759 Security Governance jobs in Malaysia
Information Security Governance
Posted today
Job Viewed
Job Description
1. Certification & Compliance Governance
• Oversee Pacific Internet's ISO27001:2022 certification program and surveillance audits.
• Govern Acclivis' transition from ISO27001:2015 to ISO27001:2022.
• Act as liaison with certification bodies and external auditors.
2. ISMS Governance & Documentation
• Establish, review, and maintain ISMS documentation (policies, procedures, SOPs, SoA).
• Ensure alignment of ISMS with ISO27001:2022 requirements across both entities.
• Monitor and enforce compliance with customer, contractual, and regulatory requirements.
3. Risk & Assurance Management
• Govern the enterprise risk assessment and treatment plan process.
• Track remediation and closure of audit findings, vulnerabilities, and compliance gaps.
• Provide assurance to customer security due-diligence requests
4. ITIL Service Management Governance
• Oversee integration of ISO27001 requirements into ITIL processes:
• Change Management – security risk evaluation in change approvals.
• Incident Management – incident classification and escalation under ISMS.
• Problem Management – root cause governance to prevent recurring failures.
• Service Request Management – secure onboarding, offboarding, and access governance.
5. Governance Committees & Structures
• Establish and chair the Information Security Steering Committee (ISSC) to oversee ISMS performance, risks, and improvements.
• Facilitate a Risk & Compliance Committee for risk treatment and audit follow-up.
• Ensure security participation in the Change Advisory Board (CAB) to align ITIL changes with ISO27001 governance.
• Document all committee activities (agenda, minutes, actions, follow-up).
6.Awareness, Reporting & Culture
• Govern delivery of ISO27001/security awareness training.
• Report ISMS performance, compliance status, and risks to senior leadership.
• Foster a culture of governance, accountability, and continuous improvement.
Information Security Governance & Compliance Lead
Posted today
Job Viewed
Job Description
Certification & Compliance Governance
Oversee Pacific Internet’s ISO27001:2022 certification program and surveillance audits. Govern Acclivis’ transition from ISO27001:2015 to ISO27001:2022. Act as liaison with certification bodies and external auditors. ISMS Governance & Documentation
Establish, review, and maintain ISMS documentation (policies, procedures, SOPs, SoA). Ensure alignment of ISMS with ISO27001:2022 requirements across both entities. Monitor and enforce compliance with customer, contractual, and regulatory requirements. Risk & Assurance Management
Govern the enterprise risk assessment and treatment plan process. Track remediation and closure of audit findings, vulnerabilities, and compliance gaps. Provide assurance to customer security due-diligence requests. ITIL Service Management Governance
Oversee integration of ISO27001 requirements into ITIL processes: Change Management – security risk evaluation in change approvals. Incident Management – incident classification and escalation under ISMS. Problem Management – root cause governance to prevent recurring failures. Service Request Management – secure onboarding, offboarding, and access governance. Governance Committees & Structures
Establish and chair the Information Security Steering Committee (ISSC) to oversee ISMS performance, risks, and improvements. Facilitate a Risk & Compliance Committee for risk treatment and audit follow-up. Ensure security participation in the Change Advisory Board (CAB) to align ITIL changes with ISO27001 governance. Document all committee activities (agenda, minutes, actions, follow-up). Govern delivery of ISO27001/security awareness training. Report ISMS performance, compliance status, and risks to senior leadership. Foster a culture of governance, accountability, and continuous improvement. Application & Additional Information
Application questions: Which of the following statements best describes your right to work in Malaysia? What's your expected monthly basic salary? Which of the following types of qualifications do you have? How many years' experience do you have as a Compliance Lead? To help fast track investigation, please include here any other relevant details that prompted you to report this job ad as fraudulent / misleading / discriminatory / salary below minimum wage. Researching careers? Find all the information and tips you need on career advice.
#J-18808-Ljbffr
Cloud Technical Security Governance
Posted 2 days ago
Job Viewed
Job Description
- Create, review, and update the Group IT Security Policies, Standards, Procedures, Guidelines, checklists, and assessment requirements related to Cloud Security.
- Will be used by Regional & Overseas Units.
- Ensure compliance with all local regulators’ requirements and industry best practices.
- Align cloud security policies and assessment questions with industry standards (e.g., ISO 27001, NIST, CSA STAR, SOC 2) and regulatory requirements (e.g., BNM RMiT, MAS, OJK, HKMA).
- Regularly review and update cloud security policies to address emerging threats and regulatory changes.
- Perform comprehensive cloud security assessments for new and existing cloud projects, including private and public cloud solutions.
- Review evidence from solution providers and third parties such as SOC 2 reports, CSA STAR certifications, attestation reports, and penetration testing results.
