Senior IT Risk & Security Governance Engineer

Agensi Pekerjaan Penta Consultancy Sdn. Bhd

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

39 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Agensi Pekerjaan Penta Consultancy Sdn. Bhd in Kuala Lumpur seeks an experienced Information Security and IT Risk Manager to lead governance, risk assessment, and regulatory compliance efforts within a financial services context.

You will coordinate risk reporting, risk appetite, audit support, and third-party security assessments, working with senior stakeholders to translate complex risks into actionable mitigations.

Qualifications

  • Bachelor's degree (preferably in IT), such as Computer Science, Computer Engineering, Information Systems, or related field, or equivalent experience.
  • Minimum of 8 years of relevant experience in information and cybersecurity risk management, preferably within the financial services industry.
  • Possession of industry-recognized information security certifications (e.g., CISSP, CISA, CISM, CRISC, CGEIT) is an added advantage.
  • Excellent verbal and written communication skills in English, with the ability to engage effectively with both technical and non-technical senior stakeholders.

Responsibilities

  • Support the maintenance and enhancement of the technology risk governance framework, including efforts to achieve relevant certifications.
  • Assist in ensuring compliance with Bank Negara Malaysia's RMiT policy and other applicable regulatory requirements.
  • Contribute to the development and periodic review of IT and cybersecurity risk appetite statements and governance strategies.
  • Provide oversight on governance practices and control measures related to technology and cybersecurity risks.
  • Assist in coordinating the Information Security Working Committee and other related governance forums.
  • Lead and perform periodic control and risk assessments, ensuring thorough coverage across all critical technology and cybersecurity areas.
  • Record, monitor, and report risk assessment outcomes, clearly communicating risk exposure and recommended actions to stakeholders.
  • Serve as the primary owner for open risk items, ensuring proper tracking, timely escalation, and effective remediation by responsible parties.
  • Develop and present key risk metrics and reports for management review.
  • Provide control assurance support, including facilitating risk assessments, managing deviations, and overseeing mitigation plans.
  • Support internal and external audit activities, including coordinating control assessments and ensuring regulatory compliance.
  • Perform third-party security risk assessments (TPSA) and contribute to supply chain risk management initiatives.
  • Monitor and follow up on audit findings to ensure timely resolution and closure.
  • Track external threat intelligence and elevate emerging risks when necessary.
  • Support the review, maintenance, and publication of information security policies, standards, and procedures.
  • Assist in the approval process and facilitate the training and communication of security policies and best practices.
  • Monitor adherence to cybersecurity policies and controls across the IT function.
  • Propose enhancements to policies and procedures to improve operational efficiency and ensure regulatory compliance.

Skills

Information security risk management
Regulatory compliance
Risk assessment
Policy development
Governance
Audit coordination

Education

Bachelor's degree in IT

Job description

Agensi Pekerjaan Penta Consultancy Sdn. Bhd in Kuala Lumpur seeks an experienced Information Security and IT Risk Manager to lead governance, risk assessment, and regulatory compliance efforts within a financial services context.

You will coordinate risk reporting, risk appetite, audit support, and third-party security assessments, working with senior stakeholders to translate complex risks into actionable mitigations.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations & Compliance Specialist
Security Operations & Compliance Specialist

Agensi Pekerjaan Penta Consultancy Sdn. Bhd • Kuala Lumpur

On-site
MYR 45,000 - 78,000
Security Engineer
Security Engineer

Agensi Pekerjaan Penta Consultancy Sdn. Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Information Security & Risk Leader
Senior Information Security & Risk Leader

Prudential Services Asia • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior IT Security Manager: Risk, Compliance & Incident Response
Senior IT Security Manager: Risk, Compliance & Incident Response

Agensi Pekerjaan Minde Group Sdn Bhd • Penang

On-site
MYR 180,000 - 270,000
IT Governance & Risk Lead: PAM & IAM
IT Governance & Risk Lead: PAM & IAM

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Regional IT Security Governance Lead
Regional IT Security Governance Lead

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Senior IT GRC Lead
Senior IT GRC Lead

Revenue Group Berhad • Petaling Jaya

On-site
MYR 72,000 - 120,000
Senior Information Security & Risk Leader, SC GTRM & PAM
Senior Information Security & Risk Leader, SC GTRM & PAM

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 300,000
IAM Governance & Compliance Lead
IAM Governance & Compliance Lead

Agensi Pekerjaan Penta Consultancy Sdn. Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Risk & Quality Manager: Governance & Compliance
Risk & Quality Manager: Governance & Compliance

PwC • Kuala Lumpur

On-site
MYR 180,000 - 260,000