities and observations.
Report and escape security incidents to the Global Information Security Officer (GISO).
Co-ordinating with asset and process owners for periodic review of asset list and risk assessment.
Conduct periodic security awareness training for staff.
2. Business Continuity Planning (BCP)
Maintain and update the local Business Continuity Plan.
Coordinate regular BCP testing and simulations.
Ensure critical business functions are identified and recovery strategies are in place.
Support the implementation of the Business Continuity Management System (BCMS) ISO22301
Liaise with global and regional BCP teams to align local plans with corporate standards.
3. Emergency Response Planning (ERP)
Develop and maintain emergency response procedures for the local office.
Coordinate with building management and local authorities during emergencies.
Ensure emergency contact lists and communication protocols are up to date.
4. Physical Security
Oversee access control systems, visitor management, and office security measures.
Conduct regular security risk assessments and recommend improvements.
Manage relationships with security vendors and service providers.
5. Compliance & Reporting
Ensure compliance with local laws and regulations related to security and safety.
Prepare and submit regular reports on security incidents, audit findings, and risk assessments
Participate in regional and global security meetings and initiatives.
Bachelor's degree in Information Security, Risk Management, or related field
Minimum 2 years of experience in a security, compliance, or risk management role
Familiarity with ISO 27001, BCP/ERP frameworks, and emergency response protocols
Strong communication and coordination skills
Ability to work independently and manage multiple priorities
Bachelor’s degree in a relevant field is an advantage