about the company
A leading financial services organisation with a strong focus on technology, cybersecurity and data protection is strengthening its information security capabilities. The organisation operates within a highly regulated environment and places strong emphasis on protecting sensitive customer data, maintaining robust security controls, and meeting regulatory and Group cybersecurity standards.
This is an opportunity to join an established technology and cybersecurity environment where you will work closely with Technology, Business and Group stakeholders to strengthen the organisation’s overall security and risk posture.
...
about the job
We are looking for an Information & Cybersecurity Consultant to strengthen the organisation’s cybersecurity, data protection and technology risk capabilities.
In this role, you will provide cybersecurity advisory across technology initiatives, conduct risk and controls assessments, support regulatory and audit requirements, and help ensure effective implementation and operation of security controls.
Key responsibilities include:
- Provide cybersecurity guidance and review solution designs for technology projects and initiatives.
- Advise on secure architecture, application security and appropriate cybersecurity controls.
- Manage and govern Data Loss Prevention (DLP) and cryptographic controls, including DLP recertification and key management processes.
- Support compliance with BNM RMiT, regulatory requirements, internal policies and Group cybersecurity standards.
- Prepare documentation and evidence for IT audits, regulatory engagements and compliance assessments.
- Support security operations and the management of security technologies such as DLP, Endpoint Protection (EPP) and WAF.
- Conduct security monitoring, controls reviews and operational checks to maintain security readiness.
- Support phishing response activities and cybersecurity simulation exercises.
- Drive cybersecurity awareness and training initiatives across Technology and Business teams.
- Promote secure development practices and strengthen the organisation's overall security culture.
- Interpret cybersecurity and risk information and translate findings into practical recommendations.
- Work closely with Technology, Business and Group stakeholders to deliver security improvements.
Key requirements:
- Bachelor’s degree in Computer Science, Information Systems, Engineering or a related discipline.
- Minimum 4 years of experience in cybersecurity, data protection or technology risk.
- Strong understanding of application security, cybersecurity technologies and cloud security.
- Hands-on or strong working knowledge of DLP governance, data protection, cryptographic controls and regulatory compliance.
- Experience supporting BNM RMiT, regulatory engagements and IT audits.
- Experience within financial services, insurance or other regulated environments is highly preferred.
- Familiarity with secure SDLC and customer data protection.
- Relevant certifications such as CISSP, CISM, CCSP, Security+, CEH or equivalent will be advantageous.
- Strong stakeholder management, communication, analytical and documentation skills.
about the manager/team
You will be part of an established Information & Cybersecurity / Technology Risk environment, working closely with Technology, Business and Group stakeholders to strengthen cybersecurity controls and ensure alignment with regulatory and organisational standards.
The team works across a broad range of cybersecurity and technology risk areas, including data protection, DLP, security architecture, application security, regulatory compliance, security operations and audit readiness.
This role is suited for a cybersecurity professional who is comfortable operating in a regulated environment, can translate technical and risk requirements into practical business recommendations, and is confident engaging stakeholders across different levels of the organisation.