Epicareer Might not Working Properly
Learn More

Information Security Lead

Salary undisclosed

Apply on


Original
Simplified

Boost Bank, is first primarily Malaysian owned digital bank, we are anchored in the mission to pave the way for a banking revolution that serves all Malaysians and make financial wellbeing a seamless part of life. We are adopting and working on leading- and cutting-edge technology solutions to service the dynamic needs of the Malaysian market.

Information Security Lead is responsible to establish, manage and review the technology compliance and its control mechanisms. Contribute to regulatory compliance, technology compliance implementation and technology compliance advisory as part of product or business growth.

Key Responsibilities:

  • Enhance and implement the approved cyber security strategy aligned with the bank's overall business objectives and regulatory requirements.
  • Develop and implement an effective incident response plan to manage and mitigate security breaches.
  • Manage, Review and enhancement of SOC services.
  • Evaluate and recommend security technologies and solutions
  • Act as the primary liaison between the security function and other teams within the organization, including the IT leadership team, risk management and compliance teams, and external partners
  • Drive Technology and Cloud risk assessments, control identification and facilitate risk remediation.
  • Actively participate and support all phases of the audit lifecycle if required.
  • Lead Security testing planning and execution
  • Track and manage information security compliance and technology risk related gaps and integrate into enterprise risk management reporting.
  • Manage relationships with third-party vendors and ensure they adhere to the bank's security standards
  • Management reporting on information security initiatives and risk management activities

Soft Competencies

  • To establish good and effective cross-department working relationships with key reporting areas and build strong working relationships with subsidiaries, external consultants, vendors and regulators.
  • Work as a collaborative partner by seeking & considering other opinions and by contributing to an atmosphere where ideas can be openly exchanged.

Job Requirements

  • A bachelor’s degree in information systems or other related disciplines from an accredited institution is required.
  • Certifications in security, risk management or relevant fields is a plus
  • At least 5+ years of relevant experience in financial services technology compliance
  • Proven track record in managing compliance and risk in a technology-driven environment, preferably within the banking or financial industry.
  • Possess good background in financial services sector, financial transactional processes, technology systems, its regulatory requirements and internal controls (e.g. RMiT, e-money guidelines, outsourcing guidelines, FSA 2013, PDPA)
  • Proficiency in risk assessment methodologies, compliance frameworks, and control implementation.
  • Experience in working with a consulting firm is an added advantage
  • Able to utilize both vertical and lateral thinking in providing perspectives on compliance matters to support risk management and company growth.
  • Results-driven person who is highly committed and independent with minimum supervision required.
  • Excellent verbal and written communication skills with the ability to address cybersecurity issues in both technical and non-technical terms.
  • Good knowledge of technology compliance and technology risk management