Head, IT Security & Compliance Management
Head, IT Security & Compliance Management
PERSOL Malaysia- Posted 8 days ago
- Be among the first 10 applicants
Job Description
HEAD, IT SECURITY & COMPLIANCE MANAGEMENT
- Location: Kuching, Sarawak Division: Information Technology Experience: More than 15 years Qualification: Bachelor's or Master's Degree Employment Type: Full Time
ROLE SUMMARY
The Head of IT Security and Compliance will be responsible for developing and maintaining the organization's information security framework, ensuring regulatory compliance and protecting digital assets across systems and platforms.
The role will lead cybersecurity strategy, security governance, risk management, compliance, incident response and security team development.
KEY RESPONSIBILITIES
- Develop and execute the organization's cybersecurity framework in alignment with industry standards Establish IT security policies, procedures and governance models Ensure compliance with ISO 27001, NIST, GDPR, PCI DSS and relevant industry regulations Conduct regular security audits, risk assessments and vulnerability assessments Identify security risks and develop appropriate mitigation strategies Oversee threat monitoring, detection and incident response activities Lead cybersecurity incident response and forensic investigations Implement disaster recovery and business continuity plans Develop penetration testing and vulnerability management programmes Manage regulatory compliance and audit processes Maintain compliance documentation, reports and risk assessment records Implement role-based access controls, multi-factor authentication and encryption protocols Ensure secure employee and third-party vendor onboarding and offboarding Manage cybersecurity vendors and monitor service level agreements Support procurement and contract negotiations for cybersecurity solutions Collaborate with legal, finance, IT and other business functions on security and compliance matters Build, lead and mentor a high-performing cybersecurity team Provide technical leadership on security architecture and compliance Drive continuous training and development for IT security personnel
JOB REQUIREMENTS
- Bachelor's or Master's Degree in Cybersecurity, Information Technology or a related field More than 15 years of experience in IT security and compliance Strong knowledge of enterprise security frameworks and governance Strong knowledge of ISO 27001, NIST, GDPR, PCI DSS and IAM solutions Proven experience managing large-scale IT security operations Experience in risk management, incident response and security assessments Experience with regulatory compliance, audits and documentation Experience in vendor management, contract negotiation and SLA management Strong understanding of cloud security across AWS, Azure or Google Cloud Knowledge of penetration testing, vulnerability management and threat modelling Strong leadership, strategic thinking and stakeholder management skills Excellent communication, analytical and problem-solving abilities Strong attention to detail and ability to manage critical security matters under tight deadlines
PREFERRED CERTIFICATIONS
- CISSP CISM ISO 27001 Lead Auditor Certified Ethical Hacker PMP
TECHNICAL EXPERTISE
- ISO 27001 Information Security Management Systems NIST Cybersecurity Framework GDPR and data protection requirements PCI DSS Identity and Access Management RBAC and MFA Encryption and authentication Cloud security Penetration testing and vulnerability management Security risk management and incident response Compliance and audit management
LEADERSHIP SKILLS
- Cybersecurity strategy and governance Vendor and stakeholder management Cross-functional collaboration Team leadership and development Security risk communication and executive reporting
More Info
Job Type:
Industry:
Function:
Employment Type:
Key Skills
security risk management
threat modelling
compliance and audit management
IAM solutions
