Head of Information Security
On-siteKuala Lumpur, Kuala Lumpur, Malaysia
Job Summary
Lead the company's local information security governance and regulatory compliance initiatives by serving as the primary Information Security representative. Coordinate with the Global Security Center to implement local regulatory requirements and act as the main liaison with Malaysian regulators on cybersecurity and technology risk matters. Ensure compliance with local frameworks, IT security standards, and mandatory breach notification obligations while supporting regulatory inspections, audits, and incident response coordination. Review and localize global security policies to align with Malaysian regulations, deliver adapted security awareness training, and manage stakeholder relationships across Compliance, Legal, Risk, and Technology teams. Monitor regulatory developments to recommend best practices and support local cyber resilience and disaster recovery testing activities.
Required Qualifications
- Bachelor's Degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related field
- 5-8 years of relevant experience in Information Security, Cybersecurity, IT Risk, Technology Risk, or Information Security Governance
- Familiar with Malaysian regulatory requirements relating to cybersecurity and information security, particularly from the Securities Commission Malaysia (SC) or other financial regulators
- Able to work independently with minimal supervision and manage multiple stakeholders across regional and global teams
- Understanding of information security frameworks such as ISO 27001, NIST Cybersecurity Framework, or equivalent
- Experience supporting regulatory audits and examinations
- Comfortable working in a dynamic, fast-paced startup environment
- Strong communication and stakeholder management skills, with the ability to engage regulators, senior management, and regional teams effectively
- Language proficiency in English, Malay is a must; Chinese/Mandarin is highly advantageous given global team collaboration
Desired Qualifications
- Experience within a brokerage firm, investment bank, capital markets, fintech, or financial services environment
- Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.