Search by job, company or skills

Lead, Technology Security Operations

  • Posted 12 hours ago
  • Be among the first 10 applicants

Job Description

We fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion – LEAP

We are a culture that empowers everyone to innovate and create solutions that will leave a positive impact on our communities and our nation, Touch n Go will always be here to inspire our talents to grow as leaders and innovators giving you the power to make a difference

What would you do Technology & Cyber Risk Management

  • Own and maintain the centralized Technology & Cyber Risk Register, ensuring risks are accurately identified, assessed, documented, monitored, and reported
  • Perform risk assessments across IT infrastructure, applications, cloud environments, cybersecurity controls, and technology operations
  • Define and maintain risk ratings, risk ownership, mitigation strategies, compensating controls, and risk acceptance records
  • Ensure technology and cyber risks are managed in accordance with internal governance standards and regulatory requirements, including NACSA Arahan No. 5 and Bank Negara Malaysia's Risk Management in Technology (RMiT) frameworsk
  • Facilitate periodic risk reviews with stakeholders and ensure risk treatment plans are implemented and tracked to completion
  • Identify emerging technology and cyber threats and assess their potential impact on the organization

Audit & Regulatory Coordination

  • Act as the primary liaison and coordinator for all technology and cybersecurity-related audits, reviews, and regulatory assessments
  • Coordinate audit activities involving Internal Audit, External Audit, regulators, and other assurance functions
  • Manage requests for information, evidence collection, documentation reviews, and audit responses
  • Translate audit observations and regulatory findings into actionable remediation plans with clear ownership and accountability
  • Monitor remediation progress and ensure findings are resolved within agreed timelines
  • Maintain comprehensive records and evidence repositories to support audit readiness and regulatory compliance
  • Track all audit and regulatory findings through to formal closure and validation

IT & Cyber Issue Management

  • Establish and maintain a centralized IT & Cyber Issue Register encompassing audit findings, vulnerability assessment results, penetration testing findings, security alerts, operational issues, and control weaknesses
  • Drive the end-to-end issue management lifecycle, including identification, assessment, assignment, tracking, validation, and closure
  • Ensure issue owners are accountable for implementing effective remediation actions within established timelines
  • Monitor remediation Service Level Agreements (SLAs) and escalate overdue, high-risk, or unresolved issues to management
  • Validate closure evidence to ensure issues have been effectively remediated and associated risks adequately mitigated
  • Identify recurring issues, systemic weaknesses, and trends to support continuous improvement initiatives

Cross-Functional Coordination

  • Serve as the central coordination point between IT Operations, Security Operations, technology teams, vendors, and service providers
  • Ensure effective collaboration and communication across stakeholders involved in risk mitigation and issue remediation activities
  • Manage cross-functional dependencies and facilitate timely resolution of technology and cybersecurity issues
  • Drive proactive follow-up and governance oversight to prevent issues from being overlooked or delayed
  • Support the resolution of complex issues requiring engagement across multiple functions

Governance, Risk & Compliance (GRC) Enablement

  • Act as the key interface between technical teams and governance functions, including Risk Management, Compliance, and Audit
  • Translate technical findings and cybersecurity concerns into meaningful business risk impacts for management and governance stakeholders
  • Interpret regulatory, risk, and compliance requirements and coordinate implementation activities with technology teams
  • Ensure consistency and traceability across risk registers, issue registers, audit findings, and remediation plans
  • Support governance reviews, risk assessments, policy compliance activities, and control effectiveness reviews

Governance Reporting & Stakeholder Management

  • Prepare and present regular reports and dashboards on technology risks, cybersecurity issues, audit findings, remediation progress, and compliance status
  • Provide meaningful analysis and recommendations to support risk-based decision-making by senior management and governance committees
  • Support risk prioritization, mitigation planning, and risk acceptance discussions
  • Deliver accurate, timely, and consistent reporting to the Head of IT Security, CTO, Risk Committees, and other governance forums
  • .Escalate significant risks, control deficiencies, and remediation delays to appropriate management levels where required

Who should join us

  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Risk Management, or a related discipline
  • Professional certifications such as CISA, CISM, CRISC, CISSP, CGEIT, or ISO 27001 Lead Auditor/Lead Implementer are highly desirable
  • Minimum 5 years of experience in Technology Risk Management, Cybersecurity Governance, IT Audit, IT Compliance, Information Security, or related disciplines
  • Knowledge of technology risk management and cybersecurity governance pratice
  • Familiarity with NACSA Arahan No. 5, BNM RMiT, ISO 27001, NIST Cybersecurity Framework, and related industry standards
  • Strong stakeholder management and communication skills
  • Excellent analytical, problem-solving, and coordination abilities
  • Strong report writing and presentation skills
  • Ability to influence stakeholders and drive accountability across technical and non-technical teams.
  • Strong organizational skills with the ability to manage multiple priorities simultaneously

Our Perks & Benefits:

  • Hybrid work arrangement and flexi hours.
  • e-Wallet meal allowance.
  • Unlimited office pantry fruits, snacks and drinks.
  • Mobile and broadband subscription reimbursement.
  • Flexibility to opt dependents coverage (spouse, child, parents or parents-in-law) for outpatient medical benefits.
  • Additional leave including family leave and paid care leave to care for family members.
  • Medical coverage including dental, optometrist, mental care, maternity, registered
  • Traditional Chinese Medicine (TCM) and Chiropractic.
  • Corporate membership discount and many more to explore.

We believe that you have what it takes to fit into the Touch n Go family and help revolutionize the Fintech industry by paving the way to a cashless society. If you're ready to take the next step, apply now!

Touch n Go is an organization that strives to provide Equal Opportunity Employment, based on merit, qualifications, capabilities, and calibre. It is Touch n Go's policy to not discriminate based on age, race, religion, colour or other personal status, identity or characteristics. Fair Opportunity is Our Value and Practice. Please advise us of any accommodations you may need by e-mailing: [Confidential Information]

Note: Only shortlisted candidates will be contacted.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 151667205

Similar Jobs

Malaysia, Kuala Lumpur

Skills:

analytical capability NegotiationInternal control and complianceMicrosoft Office ApplicationsFamiliarity with Incoterms and shipping terminologyContract Drafting

Malaysia, Kuala Lumpur

Skills:

ServicenowAribaAdvanced Exceldashboard reportingProcurement Operations

Malaysia, Kuala Lumpur

Skills:

JavaPostgreSQLMicrosoft Sql ServerJenkinsMySQLAWSe-commerceJava profilingJVM tuningCI CDGC mechanismsheap dump analysis

Malaysia, Kuala Lumpur

Skills:

internet traffic operationsRFMmanagement experienceattribution analysisconsumer credit operationsinternet finance operating frameworksAARRRuser segmentation

Malaysia, Kuala Lumpur

Skills:

stock transfers Microsoft ExcelPurchasingConsignment ReportingInventory Accounting ERPInventory ManagementGoods Received NotesInventory ReconciliationLogistics Coordination