Epicareer Might not Working Properly
Learn More

Technology Risk and Cybersecurity Specialist

  • Full Time, onsite
  • Kingfisher HR Solutions Group
  • Wilayah Persekutuan Kuala Lumpur, Malaysia
Salary undisclosed

Apply on


Original
Simplified

About the company:

My client is an innovative digital asset custodian based in Malaysia, dedicated to offering secure and regulatory-compliant custody solutions for digital assets. Their mission focuses on ensuring the safety and integrity of clients' digital holdings through advanced security measures and cutting-edge technology.

About the role:

The Technology Risk and Cybersecurity Specialist will identify, assess, and mitigate risks related to technology and information systems, including data security.

This role involves developing and implementing controls across technology processes and cybersecurity measures to protect against cyber threats, ensuring compliance with relevant regulations, and managing incident response activities.

The ideal candidate will have a strong understanding of technology-related regulations, risk management, and cybersecurity practices and hands-on experience in implementing industry best practices to safeguard the organization and its assets.

Working arrangement: Hybrid working arrangement.

Responsibilities

Risk Assessment and Management:

  • Conduct IT risk assessments to identify technology-related risks, including cybersecurity-related threats and vulnerabilities.
  • Develop and implement risk mitigation strategies to mitigate the identified IT risks.
  • Perform periodic monitoring of existing technology-related controls (including cybersecurity-related controls) to ensure their operating effectiveness is in alignment with the business objectives.
  • Collaborate with other teams to ensure that technology risk management practices are consistently performed and integrated into all business aspects.

Technology and Cybersecurity Strategy and Implementation:

  • Ownership of Technology and Cybersecurity policies and procedures to oversee its continuous improvement and implementation of technology-related controls (including cybersecurity).
  • Conduct regular Technology and security audits/reviews to ensure compliance with regulations and international best practices, including taking ownership of remediation actions.
  • Oversee vulnerability assessments and penetration testing and follow up on the remediation of identified vulnerabilities.
  • Stay updated on the latest cybersecurity trends and threats, and proactively recommend improvements.

Incident Response and Management:

  • Lead the incident response team in identifying, analyzing, and responding to IT security incidents.
  • Develop and maintain incident response plans and ensure all stakeholders are trained and prepared.
  • Coordinate with external partners and law enforcement in the event of a significant IT security breach.
  • Document and report on IT security incidents, providing detailed analysis and recommendations to mitigate against future occurrences.

Compliance and Regulatory Requirements:

  • Ensure the organization’s technology and cybersecurity practices comply with relevant laws, regulations, and industry standards.
  • Collaborate with legal and compliance teams to manage audits and regulatory inspections.
  • Maintain up-to-date knowledge of relevant regulations such as Securities Commission’s Technology related guidelines and publications, and industry-specific standards (e.g. ISO 27001, ISO 27017, ISO 27018, SoC2, etc.).

Training and Awareness:

  • Develop and deliver training programs to educate employees on IT security best practices.
  • Promote a culture of IT security awareness throughout the organization.
  • Provide guidance and support to staff on IT security-related issues.

Qualifications & Requirements

Education and Experience:

  • Bachelor’s Degree: Degree in Cybersecurity, Information Technology, Risk Management, or a related discipline.
  • Experience: At least 5 years of hands-on experience in cybersecurity, technology risk management, technology auditing, or similar fields.
  • Certifications: Professional certifications such as CISSP, CISA, CISM, CRISC, or equivalent are highly desirable.

Skills and Competencies:

  • Cybersecurity Frameworks: In-depth knowledge of cybersecurity frameworks (exp: NIST and ISO/IEC 27001).
  • Risk Assessment: Proficient in risk assessment methodologies and tools.
  • Security Technologies: Familiarity with security technologies such as firewalls, IDS/IPS, SIEM, and encryption solutions.
  • Problem-Solving: Strong analytical skills with a proven ability to manage complex IT security incidents effectively.
  • Communication: Excellent verbal and written communication skills, with the ability to articulate technical concepts to non-technical audiences.
  • Teamwork and Independence: Capable of working independently as well as collaboratively in a dynamic, fast-paced environment.

Additional Information:

  • Occasional travel may be required.
  • On-call availability for emergency incident response.
  • This role reports to the Head of Risk.

If you're interested and want to know more information, do reach out to Melissa Lai - [email protected]

Have a good day, cheers!