Search by job, company or skills

Manager | Cybersecurity Risk Management

  • Posted an hour ago
  • Be among the first 10 applicants

Job Description

JOB SUMMARY

Manage cybersecurity risk management processes, advisory services, governance monitoring and reporting activities to ensure cybersecurity risks are consistently assessed, treated and escalated in line with EPF's policies, risk appetite and resilience objectives, while assisting in executing the CISO second line of defence role for cyber and technology risk matters, including cybersecurity risk management, timely incident response and reporting to NACSA, and oversight reporting to senior management and the Board.

JOB RESPONSIBILITIES

  • Manage and oversee the implementation and enhancement of the TRMF, CRF, and cybersecurity governance documents to ensure effective compliance and alignment with EPF and regulatory requirements.
  • Monitor and enforce cybersecurity regulatory compliance to ensure continuous alignment with applicable laws and regulatory requirements, including Act 854, the NACSA Code of Practice (CoP), and directives issued by the NACSA Chief Executive.
  • Manage and oversee end-to-end cybersecurity risk advisory for projects, systems, and operational processes by ensuring risk assessments, validation, and recommendations are delivered consistently and effectively.
  • Control and monitor third-party cybersecurity risk assessment activities by ensuring control assessments, gap identification, recommendations and remediation tracking are performed consistently across relevant vendor engagements.
  • Manage cybersecurity-related Technology Risk Exemptions (TRE) by ensuring proper risk advisory, governance documentation, mitigation tracking and escalation of material risks to relevant management committees.
  • Oversee and assist coordination with the Digital Security Department (SOTD/SOC) and relevant response teams during cyber crises (or simulations) and continuous improvement initiatives, encompassing cybersecurity incident risk assessment, breach impact analysis, remediation tracking, and post-incident risk updates.
  • Manage Emerging Risk and CRF KRI activities by monitoring forward-looking risk exposures, reviewing key indicators, coordinating assessment outcomes and reporting advisory insights to support proactive risk management and management decision-making.
  • Report management and governance committees on cybersecurity risk matters, including key risk exposures, control gaps, remediation progress and implications to EPF's business and operations.
  • Conduct a comprehensive review of Operating Manuals and Work Instructions within the technology division from a cybersecurity risk perspective to strengthen governance controls and support the continuous improvement of risk management practices.

JOB REQUIREMENTS

  • Malaysian citizen.
  • Obtain a pass in Bahasa Melayu, including an oral test in Sijil Pelajaran Malaysia (SPM) level or equivalent qualification recognised by the Government.
  • Possess a Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Risk Management or a related field. A Master's Degree is an added advantage.
  • At least 10 – 13 years of relevant experience in IT security, cybersecurity, technology risk management, cybersecurity risk management, IT audit, IT governance, compliance, advisory or related fields with experience leading workstreams or supervising team members.
  • Experience managing cybersecurity or technology risk assessment activities.
  • Experience providing cybersecurity risk advisory to business, technology or management stakeholders.
  • Experience reviewing risk assessment outputs, mitigation plans, dashboards, committee papers or management reports.
  • Experience coordinating cross-functional cybersecurity risk or governance initiatives.
  • Experience managing emerging risk activities, forward-looking risk monitoring or risk insight reporting.
  • Exposure to financial services, critical infrastructure, regulated environment or large enterprise environment is an added advantage.
  • Professional certifications such as C-CISO, CISM, CISSP, CRISC, ISO 27001, or equivalent cybersecurity/risk management certifications are highly desirable.
  • Strong knowledge of regulatory frameworks and standards such as BNM RMiT, TRMF, CRF, ISO/IEC 27001, NIST and related cybersecurity governance requirements.

PLACEMENT

Cybersecurity Risk Unit, Risk Management Advisory I Section, Risk Management Department

JOB STATUS

Permanent

All applications are strictly CONFIDENTIAL and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152392065

Beware of Scammers

We don’t charge money for job offers