Manager I, Cyber Security

Worley

Kuala Lumpur

On-site

MYR 180,000 - 300,000

Full time

32 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work arrangements
Competitive remuneration & employee’s

Job summary

Worley, a global energy and resources company, is seeking a Manager I, Cyber Security for its Malaysia operations. The role focuses on assessing security control exceptions, managing deviations from standards, and supporting risk management across the supplier ecosystem.

The candidate will drive continuous improvement of Worley’s cybersecurity practices and collaborate with Legal, Procurement, Privacy, Digital teams and business units.

Qualifications

  • Bachelor’s degree in a relevant field, or equivalent.
  • Certifications such as CISM, CRISC, ISO27001 Lead Auditor, CISSP, CISA are preferred.
  • Demonstrated ability to partner with stakeholders and align IT with business strategy.

Responsibilities

  • Lead the information security risk management program, including assessments and third-party risk oversight.
  • Coordinate internal and external audits and ensure certification requirements are met.
  • Develop and coach the team to deliver on operational objectives and strategic outcomes.
  • Embed information security requirements within onboarding processes and contractual arrangements.

Skills

Stakeholder collaboration
Full technology stack awareness
Attention to detail
Risk assessment documentation
Data handling & confidentiality

Education

Bachelor's degree
IT security certifications (CISM, CRISC, CISSP, etc.)

Tools

MS Visio
MS SharePoint

Job description

About Us

Worley is a global company of energy, chemicals and resources experts headquartered in Australia. We partner with our customers to deliver projects and create value across the life of their assets. We specialize in consulting, engineering, procurement and construction across the project lifecycle, with services extending through to operations and decommissioning. Leveraging extensive experience and AI-enabled delivery, we support customers in navigating complexity as they meet today's needs and transition to more sustainable solutions.

About Us

Worley is a global company of energy, chemicals and resources experts headquartered in Australia. We partner with our customers to deliver projects and create value across the life of their assets. We specialize in consulting, engineering, procurement and construction across the project lifecycle, with services extending through to operations and decommissioning. Leveraging extensive experience and AI-enabled delivery, we support customers in navigating complexity as they meet today's needs and transition to more sustainable solutions.

About The Job

We’re looking for a Manager I, Cyber Security to join our Malaysia team.

As a Manager I, Cyber Security, you will be responsible for working with various stakeholders across Worley to assess and manage exceptions from security control implementation, including web filtering, network controls, data loss prevention controls and others. This position will also manage the process for deviations from company information security standards. Additionally, this position supports information security risk management and third-party risk management tasks to continuously improve Worley’s cybersecurity practices.

To succeed in this role, you should have experience in information security or information technology.

What You’ll Do

We are looking for a Manager I, Cyber Security to join our team Malaysia.

