Information Security C Governance Manager
senheng electric (kl) sdn bhd- Posted 15 hours ago
- Be among the first 10 applicants
Job Description
Role Summary
Reporting to the Chief Technology Officer (CTO), lead the Information Security C Governance (ISG) division, responsible for strengthening the organization's cybersecurity posture, technology governance, risk and compliance, and Digital Workplaceservices.
The role provides leadership and oversight across cybersecurity operations and governance, IT and cybersecurity risk and compliance, third-party technology risk, and end-user technology services. It ensures technology risks are appropriately managed, security controls remain effective, regulatory and audit obligations are addressed,
and employees receive secure and reliable workplace technology support.
The Division Head works closely with other technology divisions, business stakeholders and external service providersto establish clear accountability, effective controls and sustainable organizational capability.
Key Responsibilities
1.Cybersecurity Management
- Lead the organization's cybersecurity function covering security governance, security operations oversight, vulnerability management and incident response coordination.
- Oversee security monitoring and threat detection activities delivered through internal capabilities and external SOC/security partners.
- Ensure cybersecurity incidents are appropriately assessed, escalated, contained and followed through to remediation.
- Establish and maintain cybersecurity policies, standards, controls and operating procedures.
- Drive vulnerability identification, prioritization and remediation with the respective technology owners.
- Oversee endpoint security controls and security compliance across corporate devices.
- Coordinate cybersecurity assessments, reviews and improvement initiatives across the technology environment.
- Lead cybersecurity awareness and education initiatives together with relevant business functions.
- Provide management reporting on cybersecurity posture, incidents, risks, vulnerabilities and remediation progress.
2.Technology Governance, Risk s Compliance (GRC)
- Lead IT and cybersecurity governance, risk and compliance activities across the organization.
- Maintain technology governance frameworks, policies, standards and procedures appropriate to organizational requirements.
- Own and maintain the technology risk register and oversee risk treatment and remediation actions with accountable risk owners.
- Coordinate technology-related audit activities, evidence gathering, remediation and audit readiness.
- Maintain governance and control requirements supporting ISO 27001/ISMS, ITGC and other applicable technology compliance obligations.
- Monitor compliance with approved technology policies, standards and security requirements.
- Establish practical governance mechanisms that balance control requirements with business and operational needs.
- Support technology-related regulatory and data protection requirements in coordination with the Data Protection Officer(DPO) and relevantbusiness owners.
- Provide regular reporting to the CTO and relevant management/governance forums on technology risks, compliance status,audit findings and remediation progress.
3.Cybersecurity Resilience s Incident Preparedness
- Establish and maintain cybersecurity incident response and escalation frameworks.
- Coordinate cybersecurity incident response exercises and readiness assessments with relevant technology teams,business functions and external partners.
- Ensure cybersecurity considerations are incorporated into technology continuity and crisis management arrangements.
- Support enterprise crisis management for significant cybersecurity incidents.
- Track lessons learned from cybersecurity incidents and exercises and ensure agreed improvement actions are implemented.
- Collaborate with infrastructure and application owners on recovery and resilience requirements without assuming operational ownership of their platforms.
4.Digital Workplace s End-User Services
- Own the Digital Workplace service covering end-user computing, endpoint support and workplace technology services.
- Ensure responsive and reliable end-user support across headquarters, retail outlets and other business locations.
- Oversee endpoint provisioning, configuration, support, patching and security compliance in accordance with approved standards.
- Govern device lifecycle activities including onboarding, replacement, reassignment and secure decommissioning in coordination with relevant assetowners.
- Define and monitor service levels, support performance and user experience metrics.
- Ensure appropriate escalation from L1 support to infrastructure, application or external support teams based on defined ownership.
- Identify opportunities to improve employee productivity, support efficiency and Digital Workplace experience through standardization, automation and appropriate technology adoption.
5.Security, Technology Control s Third-Party Risk Management
- Define minimum cybersecurity and technology control requirements applicable across infrastructure, applications, endpoints and third-party services.
- Establish and maintain the technology and cybersecurity components of the organization's Third-Party Risk Management (TPRM) framework.
- Conduct or coordinate risk-based cybersecurity and technology assessments of relevant third parties during onboarding, renewal and where material changes or risks arise.
- Review technology-related contracts, agreements and Information Security Appendices (ISA) to identify cybersecurity, technology risk, compliance and third-party control requirements, gaps and obligations.
- Work with Legal, Procurement, business owners and technology stakeholders to ensure material security requirements and third-party risks are appropriately addressed before contractual commitment.
- Track material third-party technology and cybersecurity risks, findings and remediation actions, and escalate unresolved or unacceptable risks through the appropriate governance channels.
- Participate in technology initiatives and significant changes where cybersecurity, technology risk or compliance assessment is required.
- Ensure appropriate security reviews are incorporated into technology procurement, implementation and change processes.
- Work with respective technology owners to assess compliance with established security and technology control requirements and address identified gaps.
- Escalate material control deficiencies, contractual security risks and technology risks to the CTO where they cannot be adequately addressed or accepted within established authority.
6.Vendor s ManagedServices Governance
- Govern external service providers supporting cybersecurity, SOC, Digital Workplace and other ISG-managed services.
- Establish and monitor appropriate SLAs, KPIs, service expectations and contractual obligations.
- Conduct regular service reviews and ensure performance issues are addressed and escalated where necessary.
- Ensure clear accountability between internal teams and external service providers to avoid ownership gaps.
- Assess vendor performance, capability, cost effectiveness and continued suitability.
- Reduce unnecessary dependency on individual vendors by maintaining appropriate documentation, knowledge transfer and internal oversight capability.
7.Leadership s Capability Development
- Lead, coach and develop the ISG team across cybersecurity, GRC and Digital Workplace responsibilities.
- Define clear roles, responsibilities, KPIs and development expectations for team members.
- Build sustainable internal capability while making appropriate use of specialized external expertise.
- Establish succession and knowledge-transfer arrangements for critical ISG responsibilities.
- Promote collaboration between ISG, other technology divisions and business stakeholders.
- Foster a risk-aware and security-conscious culture without creating unnecessary barriers to business execution.
8.Financial s ResourceManagement
- Develop and manage the ISG operating budget and resource requirements.
- Manage cybersecurity, Digital Workplace and ISG-related vendor expenditure.
- Identify opportunities for cost optimization, service consolidation and improved utilization of technology investments.
- Support annual planning and investment prioritization based on business risk, regulatory requirements, operational needsand technology strategy.
- Ensure ISG investments provide appropriate business value and risk reduction.
Requirements s Qualifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems or a related discipline.
- Approximately 5+ years of relevant technology experience, including experience leading teams, functions or significant technology responsibilities.
- Practical experience in cybersecurity, technology governance, risk, compliance or IT service management.
- Experience managing cybersecurity operations and/or external SOC/security service providers.
- Working knowledge of cybersecurity risk management, vulnerability management and incident response.
- Familiarity with ISO 27001/ISMS, ITGC, PDPA and technology audit requirements.
- Experience with third-party technology/cybersecurity risk assessments and reviewing security requirements within contracts, vendor agreements or security appendices.
- Experience managing outsourced or managed technology services and vendor performance.
- Understanding of endpoint management, end-user computing and Digital Workplace environments.
- Strong stakeholder management skills with the ability to work across technical teams, business functions, auditors and external service providers.
- Ability to translate technology and cybersecurity risks into clear business impact and management actions.
- Experience in a multi-site, retail or similarly distributed operating environment is an advantage.
More Info
Key Skills
cybersecurity management
endpoint management
third-party risk management
cybersecurity policies
threat detection