- Validate cloud architecture and configurations to ensure compliance with security policies and standards.
- Develop Regional IT Security Governance processes aligned with the Bank’s strategy.
- Liaise with and manage business projects, infrastructure upgrades, penetration testing, and code reviews.
- Provide proactive IT security consultancy and advisory services on policies, standards, and best practices across the Group.
- Education and Experience:
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- At least 2 years of experience in cloud security, governance, or a similar role; total of at least 3 years in IT security or infrastructure.
- Proven experience in conducting cloud security assessments and technical validations.
- Technical Skills:
- Strong understanding of cloud platforms (AWS, Azure, Google Cloud) and their security features.
- Knowledge of cloud security frameworks and standards (ISO 27001, NIST, CSA STAR, SOC 2).
- Experience with security tools and technologies used in cloud environments (e.g., SIEM, IAM, encryption).
Cloud Technical Security Governance
Posted 2 days ago
Job Viewed
Job Description
Job Description - Cloud Technical Security Governance
- Create, review and update the Group IT Security Policies, Standards, Procedures, Guidelines, checklist and assessment requirements related to Cloud Security
- Will be used by Regional & Overseas Units
- Comply to all local regulators’ requirements and industry best practise are captured and adhere to.
- Ensure that cloud security policies and assessment questions are aligned with industry best practices (e.g. ISO 27001, NIST, CSA STAR, SOC 2) and regulatory requirements (e.g.BNM RMiT, MAS, OJK, HKMA)
- Regularly review and update cloud security policies to address emerging threats and changes in the regulatory landscape.
- Perform comprehensive cloud security assessments for new and existing cloud projects, encompassing both private and public cloud solutions.
- Review evidence provided by solution provider and third parties such as SOC 2 reports, CSA STAR certifications, attestation reports, and penetration testing results.
- Conduct technical validation of cloud architecture and configurations to ensure compliance with security policies and standards.
- Develop Regional IT Security Governance processes to align with the Bank’s strategy and aspirations
- Liaise and manage business projects and infrastructure upgrades penetration testing and code reviews
- Enforcement and proactively provides IT security consultancy/ advisory services on policies, standards and best practices across the Group
Qualifications
- Education and Experience :
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- Minimum of 2 years of experience in cloud security, cloud governance, or a similar role. A total of at least 3 years of experience in IT security, or infrastructure is required.
- Proven experience in conducting cloud security assessments and technical validations.
- Technical Skills :
- Strong understanding of cloud platforms (AWS, Azure, Google Cloud) and their security features.
- Knowledge of cloud security frameworks and standards (ISO 27001, NIST, CSA STAR, SOC 2).
- Experience with security tools and technologies used in cloud environments (e.g., SIEM, IAM, encryption).
Executive, ICT Security Governance
Posted today
Job Viewed
Job Description
About the role
Join our dynamic team at the Companies Commission of Malaysia/Suruhanjaya Syraikat Malaysia (SSM) as an Executive in ICT Security Governance In this contract role, you will be instrumental in advancing our ICT security framework. This exciting opportunity is based at our state-of-the-art headquarters, Menara SSM @ Sentral, in the heart of Kuala Lumpur Sentral.
What you'll be doing
- Assist in reviewing IT Security Policy to ensure documentation is up-to-date according to the latest changes in the environment and government direction.
- Assist in handling, monitoring, and upholding ISMS certification standards.
- Provide advisory on IT security needs to meet user requirements and maintain security standards.
- Draft security awareness materials with up-to-date information to raise user acknowledgment and maintain a secure environment.
- Prepare materials for SSM IT Security Policy trainings to increase compliance in ICT security governance.
- Draft or review business continuity policy to enable business continuity during an unplanned disruption in service.
- Comply with all SSM policies and SOPs.
What we're looking for
- Educational Background: A Bachelor Degree in Computer Science / Information Technology or equivalent recognised certification.
- Experience: Preferably relevant working experience in IT Security Governance.
Knowledge/Skills/Abilities:
- Expertise in network troubleshooting, server environments, application, and system security.
- Proficient in security management and standards.
- Skilled in data security, including logical and physical access controls.
What we offer
At Suruhanjaya Syarikat Malaysia/Companies Commission of Malaysia, we are committed to providing a rewarding and supportive work environment. You will have the opportunity to work on cutting-edge technologies, contribute to impactful projects, and grow your career. We offer competitive remuneration, flexible work arrangements, and a range of benefits to support your well-being.
