about the company
Our client is one of Malaysia's leading financial institutions, serving millions of customers across the region. As part of its ongoing digital transformation, the organization continues to strengthen its cybersecurity governance and information security capabilities to protect critical business operations and customer data.
This role offers the opportunity to contribute to enterprise-wide cybersecurity governance initiatives while working alongside experienced information security professionals within a highly regulated environment.
...
about the job
We are looking for a Lead, IT Security Policy & Awareness to drive enterprise information security governance and promote a strong security culture across the organization.
This role is responsible for developing security policies, managing governance initiatives and leading security awareness programmes to ensure employees understand and comply with information security requirements. You will work closely with technology teams, risk functions and business stakeholders to strengthen the organization's overall cybersecurity posture.
This position is ideal for professionals who enjoy influencing stakeholders, driving security governance and building effective cybersecurity awareness programmes
Key Responsibilities
- Develop, review and maintain enterprise IT security policies, standards, guidelines and governance documentation.
- Lead organization-wide security awareness and cybersecurity education initiatives to promote a strong security culture.
- Ensure information security policies comply with regulatory requirements, internal governance standards and industry best practices.
- Collaborate with technology, risk, audit and business teams to implement and improve security governance processes.
- Monitor regulatory updates, cybersecurity trends and emerging threats to recommend policy enhancements.
- Conduct policy reviews, governance assessments and compliance monitoring activities.
- Prepare governance reports, management presentations and executive updates on policy compliance and awareness programme effectiveness.
- Support internal and external audits by providing governance documentation and policy evidence.
- Drive continuous improvement initiatives to strengthen enterprise cybersecurity governance.
Preferred Skills & Experience
- Minimum 8 years of experience in IT Security related working experience in Financial Services Industry (FSI)/ Banking industry or similar environment.
- Knowledge in information security, specifically in compliance assessment, policy development, and industry standard frameworks such as ISO 27001, PCI-DSS, etc. preferably gained in the Financial Services sector; experience in service continuity would also be desirable.
- Knowledge in regional FSI regulator’s requirements and guidelines such as MAS, BI, BSP, BNM, PBOC, HKMA etc.
- Experience developing and maintaining enterprise security policies, standards and governance documentation.
- Proven experience planning and delivering security awareness or cybersecurity training programmes.
- Strong stakeholder management skills with experience working across business, technology and executive teams.
- Excellent communication, presentation and documentation skills.
- Ability to translate complex technical security concepts into practical business guidance.
Nice to Have
- Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor or Security+.
- Experience working in banking, financial services or other highly regulated industries.
- Familiarity with enterprise risk management and technology governance frameworks.
- Experience supporting digital transformation or enterprise cybersecurity programmes.
about the manager/team
You will be joining an experienced Information Security Governance team responsible for shaping the organization's cybersecurity policies, governance framework and security awareness strategy. The team works closely with technology, risk, compliance and business leaders to ensure security is embedded across the organization while supporting ongoing regulatory and digital transformation initiatives.
This role offers strong exposure to executive stakeholders, enterprise governance programmes and large-scale cybersecurity initiatives within a mature and highly regulated environment.