The Role Responsibilities Include
  • 2nd Line of Defence in IIA Three Lines of Defence Model.
  • Lead the supplier information security risk management program, including security assessments, assurance reviews, remediation oversight, and ongoing monitoring of third-party security risks.
  • Collaborate with Procurement, Legal, Privacy, Digital, and business stakeholders to ensure information security requirements are embedded within supplier onboarding processes, contractual arrangements, and business operations.
  • Manage and continuously enhance the Information Security Management System (ISMS), including maintaining ISO/IEC 27001 certification, coordinating internal and external audits, overseeing corrective actions, and ensuring ongoing compliance with certification requirements.
  • Own and administer the Digital Risk Register and Information Security Risk Register, including facilitating risk identification, assessment, treatment, monitoring, reporting, and periodic review in alignment with enterprise risk management requirements.
  • Conduct and facilitate information security risk assessments, including the evaluation of proposed deviations from security standards, policies, and control requirements.
  • Coordinate and support internal and external audits, certification activities, customer security assurance requests, and regulatory reviews.
  • Lead, coach, and develop team members while ensuring delivery of operational objectives, continuous improvement initiatives, and strategic program outcomes.
Education – Qualifications, Accreditation, Training:
  • A relevant bachelor’s degree.
  • Certifications such as – CISM, CRISC, ISO27001 Lead Auditor, ISO42001 Lead Auditor, CISSP, CISA
  • 10 + years of experience in information security or information technology.
Job Specific Knowledge / Experience
  • Demonstrated ability to partner and collaborate effectively with stakeholders, demonstrating an appreciation of both IT and business strategy.
  • Advanced awareness of full technology stack.
  • Exceptional attention to detail, with the aptitude to collect, analyze and conclude on data.
  • Demonstrated ability to produce clear, concise, and logical risk assessment documentation.
  • Operational knowledge of data handling and confidentiality.
  • Ability to work in a fast-paced unstructured customer-centric environment across multiple geographies and operational contexts.
  • Knowledge of frameworks including ITIL, COBIT, NIST CSF (Cyber Security Framework), Essential 8 and ISO27001.
IT Skills
  • Advanced user in MS Office applications (including MS Visio) and MS SharePoint
  • Advanced awareness of full technology stack.
People Skills
  • Interpersonal: Builds appropriate, constructive, and effective business relationships throughout the organization; uses diplomacy and tact; is approachable; communicates clearly, accurately, and consistently both verbally and in written matters. Employs the principles of active listening and encourages feedback from others.
  • Teamwork: Enjoys working in a small high caliber team with high visibility to senior stakeholders. Able to work and liaise with multiple teams and stakeholders, able to prioritize workloads and help other team members to achieve team goals.
  • Action Orientation: Achieves results set by self and others, meets timelines, pushes to achieve stretch goals, and demonstrates enthusiasm, persistence, and tenacity. Breaks down work into executable tasks.
  • Intellectual Capacity - Deals with new concepts and complexity comfortably. Examines problems carefully and thoroughly and understands their interdependencies. Can pull information and ideas from many sources and see the importance of many factors.
Flexible Working Arrangements
  • This is a global role and will require flexibility to work across multiple time zones.
Why you should apply
  • Flexible work arrangements.
  • Take advantage of our global on-line learning platform!
  • Competitive remuneration & employee benefits.
  • Enjoy a varied & challenging role.
  • Career development opportunities beyond this role.
Moving forward together

We want our people to be energized and empowered to drive sustainable impact. So, our focus is on a values-inspired culture that unlocks brilliance through belonging, connection and innovation. We're building a diverse, inclusive and respectful workplace. Creating a space where everyone feels they belong, can be themselves, and are heard.

And we're not just talking about it; we're doing it. We're reskilling our people, leveraging transferable skills, and supporting the transition of our workforce to become experts in today's low carbon energy infrastructure and technology. Whatever your ambition, there's a path for you here.

And there's no barrier to your potential career success. Join us to broaden your horizons, explore diverse opportunities, and be part of delivering sustainable change.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager I, Cyber Security
Manager I, Cyber Security

WorleyParsons • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Cyber Security Manager I: ISMS, Risk & Compliance Lead
Cyber Security Manager I: ISMS, Risk & Compliance Lead

Worley • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Flexible work arrangements
Competitive remuneration & employee’s
Senior Marketing Coordinator
Senior Marketing Coordinator

WorleyParsons • Malaysia

On-site
MYR 65,000 - 95,000
Cyber Security Program Manager ISMS & Risk
Cyber Security Program Manager ISMS & Risk

WorleyParsons • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Manager, Cybersecurity Engineering - Operations
Manager, Cybersecurity Engineering - Operations

SD Guthrie • Selangor

Hybrid
MYR 240,000 - 420,000
Flexible Benefits
Hybrid Workplace
Learning on Demand
+3
Project Accountant at Wood
Project Accountant at Wood

Wood • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Cyber Security Engagement Manager
Cyber Security Engagement Manager

Wizlynx Malaysia Sdn Bhd • Kuala Lumpur

On-site
Head of Information Technology
Head of Information Technology

Talenta Consultants • Kuala Lumpur

On-site
MYR 240,000 - 420,000
Staff IT Security Engineer
Staff IT Security Engineer

Michael Page • Penang

On-site
MYR 194,000 - 238,000
Comprehensive benefits
Permanent position
Business Consulting - Customer (Energy), Senior Associate
Business Consulting - Customer (Energy), Senior Associate

Ernst & Young Advisory Services Sdn Bhd • Kuala Lumpur

On-site
MYR 130,000 - 180,000
Flexible working arrangements