about the company
A leading digital investment platform built on next-generation global infrastructure, providing investors and traders with advanced tools, curated learning and next-level data. Our client is regulated by the Securities Commission Malaysia and holds a Capital Markets Services Licence.
...
about the job
We are looking for a Senior IT Manager – Information Security, Risk & Governance to lead IT security, technology risk, regulatory compliance and infrastructure governance for Webull Malaysia.
This is a key role with strong exposure to Securities Commission Malaysia (SC) regulatory requirements and Bursa Malaysia ITSS, including ownership of SC Guidelines on Technology Risk Management (GTRM) and Bursa IT recommendations. The role will also oversee key cybersecurity controls including Privileged Access Management (PAM), Multi-Factor Authentication (MFA) and Endpoint Detection & Response (EDR), as well as cloud and third-party governance, incident response and IT infrastructure.
We are particularly interested in candidates with hands-on PAM experience combined with strong Securities Commission Malaysia / SC GTRM exposure. Experience with Bursa Malaysia ITSS, financial services regulatory frameworks, AI/data initiatives, cloud governance and enterprise infrastructure will be highly advantageous.
The ideal candidate will bring 5–8+ years of experience across IT Risk, IT Compliance, Information Security, IT Infrastructure or IT Operations within Financial Services, with strong stakeholder management and regulatory knowledge. CISA or CRISC certification would be an added advantage.
Ability to communicate in Chinese would be essential as this role requires interaction with colleagues based in China.
about the manager/team
You will work closely with the Head of IT and play a strategic role within the Malaysia IT function, acting as a key advisor on information security, technology risk, regulatory compliance and IT operations.
The position will provide exposure to senior stakeholders and regional teams, including colleagues based in China. Strong communication, stakeholder management and the ability to translate regulatory and security requirements into practical IT controls will be important.
This is an opportunity for an experienced IT security/risk professional to take on a broad leadership role covering regulatory governance, PAM, cybersecurity controls, cloud governance, infrastructure and IT resilience within a rapidly growing digital investment platform.