Stand out for this role — generate a tailored resume and cover letter in about a minute.
Software International Corporation in Kuala Lumpur is seeking a Reverse TPSA Manager to lead third-party security assessments and coordinate responses to client due diligence requests. You will work with Information Security, Privacy, Legal, and Compliance teams to articulate the company’s security posture and control environment while protecting confidential information.
The role emphasizes coordinating TPSA activities, responding to RFSIs, client audits, and cybersecurity questionnaires,
Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
Software International Corporation – Kuala Lumpur, Kuala Lumpur
The Reverse TPSA Manager is responsible for managing and coordinating security, technology risk,
privacy, and compliance assessments conducted by company’s clients, brokers, consultants, and
prospective customers.
The role serves as the central point of contact for all client security due diligence activities, ensuring
timely and accurate responses to Third-Party Security Assessments (TPSAs), Requests for Security
Information (RFSIs), client audits, and cybersecurity questionnaires. The individual will work closely
with Information Security, Technology, Risk Management, Legal, Compliance, Privacy, Procurement,
and Business Units to articulate company’s security posture and control environment while
protecting confidential and proprietary information.
This role is critical in enabling business growth, strengthening client trust, and demonstrating
company's commitment to cybersecurity, operational resilience, and regulatory compliance.
Lead and manage end-to-end client Third-Party Security Assessment (TPSA) activities.
Serve as the primary coordinator for security due diligence requests from Corporate Solutions clients and prospective customers.
Review, assess, and complete security questionnaires covering cybersecurity, cloud security, data protection, operational resilience, business continuity, and regulatory compliance.
Ensure responses are accurate, consistent, evidence-based, and aligned with company’s security standards.
Track TPSA requests and ensure completion within agreed timelines and service levels.
Represent company's cybersecurity and technology risk control environment during client due diligence engagements.
Support client discussions, workshops, and security review meetings.
Explain technical controls and security practices in clear business language suitable for nontechnical stakeholders.
Address security concerns raised by clients and coordinate responses with relevant subject matter experts.
- Collaborate with:
- Coordinate collection of evidence and validation of control effectiveness.
- Escalate complex security or compliance issues where required.
- Maintain a centralized repository of:
- Ensure all externally shared information complies with company's information classification and disclosure requirements.
- Conduct periodic reviews of security response libraries to maintain accuracy and relevance.
- Support responses related to:
- Ensure client responses remain aligned with prevailing regulatory obligations and corporate policies.
Develop and maintain TPSA performance metrics and reporting dashboards.
Monitor trends in client security requirements and emerging cybersecurity expectations.
Identify recurring assessment themes and recommend process improvements.
Improve automation, standardization, and efficiency of security assessment responses.
Cybersecurity & Risk Knowledge
- Strong understanding of:
Frameworks & Regulations
- Knowledge of:
Excellent written communication and documentation skills.
Ability to respond to detailed client security questionnaires.
Strong stakeholder engagement and influencing capabilities.
Ability to translate technical controls into concise business-friendly responses.
Strong presentation and facilitation skills.
Strong problem-solving and critical-thinking capabilities.
Ability to assess client requirements and map them to existing controls.
Ability to identify gaps, risks, and potential remediation actions.