If you're ready to elevate your career in ICT security governance, apply now and become a part of our dynamic team
Cloud Technical Security Governance
Posted 11 days ago
Job Viewed
Job Description
Will be used by Regional & Overseas Units Comply to all local regulators’ requirements and industry best practise are captured and adhere to. Ensure that cloud security policies and assessment questions are aligned with industry best practices (e.g. ISO 27001, NIST, CSA STAR, SOC 2) and regulatory requirements (e.g.BNM RMiT, MAS, OJK, HKMA) Regularly review and update cloud security policies to address emerging threats and changes in the regulatory landscape.
Perform comprehensive cloud security assessments for new and existing cloud projects, encompassing both private and public cloud solutions.
Review evidence provided by solution provider and third parties such as SOC 2 reports, CSA STAR certifications, attestation reports, and penetration testing results. Conduct technical validation of cloud architecture and configurations to ensure compliance with security policies and standards.
Develop Regional IT Security Governance processes to align with the Bank’s strategy and aspirations Liaise and manage business projects and infrastructure upgrades penetration testing and code reviews Enforcement and proactively provides IT security consultancy/ advisory services on policies, standards and best practices across the Group Qualifications Education and Experience : Bachelor’s degree in Computer Science, Information Technology, or a related field. Minimum of 2 years of experience in cloud security, cloud governance, or a similar role. A total of at least 3 years of experience in IT security, or infrastructure is required. Proven experience in conducting cloud security assessments and technical validations. Technical Skills : Strong understanding of cloud platforms (AWS, Azure, Google Cloud) and their security features. Knowledge of cloud security frameworks and standards (ISO 27001, NIST, CSA STAR, SOC 2). Experience with security tools and technologies used in cloud environments (e.g., SIEM, IAM, encryption).
#J-18808-Ljbffr
Cloud Technical Security Governance
Posted 11 days ago
Job Viewed
Job Description
Create, review, and update the Group IT Security Policies, Standards, Procedures, Guidelines, checklists, and assessment requirements related to Cloud Security.
Will be used by Regional & Overseas Units. Ensure compliance with all local regulators’ requirements and industry best practices. Align cloud security policies and assessment questions with industry standards (e.g., ISO 27001, NIST, CSA STAR, SOC 2) and regulatory requirements (e.g., BNM RMiT, MAS, OJK, HKMA). Regularly review and update cloud security policies to address emerging threats and regulatory changes.
Perform comprehensive cloud security assessments for new and existing cloud projects, including private and public cloud solutions.
Review evidence from solution providers and third parties such as SOC 2 reports, CSA STAR certifications, attestation reports, and penetration testing results. Validate cloud architecture and configurations to ensure compliance with security policies and standards.
Develop Regional IT Security Governance processes aligned with the Bank’s strategy. Liaise with and manage business projects, infrastructure upgrades, penetration testing, and code reviews. Provide proactive IT security consultancy and advisory services on policies, standards, and best practices across the Group. Qualifications
Education and Experience: Bachelor’s degree in Computer Science, Information Technology, or a related field. At least 2 years of experience in cloud security, governance, or a similar role; total of at least 3 years in IT security or infrastructure. Proven experience in conducting cloud security assessments and technical validations. Technical Skills: Strong understanding of cloud platforms (AWS, Azure, Google Cloud) and their security features. Knowledge of cloud security frameworks and standards (ISO 27001, NIST, CSA STAR, SOC 2). Experience with security tools and technologies used in cloud environments (e.g., SIEM, IAM, encryption).
#J-18808-Ljbffr
Be The First To Know
About the latest Security governance Jobs in Malaysia !
IT Security Governance and Risk Management Analyst
Posted 1 day ago
Job Viewed
Job Description
JOB SUMMARY
- This position will be reporting to the Head of Security Governance & Risk Management Section and will function under the Advisory & Governance Unit.
- Support and strengthen cybersecurity governance through comprehensive risk assessments, in-depth advisory services, and proactive engagement with key stakeholders to ensure compliance with internal policies and regulatory standards.
- Provide IT security advisory for business initiatives, systems implementations, and operational processes to ensure alignment with security policies and risk appetite.
- Review and assess IT change requests, vendor solutions, technology initiatives and third-party controls for security risks and recommend mitigation strategies.
- Support the execution, and analyse cybersecurity simulation exercises (e.g., phishing, smishing) to test and enhance organizational readiness.
- Monitor the implementation of risk mitigation plans and follow up with relevant departments to ensure timely closure of issues.
- Participate in governance forums on matters relating to IT risk and security governance.
- Prepare reports, presentations, and dashboards on cybersecurity risk posture, incidents, and remediation progress for internal stakeholders and management.
- Contribute to the development and refinement of IT security governance frameworks, policies, and procedures.
- Ensure security assessment exercise is conducted and remediated in a timely manner.
- Malaysian citizen.
- Pass Malay Language including oral test at Sijil Pelajaran Malaysia (SPM) level.
