About the Role
The Head of Cybersecurity Services is responsible for establishing and managing the bank's IT security operations to ensure the confidentiality, integrity, and availability of digital assets. This role will lead a team to monitor, detect, and respond to security threats, implement robust security protocols, and ensure compliance with regulatory requirements. The ideal candidate will possess deep expertise in cybersecurity, especially within the banking industry, and have a track record of safeguarding critical information assets in a dynamic digital environment.
What will you do:
- Oversee the daily operations of the Security Operations Center (SOC), including threat monitoring, incident response, and vulnerability management.
- Implement and maintain advanced threat detection, analysis, and mitigation tools and technologies to ensure proactive defense against cyber threats.
- Collaborate with IT and application teams to embed security best practices in core banking systems, digital platforms, and mobile applications.
- Develop and lead the incident response program, coordinating rapid response to security incidents and minimizing impact on business operations.
- Conduct root cause analysis for incidents, driving continuous improvements in detection and response strategies.
- Oversee red team exercises and penetration testing to identify and remediate vulnerabilities.
- Establish and enforce IT security policies, procedures, and standards in alignment with regulatory requirements (e.g., BNM guidelines in Malaysia) and best practices.
- Ensure compliance with relevant banking regulations, including data privacy, cybersecurity frameworks, and financial standards.
- Conduct regular security assessments and audits to measure the effectiveness of security controls and ensure regulatory alignment.
- Lead the risk assessment process to identify potential vulnerabilities in infrastructure, applications, and data environments.
- Oversee the execution of vulnerability scanning, penetration testing, and risk assessment reports, ensuring remediation plans are actioned and tracked.
- Evaluate third-party vendors for security risks and ensure appropriate controls are in place for vendor access to sensitive data.
- Manage, mentor, and develop a team of security professionals, fostering a culture of vigilance, accountability, and continuous improvement.
- Coordinate with HR for ongoing training and skill development programs to keep the security team up-to-date on the latest threats and technologies.
- Build strong relationships with other departments, including IT, risk, and compliance, to create a cohesive approach to security.
- Stay updated on cybersecurity trends, threats, and regulatory changes to recommend strategic investments in security tools and capabilities.
- Work closely with technology and product teams to ensure secure development practices and embed security in new initiatives.
- Regularly report on the status of the bank's security posture to senior leadership, the board, and relevant committees.
- Communicate security risks, trends, and incidents effectively to non-technical stakeholders to ensure informed decision-making.
- Develop metrics and KPIs to measure the success of the security program and drive continuous improvement.
Skills, certifications and experience you possess:
- Bachelor's Degree in Computer Science, Information Technology, or any related field.
- At least 10+ years experience in a leadership role within application development or related IT services.
- Demonstrated strong understanding of application security, data leak prevention, penetration testing, current technologies, and industry trends.
- Knowledge of security protocols, compliance, and risk management in cybersecurity services.
- Excellent communication and interpersonal skills to manage and collaborate with cross-functional teams and stakeholders.
- Strong problem-solving skills and the ability to make strategic decisions that positively impact the organization.
- Familiar with the local regulations (e.g. BNM) and able to manage regulatory requirements from a technology solution/decision perspective.