Get more replies from employers
Send a job-specific resume in minutes.
Hong Leong Finance Limited is seeking a senior IT security professional to drive secure-by-design architecture reviews within MAS TRM guidelines. You will lead governance, risk, and compliance activities across projects, cloud services, and third-party integrations.
You will promote secure design principles, conduct practical training, and engage stakeholders to mitigate technology risks while maintaining regulatory alignment.
The role will be responsible for driving secure-by-design assessments and MAS Technology Risk Management Guidelines reviews across system architectures, technology projects, applications, and infrastructure changes. As part of the IT Security team, the role will provide cyber assurance by assessing architecture designs, identifying security and regulatory gaps early in the technology lifecycle, and ensuring appropriate controls are embedded before implementation. You will act as a trusted advisor to IT project, infrastructure and application teams, promoting secure design principles, MAS TRM alignment, and practical risk mitigation across the organization.
The key responsibilities of the role include:
Develop and maintain cybersecurity governance framework aligned with MAS Technology Risk Management Guidelines, with emphasis on translating regulatory expectations into practical architecture review criteria, secure design standards, and control requirements.
Lead secure-by-design assessments for new systems, major enhancements, infrastructure changes, cloud services, APIs, and third-party technology integrations; identify architecture risks, control gaps, and remediation actions before production implementation.
Perform MAS TRM Guidelines reviews for system architectures and technology initiatives, ensuring compliance with regulatory expectations for technology risk governance, security controls, resilience, access management, data protection, and third-party dependencies.
Develop and update security policies, standards, architecture review checklists, and secure design guidelines; drive awareness and adoption across IT and business project teams.
Manage vendor security assessments and review third-party solution architectures to ensure security, resilience, data protection, and MAS TRM-related requirements are adequately addressed.
Promote a secure-by-design culture and conduct practical training for IT teams on architecture risk assessment, MAS TRM considerations, and early security engagement in project delivery.
Track KRIs and security KPIs and prepare GRC reports for management updates.
Support incident response and maintain documentation for audit purposes.
Act as a trusted security advisor to project, application, infrastructure, and architecture teams by providing timely guidance on secure design, regulatory alignment, and pragmatic risk mitigation options.
The successful candidate can expect a competitive package that includes an attractive basic salary, annual bonus and variable bonus.
(We regret that only shortlisted candidates will be notified)