- Possess a Bachelor's Degree in Computer Science/ Information Technology, Cybersecurity or equivalent qualification from accredited higher learning institutions.
- Minimum 4 – 7 years of experience in IT security, risk management, or cybersecurity advisory roles.
- Strong understanding of information security principles, risk assessment methodologies, and regulatory frameworks (e.g., ISO 27001, NIST, CIS).
- Excellent analytical thinking, communication, and stakeholder engagement skills.
- Experience coordinating with cross-functional teams on security governance and compliance efforts.
- Professional certifications such as CISM, CISSP, CRISC, or equivalent are highly desirable.
Permanent
All applications are strictly CONFIDENTIAL and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.
#J-18808-LjbffrIT Security Governance and Risk Management Analyst
Posted today
Job Viewed
Job Description
JOB SUMMARY
- This position will be reporting to the Head of Security Governance & Risk Management Section and will function under the Advisory & Governance Unit.
- Support and strengthen cybersecurity governance through comprehensive risk assessments, in-depth advisory services, and proactive engagement with key stakeholders to ensure compliance with internal policies and regulatory standards.
JOB RESPONSIBILITIES
- Provide IT security advisory for business initiatives, systems implementations, and operational processes to ensure alignment with security policies and risk appetite.
- Review and assess IT change requests, vendor solutions, technology initiatives and third-party controls for security risks and recommend mitigation strategies.
- Support the execution, and analyse cybersecurity simulation exercises (e.g., phishing, smishing) to test and enhance organizational readiness.
- Monitor the implementation of risk mitigation plans and follow up with relevant departments to ensure timely closure of issues.
- Participate in governance forums on matters relating to IT risk and security governance.
- Prepare reports, presentations, and dashboards on cybersecurity risk posture, incidents, and remediation progress for internal stakeholders and management.
- Contribute to the development and refinement of IT security governance frameworks, policies, and procedures.
- Ensure security assessment exercise is conducted and remediated in a timely manner.
JOB REQUIREMENTS
- Malaysian citizen.
- Pass Malay Language including oral test at Sijil Pelajaran Malaysia (SPM) level.
- Possess a Bachelor's Degree in Computer Science/ Information Technology, Cybersecurity or equivalent qualification from accredited higher learning institutions.
- Minimum 4 – 7 years of experience in IT security, risk management, or cybersecurity advisory roles.
- Strong understanding of information security principles, risk assessment methodologies, and regulatory frameworks (e.g., ISO 27001, NIST, CIS).
- Excellent analytical thinking, communication, and stakeholder engagement skills.
- Experience coordinating with cross-functional teams on security governance and compliance efforts.
- Professional certifications such as CISM, CISSP, CRISC, or equivalent are highly desirable.
JOB STATUS
Permanent
All applications are strictly
CONFIDENTIAL
and only shortlisted candidates will be called in for interview. Applications are deemed
UNSUCCESSFUL
if there is no feedback from the EPF
2 MONTHS
after the closing date of advertisement.
IT Security Governance and Risk Management Analyst
Posted today
Job Viewed
Job Description
Job Summary This position will be reporting to the Head of Security Governance & Risk Management Section and will function under the Advisory & Governance Unit. Support and strengthen cybersecurity governance through comprehensive risk assessments, in-depth advisory services, and proactive engagement with key stakeholders to ensure compliance with internal policies and regulatory standards. Job Responsibilities Provide IT security advisory for business initiatives, systems implementations, and operational processes to ensure alignment with security policies and risk appetite. Review and assess IT change requests, vendor solutions, technology initiatives and third-party controls for security risks and recommend mitigation strategies. Support the execution, and analyse cybersecurity simulation exercises (e.g., phishing, smishing) to test and enhance organizational readiness. Monitor the implementation of risk mitigation plans and follow up with relevant departments to ensure timely closure of issues. Participate in governance forums on matters relating to IT risk and security governance. Prepare reports, presentations, and dashboards on cybersecurity risk posture, incidents, and remediation progress for internal stakeholders and management. Contribute to the development and refinement of IT security governance frameworks, policies, and procedures. Ensure security assessment exercise is conducted and remediated in a timely manner. Job Requirements Possess a Bachelor's Degree in Computer Science/ Information Technology, Cybersecurity or equivalent qualification from accredited higher learning institutions. Minimum 4 – 7 years of experience in IT security, risk management, or cybersecurity advisory roles. Strong understanding of information security principles, risk assessment methodologies, and regulatory frameworks (e.g., ISO 27001, NIST, CIS). Excellent analytical thinking, communication, and stakeholder engagement skills. Experience coordinating with cross-functional teams on security governance and compliance efforts. Professional certifications such as CISM, CISSP, CRISC, or equivalent are highly desirable.
#J-18808-Ljbffr