Search by job, company or skills

Head, IT Security & Compliance Management

Head, IT Security & Compliance Management

PERSOL Malaysia
15-18 Years
MYR 15,000 - 20,000 per month
  • Posted 8 days ago
  • Be among the first 10 applicants

Job Description

HEAD, IT SECURITY & COMPLIANCE MANAGEMENT

  • Location: Kuching, Sarawak Division: Information Technology Experience: More than 15 years Qualification: Bachelor's or Master's Degree Employment Type: Full Time

ROLE SUMMARY

The Head of IT Security and Compliance will be responsible for developing and maintaining the organization's information security framework, ensuring regulatory compliance and protecting digital assets across systems and platforms.

The role will lead cybersecurity strategy, security governance, risk management, compliance, incident response and security team development.

KEY RESPONSIBILITIES

  • Develop and execute the organization's cybersecurity framework in alignment with industry standards Establish IT security policies, procedures and governance models Ensure compliance with ISO 27001, NIST, GDPR, PCI DSS and relevant industry regulations Conduct regular security audits, risk assessments and vulnerability assessments Identify security risks and develop appropriate mitigation strategies Oversee threat monitoring, detection and incident response activities Lead cybersecurity incident response and forensic investigations Implement disaster recovery and business continuity plans Develop penetration testing and vulnerability management programmes Manage regulatory compliance and audit processes Maintain compliance documentation, reports and risk assessment records Implement role-based access controls, multi-factor authentication and encryption protocols Ensure secure employee and third-party vendor onboarding and offboarding Manage cybersecurity vendors and monitor service level agreements Support procurement and contract negotiations for cybersecurity solutions Collaborate with legal, finance, IT and other business functions on security and compliance matters Build, lead and mentor a high-performing cybersecurity team Provide technical leadership on security architecture and compliance Drive continuous training and development for IT security personnel

JOB REQUIREMENTS

  • Bachelor's or Master's Degree in Cybersecurity, Information Technology or a related field More than 15 years of experience in IT security and compliance Strong knowledge of enterprise security frameworks and governance Strong knowledge of ISO 27001, NIST, GDPR, PCI DSS and IAM solutions Proven experience managing large-scale IT security operations Experience in risk management, incident response and security assessments Experience with regulatory compliance, audits and documentation Experience in vendor management, contract negotiation and SLA management Strong understanding of cloud security across AWS, Azure or Google Cloud Knowledge of penetration testing, vulnerability management and threat modelling Strong leadership, strategic thinking and stakeholder management skills Excellent communication, analytical and problem-solving abilities Strong attention to detail and ability to manage critical security matters under tight deadlines

PREFERRED CERTIFICATIONS

  • CISSP CISM ISO 27001 Lead Auditor Certified Ethical Hacker PMP

TECHNICAL EXPERTISE

  • ISO 27001 Information Security Management Systems NIST Cybersecurity Framework GDPR and data protection requirements PCI DSS Identity and Access Management RBAC and MFA Encryption and authentication Cloud security Penetration testing and vulnerability management Security risk management and incident response Compliance and audit management

LEADERSHIP SKILLS

  • Cybersecurity strategy and governance Vendor and stakeholder management Cross-functional collaboration Team leadership and development Security risk communication and executive reporting

More Info

Key Skills

security risk management

threat modelling

compliance and audit management

IAM solutions

About Company