Senior Executive - Data & Digital Governance

GAMUDA

Petaling Jaya

On-site

MYR 120,000 - 180,000

Full time

39 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Gamuda Berhad seeks a Senior Executive to lead Data & Digital Governance with experience in Information Security (ISO 27001), Data Privacy (ISO 27701), and IT governance frameworks. You will develop enterprise data protection strategies and ensure compliance with GDPR, PDPA and regional regulations across multiple countries.

The role requires coordinating cross-functional teams, implementing lifecycle management, and driving continuous improvement in information management and cybersecurity

Qualifications

  • Minimum 3 years in IT governance, compliance, audits or information security.
  • Experience with ISO 27001, ISO 27701 preferred.
  • Knowledge of GDPR, PDPA or regional privacy laws is a plus.

Responsibilities

  • Define and oversee information security policies aligned with ISO/IEC 27001.
  • Lead data governance, data lifecycle, and privacy management initiatives.
  • Coordinate audits, regulatory assessments and certification renewals.
  • Act as liaison with regulators, auditors and stakeholders on data/privacy matters.

Skills

Information security
Data governance
Privacy compliance
Cybersecurity controls

Education

Bachelor's degree in IT/CS/Engineering

Tools

DLP tools
Audit platforms

Job description

Data & Digital Governance of Gamuda Berhad, the Senior Executive with experience in Information Security (ISO 27001), Data Privacy (ISO 27701), and IT Governance frameworks. Experienced in establishing enterprise-wide data protection strategies, ensuring compliance with global privacy and cybersecurity laws such as the GDPR, PDPA, and other regional data protection regulations in countries such as Malaysia, Singapore, Vietnam, Australia and others.

Strong background in aligning information governance initiatives with organizational objectives, integrating cybersecurity controls, data lifecycle management, and risk-based compliance frameworks to protect corporate assets and stakeholder interests. Skilled in leading cross-functional teams to drive digital trust, regulatory adherence, and continual improvement in information management practices across diverse business environments.

Key Responsibilities

Job description:

Job Summary

Data & Digital Governance of Gamuda Berhad, the Senior Executive with experience in Information Security (ISO 27001), Data Privacy (ISO 27701), and IT Governance frameworks. Experienced in establishing enterprise-wide data protection strategies, ensuring compliance with global privacy and cybersecurity laws such as the GDPR, PDPA, and other regional data protection regulations in countries such as Malaysia, Singapore, Vietnam, Australia and others.

Strong background in aligning information governance initiatives with organizational objectives, integrating cybersecurity controls, data lifecycle management, and risk-based compliance frameworks to protect corporate assets and stakeholder interests. Skilled in leading cross-functional teams to drive digital trust, regulatory adherence, and continual improvement in information management practices across diverse business environments.

Key Responsibilities
  • ISO Related Matters
    • Define and oversee the execution of information security policies, standards, and controls to safeguard corporate assets.
    • Ensure the implementation, and continual improvement of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001.
    • Conduct risk assessments and ensure mitigation strategies are effectively implemented across business units.
  • Data Governance and Management
    • Define and oversee the execution of Data Management related policies, standards and controls to data/ information of the Gamuda.
    • Implement and maintain the Privacy Information Management System (PIMS) based on ISO/IEC 27701.
    • Drive compliance with global privacy laws and regulations (e.g., GDPR, PDPA) and ensure data subject rights are respected.
    • Oversee data inventory, data flow mapping, and privacy impact assessments (PIAs/DPIAs).
    • Assist DPO for any Data related matters across the group.
    • Serve as the key liaison with regulators, auditors, and external stakeholders on data and cybersecurity matters.
    • Advocate for a culture of security and privacy through continuous awareness and training initiatives.
  • Cybersecurity and Compliance Integration
    • Collaborate with IT and Legal Department to align cybersecurity measures with regulatory requirements.
    • Monitor emerging cyber laws, data protection frameworks, and regulatory trends globally, advising the organization on compliance implications.
    • Manage internal and external audits, regulatory assessments, and certification renewals.
    • Benchmark against global standards and incorporate lessons learned from incidents, audits, and regulatory feedback.
Qualifications

Minimum Bachelor degree in Computer Science, Information Technology, Computer Engineering or its equivalent in IT related field.

Skills & Abilities
  • Candidates holding an ISACA CISA, CGEIT, ISO 27001 & ISO 27701 Lead Auditor, CRISC, CISSP certification are preferred.
  • Experience and knowledge of ISO 27701, PDPA, GDPR and other related privacy regulations are preferred.
  • Knowledge of IT security, incident management, data protection tools, encryption technologies, and DLP mechanisms.
  • Experience with internal/external audit management and compliance monitoring platforms.
  • Document control related work experience is an added advantage.
Expected Minimum Years of Experience

At least 3 years experience in IT/Governance, compliance, IT Audits, Data management or Information Security.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Executive - Data & Digital Governance
Senior Executive - Data & Digital Governance

Gamuda Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
Senior Data & Privacy Governance Lead
Senior Data & Privacy Governance Lead

GAMUDA • Petaling Jaya

On-site
MYR 120,000 - 180,000
Data & Privacy Governance Lead
Data & Privacy Governance Lead

Gamuda Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
Manager - Data Protection, Privacy & Data Governance
Manager - Data Protection, Privacy & Data Governance

GAMUDA LAND • Petaling Jaya

On-site
MYR 120,000 - 180,000
Senior Manager, Data Governance
Senior Manager, Data Governance

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 80,000 - 120,000
Manager – ICT Governance & Compliance
Manager – ICT Governance & Compliance

Scicom MSC Berhad • Kampung Cendana

On-site
MYR 71,000 - 85,000
Salary up to RM7000
Medical insurance
Medical and hospitalization leaves
+1
Data Protection & Privacy Lead — IT & Governance
Data Protection & Privacy Lead — IT & Governance

GAMUDA LAND • Petaling Jaya

On-site
MYR 120,000 - 180,000
Senior Legal Counsel (Strategic)
Senior Legal Counsel (Strategic)

Maxis • Kuala Lumpur

On-site
MYR 300,000 - 420,000
IT Governance Manager
IT Governance Manager

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Data Privacy Officer
Data Privacy Officer

Businesslist • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Medical benefits