Security Engineer

Agensi Pekerjaan Penta Consultancy Sdn. Bhd

Kuala Lumpur

Vor Ort

MYR 180.000 - 240.000

Vollzeit

vor 36 Stunden
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Bekomme eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Agensi Pekerjaan Penta Consultancy Sdn. Bhd in Kuala Lumpur seeks an experienced Information Security and IT Risk Manager to lead governance, risk assessment, and regulatory compliance efforts within a financial services context.

You will coordinate risk reporting, risk appetite, audit support, and third-party security assessments, working with senior stakeholders to translate complex risks into actionable mitigations.

Qualifikationen

  • Bachelor's degree (preferably in IT), such as Computer Science, Computer Engineering, Information Systems, or related field, or equivalent experience.
  • Minimum of 8 years of relevant experience in information and cybersecurity risk management, preferably within the financial services industry.
  • Possession of industry-recognized information security certifications (e.g., CISSP, CISA, CISM, CRISC, CGEIT) is an added advantage.
  • Excellent verbal and written communication skills in English, with the ability to engage effectively with both technical and non-technical senior stakeholders.

Aufgaben

  • Support the maintenance and enhancement of the technology risk governance framework, including efforts to achieve relevant certifications.
  • Assist in ensuring compliance with Bank Negara Malaysia's RMiT policy and other applicable regulatory requirements.
  • Contribute to the development and periodic review of IT and cybersecurity risk appetite statements and governance strategies.
  • Provide oversight on governance practices and control measures related to technology and cybersecurity risks.
  • Assist in coordinating the Information Security Working Committee and other related governance forums.
  • Lead and perform periodic control and risk assessments, ensuring thorough coverage across all critical technology and cybersecurity areas.
  • Record, monitor, and report risk assessment outcomes, clearly communicating risk exposure and recommended actions to stakeholders.
  • Serve as the primary owner for open risk items, ensuring proper tracking, timely escalation, and effective remediation by responsible parties.
  • Develop and present key risk metrics and reports for management review.
  • Provide control assurance support, including facilitating risk assessments, managing deviations, and overseeing mitigation plans.
  • Support internal and external audit activities, including coordinating control assessments and ensuring regulatory compliance.
  • Perform third-party security risk assessments (TPSA) and contribute to supply chain risk management initiatives.
  • Monitor and follow up on audit findings to ensure timely resolution and closure.
  • Track external threat intelligence and elevate emerging risks when necessary.
  • Support the review, maintenance, and publication of information security policies, standards, and procedures.
  • Assist in the approval process and facilitate the training and communication of security policies and best practices.
  • Monitor adherence to cybersecurity policies and controls across the IT function.
  • Propose enhancements to policies and procedures to improve operational efficiency and ensure regulatory compliance.

Kenntnisse

Information security risk management
Regulatory compliance
Risk assessment
Policy development
Governance
Audit coordination

Ausbildung

Bachelor's degree in IT

Jobbeschreibung

Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia

  • Support the maintenance and enhancement of the technology risk governance framework, including efforts to achieve relevant certifications.
  • Assist in ensuring compliance with Bank Negara Malaysia's RMiT policy and other applicable regulatory requirements.
  • Contribute to the development and periodic review of IT and cybersecurity risk appetite statements and governance strategies.
  • Provide oversight on governance practices and control measures related to technology and cybersecurity risks.
  • Assist in coordinating the Information Security Working Committee and other related governance forums.
  • Lead and perform periodic control and risk assessments, ensuring thorough coverage across all critical technology and cybersecurity areas.
  • Record, monitor, and report risk assessment outcomes, clearly communicating risk exposure and recommended actions to stakeholders.
  • Serve as the primary owner for open risk items, ensuring proper tracking, timely escalation, and effective remediation by responsible parties.
  • Develop and present key risk metrics and reports for management review.
  • Provide control assurance support, including facilitating risk assessments, managing deviations, and overseeing mitigation plans.
  • Support internal and external audit activities, including coordinating control assessments and ensuring regulatory compliance.
  • Perform third-party security risk assessments (TPSA) and contribute to supply chain risk management initiatives.
  • Monitor and follow up on audit findings to ensure timely resolution and closure.
  • Track external threat intelligence and elevate emerging risks when necessary.
  • Support the review, maintenance, and publication of information security policies, standards, and procedures.
  • Assist in the approval process and facilitate the training and communication of security policies and best practices.
  • Monitor adherence to cybersecurity policies and controls across the IT function.
  • Propose enhancements to policies and procedures to improve operational efficiency and ensure regulatory compliance.
Job Requirements
  • Bachelor's degree (preferably in IT), such as Computer Science, Computer Engineering, Information Systems, or a related field, or equivalent experience.
  • Minimum of 8 years of relevant experience in information and cybersecurity risk management, preferably within the financial services industry.
  • Possession of industry-recognized information security certifications (e.g., CISSP, CISA, CISM, CRISC, CGEIT) is an added advantage.
  • Excellent verbal and written communication skills in English, with the ability to engage effectively with both technical and non-technical senior stakeholders.
  • Strong listening, negotiation, and interpersonal skills.
  • Ability to work independently while also collaborating effectively as part of a team.
  • Solid understanding of technology and operations, including cloud environments.
  • Good knowledge of the insurance business domain and its key success factors.
  • Highly resourceful with strong attention to detail, and the ability to gather, analyze, and interpret data across multiple IT and business disciplines.
  • Strong conceptual and analytical thinking skills, with the ability to synthesize diverse information into meaningful risk insights and recommendations.
  • Knowledge of aligning IT risk responses with evolving business needs and regulatory requirements.
  • In-depth understanding of business risk, IT governance, enterprise risk management, information security, and local regulatory compliance requirements.
  • Ability to develop a comprehensive understanding of the insurance business, market, and industry, and apply this knowledge to identify operational and IT-related risks.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

SE, Infrastructure - Group Tech Risk
SE, Infrastructure - Group Tech Risk

AmBank Group • Kampung Malaysia Tambahan

Vor Ort
MYR 120.000 - 180.000
IT Security Governance
IT Security Governance

GoKardz Technologies • Kuala Lumpur

Vor Ort
MYR 90.000 - 120.000
Security Governance Assistant Manager
Security Governance Assistant Manager

Boost Holdings Sdn Bhd • Kuala Lumpur

Vor Ort
MYR 150.000 - 210.000
VP, Technology & Cyber Risk Management
VP, Technology & Cyber Risk Management

AmBank Group • Kampung Malaysia Tambahan

Vor Ort
MYR 150.000 - 210.000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting • Kuala Lumpur

Vor Ort
MYR 180.000 - 260.000
Manager – IT (Cybersecurity Risk & Policy)
Manager – IT (Cybersecurity Risk & Policy)

Mindteck, Inc. • Sepang

Vor Ort
MYR 180.000 - 280.000
Head of Cybersecurity
Head of Cybersecurity

Ryt Bank • Kuala Lumpur

Vor Ort
MYR 240.000 - 420.000
Infrastructure Information Security Manager
Infrastructure Information Security Manager

Flintex Consulting Pte Ltd • Kuala Lumpur

Vor Ort
MYR 179.000 - 223.000
Manager – ICT Governance & Compliance
Manager – ICT Governance & Compliance

Scicom MSC Berhad • Kampung Cendana

Vor Ort
MYR 71.000 - 85.000
Salary up to RM7000
Medical insurance
Medical and hospitalization leaves
+1
Information & Cybersecurity, Consultant
Information & Cybersecurity, Consultant

AIA Malaysia • Kuala Lumpur

Vor Ort
MYR 70.000 - 90.000