Business Information Security Officer
RM 15,000 - RM 18,000 / month
Checking job availability...
Original
Simplified
We are hiring for Business Information Security Officer who will be responsible for driving information security efforts within the business unit or functional area.
Mandatory Skill-set
- At least 5 years of experience working in information security, risk management, governance, and meeting regulatory requirements related to security with a specific focus on business outcomes and service delivery;
- Experience in working with and preferably leading a global, cross functional team;
- Familiarity with cybersecurity frameworks like NIST, ISO 27001, COBIT, or GDPR;
- Proven experience in incident response, risk assessment, and vulnerability management;
- Aptitude for understanding internal organizational environments and their relationship to the external business environment;
- Ability to effectively analyze risk within the context of business problems.
Desired Skill-set
- Possess at least one of the following certification CISSP. CCSP. CRISC. or CISM;
- Understand Cloud Infrastructure.
Responsibilities
- Support the overall governance of the security Key Risk Indicators (KRIS) for the designated and manage the risks to ensure alignment with the BUs' risk tolerance levels;
- Facilitate the investigation and management of security incidents for designated BUs and communicate to relevant stakeholders;
- Ensure clear documentation of the business justifications, risks, the existing mitigation controls (if any) and relevant approvals are in place;
- Support security assessment for technology solutions for designated BUs;
- Offer expertise to BUs with the help of Group Information Security (GIS) Subject Matter Expert (SME);
- Collaborate with enterprise risk management to conduct risk assessments and support the development of risk treatment plans for the BUs;
- Facilitate the local implementation of group information security initiative for the designated BUs;
- Assist with the security awareness programs for designated BUs to enforce security culture and understand the information security solutions in BUs;
- Help to develop the Business Information Security Officer (BISO) framework / handbook outlining BISOs roles and responsibilities. This standardizes practice across the organization;
- Establish and maintain BISO community to share insights or discussion of findings from audits, incidents, or latest security trend with each BUs to facilitate cross-learning and capture lessons teamed;
- Gather input or recommendations with regards to Group Information Security (GIS) functions and programs from BISOs across various countries/markets. Compile the feedback and contribute to GIS for continuous improvement of the Security Operation Model;
- Collaborate with security teams to develop and implement tailored security awareness programs for business units and devise a structured professional development pathway for BISOs.
- Should you be interested in this career opportunity, please send your updated resume to [email protected] at your earliest convenience.
- By applying, you voluntarily consent to the disclosure, collection, and use of your personal data for employment/recruitment and related purposes, in accordance with the SCIENTE Group Privacy Policy. A copy of the policy is available on the SCIENTE website ().
- Confidentiality is assured, and only shortlisted candidates will be contacted for interviews.
Job Type: Contract
Contract length: 12 months
Pay: RM15,000.00 - RM18,000.00 per month
Work Location: In person
Application Deadline: 03/03/2025
Expected Start Date: 03/17/2025