About the RoleMoomoo Malaysia is looking for an independent and proactive Head of Information Security to lead the company's local information security governance and regulatory compliance initiatives.
This is a hands-on individual contributor, the ideal candidate should be familiar with Malaysia's regulatory landscape, particularly within the capital markets and financial services industry, and be comfortable working in a fast-paced startup environment.
Responsibilites - Act as the primary Information Security representative for Moomoo Malaysia
- Coordinate and collaborate closely with the Global Security Center to ensure local regulatory requirements are implemented effectively
- Serve as the main liaison with Malaysian regulators (e.g. Securities Commission Malaysia, Bursa Malaysia and other relevant authorities) on information security, cybersecurity, technology risk and other related matters
- Ensure compliance with local regulatory requirements on Cybersecurity Frameworks, IT Security Standards, Regulatory Outsourcing Guidelines etc and internal global security policies and etc, including mandatory breach notification obligations
- Support regulatory inspections, audits, thematic reviews, information security assessments and etc
- Review, localize and implement information security policies, standards, and procedures in alignment with both global security requirements and Malaysian regulations
- Coordinate internal stakeholders across Compliance, Legal, Risk, Technology, and Business teams on security-related matters
- Monitor regulatory developments and provide recommendations on cybersecurity and information security best practices
- Support incident response coordination and regulatory reporting for security incidents within prescribed timelines.
- Support local cyber resilience, DR/BCP testing activities
- Deliver local security awareness training and programs required adapted from global materials etc
Requirements
- Bachelor's Degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related field
- 5-8 years of relevant experience in Information Security, Cybersecurity, IT Risk, Technology Risk, or Information Security Governance
- Familiar with Malaysian regulatory requirements relating to cybersecurity and information security, particularly from the Securities Commission Malaysia (SC) or other financial regulators
- Experience within a brokerage firm, investment bank, capital markets, fintech, or financial services environment will be a strong advantage
- Able to work independently with minimal supervision and manage multiple stakeholders across regional and global teams
- Understanding of information security frameworks such as ISO 27001, NIST Cybersecurity Framework, or equivalent
- Experience supporting regulatory audits and examinations
- Comfortable working in a dynamic, fast-paced startup environment
- Strong communication and stakeholder management skills, with the ability to engage regulators, senior management, and regional teams effectively
- Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent will be an added advantage
- Language proficiency in English, Malay is a must; Chinese/Mandarin is highly advantageous given global team collaboration
- Bumiputera candidates are encouraged to apply.
Benefits
We offer a comprehensive and holistic work experience and package as follows:
- 13 months contractual bonus
- Competitive compensation & benefits.
- Performance bonus
- Convenient Access to Public Transport
- Exam/Certification Sponsorship
- Career Development Opportunities in the Financial Services Industry
- Company Team Building & Bonding Activities
- Free-Flow Pantry Snacks & Drinks
- Dynamic, Multinational Working Environment
Please note that only short-listed candidates will be contacted. Thank you.