IT Security Governance Lead
Hong Leong Bank- Posted 16 hours ago
- Be among the first 10 applicants
Job Description
If you are looking to excel and make a difference, take a closer look at us…
Overview:
We are seeking a Team Lead, Security Governance specializing in Network Security Controls to manage a
team of governance specialists and oversee the policy, compliance, and risk management frameworks governing our bank's perimeter defenses.
In this role, you will lead the team acting as the ultimate authority on what security rules should be, ensuring our Firewalls, WAFs, Proxies, VPN infrastructure, and Wireless Access Networks strictly adhere
to banking regulations and internal security standards. You will direct the operationalization, documentation, regular review, and regulatory alignment of every rule, policy, network access pathway,
and application defense mechanism across the enterprise.
Responsibilities:
Team Leadership & Development: Lead, mentor, and build a high-performing team of Security Governance specialists. Manage resource allocation, performance evaluations, professional development, and day-to-day work prioritization.
Strategic Roadmap Execution: Establish operational goals, key performance indicators (KPIs), and long-term roadmap initiatives for the Network Security Governance team aligned with overall enterprise risk management strategies.
Cross-Functional Stakeholder Management: Act as the primary escalation point and bridge between governance, network engineering, Security Operations Center (SOC), enterprise risk, and external regulatory auditors
Security Framework Alignment: Oversee the definition and maintenance of the Bank's technical security standards, ensuring strict alignment with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Guide the review and updating of technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, Network Access Control (NAC) systems (Cisco ISE), and related perimeter devices.
Audit & Compliance Remediation: Lead technical readiness for internal, external, and regulatory audits. Drive team execution to track, prioritize, and validate the remediation of security findings and vulnerabilities across business units.
Metrics & KRI Reporting: Direct the tracking and executive reporting of Internal, PayNet, and Bank Negara Malaysia (BNM) regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF, NAC & Perimeter Governance: Oversee governance frameworks for WAF deployments (OWASP Top 10, API security baselines), wireless access architectures, 802.1X authentication, firewall rule lifecycles, and proxy/content filtering policies.
Exception & Risk Lifecycle Management: Standardize and supervise the formal evaluation, risk- scoring, and tracking processes for technical exception requests (e.g., emergency port openings, temporary WAF rule bypasses).
Regulatory & Audit Liaison: Serve as the lead subject matter expert and primary representative during central bank, regulatory, and internal audit engagements concerning perimeter and access security.
Skills & Experience We Are Looking For:
Experience: 8+ years in cybersecurity, technical risk, or IT audit, with 2+ years of direct team leadership, supervisory, or line management experience in a complex enterprise environment.
Perimeter Application Security Expertise: Deep technical and conceptual understanding of firewall architectures, Web Application Firewalls, secure web gateways/proxies, VPN platforms, and Cisco ISE identity/NAC frameworks.
Audit & Regulatory Mastery: Demonstrated track record interfacing with financial regulators (e.g., BNM, PayNet) and managing PCI-DSS, network segmentation, and banking compliance regimes.
Certifications: CISSP, CISA, CRISC, or CISM certifications highly preferred (or relevant senior networking/security certifications).
Mindset: A strategic, empathetic team leader who balances rigid process enforcement and audit rigor with pragmatic operational execution.
For more job opportunities, please go to HLB Careers:
More Info
Key Skills
Wireless Access Networks
KRI Reporting
Risk management frameworks
Web Application Firewalls (WAF)
SOC 2
PCI-DSS
802.1X authentication
Proxy content filtering
VPN infrastructure
ISO IEC 27001
CIS Benchmarks
Network Access Control (NAC)
