Vice President 2 – Cyber Controls, Compliance & Data Protection
On-siteKuala Lumpur, Kuala Lumpur, Malaysia
Job Summary
Establish and evolve governance frameworks for cybersecurity, technology risk, and data protection. Serve as approving authority for cybersecurity policies and technical standards. Direct bank-wide security awareness, education, and phishing simulation programs. Define risk criteria and assessment methodologies for Outsource Service Providers (OSPs). Set compliance boundaries and data residency mandates for cloud adoption. Act as primary advisor for vendor compliance anomalies and SLA breaches. Liaise with BNM, regulators, and internal audit on compliance matters. Ensure readiness and sign-off for certifications including BNM RMiT, PCI-DSS, and SWIFT CSP. Drive closure of audit findings across GCISM pillars. Endorse compliance dashboards, risk registers, and KRI reports. Present cyber risk postures and compliance gaps to senior committees. Lead remediation when KRIs breach regulatory thresholds. Define boundaries for data classification, ownership, and lifecycle management. Serve as escalation tier for complex DLP exceptions and systemic anomalies. Provide strategic direction, mentorship, and performance management. Manage budgeting, resource allocation, and tool selection for governance initiatives.
Required Qualifications
- Bachelor's/Master's degree in Cybersecurity, Information Security, Law, Risk Management, or related discipline
- 10–12 years of progressive leadership in technology governance, auditing, or risk management within financial services
- 3–5 years in senior management capacity
- Strong communication and presentation skills with proven ability to influence senior stakeholders and regulators
- Ability to translate technical vulnerabilities into business-aligned risk narratives
- Skilled in leading specialized teams, managing audit pressures, and enforcing risk accountability
- Deep expertise in Malaysian banking regulations (BNM RMiT, Outsourcing Policy, PDPA, PCI-DSS, SWIFT CSP)
- Governance & Security: CISA, CRISC, CGEIT, CISSP, CISM, ISO 27001 Lead Auditor/Implementer
- Data & Cloud: CDMP, CIPP/E, CIPM, CCAK/CCSK
Desired Qualifications
- MBA preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.