Search Jobs

Search by job, company or skills

Security Assurance & Reverse TPSA , Manager

Security Assurance & Reverse TPSA , Manager

Accion Labs Sdn Bhd
4-12 Years
MYR 2,000 - 8,000 per month
Early Applicant
Quick Apply
  • Posted 10 days ago
  • Be among the first 10 applicants

Job Description

Job Title: Security Assurance & Reverse TPSA , Manager

Role Purpose

The Reverse TPSA Manager is responsible for managing and coordinating security, technology risk, privacy, and compliance assessments conducted by AIA Malaysia's clients, brokers, consultants, and prospective customers.

The role serves as the central point of contact for all client security due diligence activities, ensuring timely and accurate responses to Third-Party Security Assessments (TPSAs), Requests for Security Information (RFSIs), client audits, and cybersecurity questionnaires. The individual will work closely with Information Security, Technology, Risk Management, Legal, Compliance, Privacy, Procurement, and Business Units to articulate AIA Malaysia's security posture and control environment while protecting confidential and proprietary information.

This role is critical in enabling business growth, strengthening client trust, and demonstrating AIA Malaysia's commitment to cybersecurity, operational resilience, and regulatory compliance.

Key Responsibilities

Reverse TPSA Management

  • Lead and manage end-to-end client Third-Party Security Assessment (TPSA) activities.
  • Serve as the primary coordinator for security due diligence requests from Corporate Solutions clients and prospective customers.
  • Review, assess, and complete security questionnaires covering cybersecurity, cloud security, data protection, operational resilience, business continuity, and regulatory compliance.
  • Ensure responses are accurate, consistent, evidence-based, and aligned with AIA Group and AIA Malaysia security standards.
  • Track TPSA requests and ensure completion within agreed timelines and service levels.

Client Security Assurance

  • Represent AIA Malaysia's cybersecurity and technology risk control environment during client due diligence engagements.
  • Support client discussions, workshops, and security review meetings.
  • Explain technical controls and security practices in clear business language suitable for non-technical stakeholders.
  • Address security concerns raised by clients and coordinate responses with relevant subject matter experts.

Stakeholder Management

  • Collaborate with:
  • Information Security
  • Technology Services
  • Enterprise Architecture
  • Data Privacy Office
  • Legal
  • Compliance
  • Operational Risk
  • Corporate Solutions Business
  • Third-Party Risk Management Teams
  • Coordinate collection of evidence and validation of control effectiveness.
  • Escalate complex security or compliance issues where required.

Documentation & Evidence Management

  • Maintain a centralized repository of:
  • Standard TPSA responses
  • Security evidence packages
  • Regulatory and compliance documentation
  • Frequently requested client artifacts
  • Security certifications and attestations
  • Ensure all externally shared information complies with AIA's information classification and disclosure requirements.
  • Conduct periodic reviews of security response libraries to maintain accuracy and relevance.

Regulatory & Compliance Support

  • Support responses related to:
  • BNM Risk Management in Technology (RMiT)
  • Personal Data Protection Act (PDPA)
  • ISO 27001
  • NIST Cybersecurity Framework
  • AIA Group Security Standards
  • Operational Resilience requirements
  • Ensure client responses remain aligned with prevailing regulatory obligations and corporate policies.

Metrics & Continuous Improvement

  • Develop and maintain TPSA performance metrics and reporting dashboards.
  • Monitor trends in client security requirements and emerging cybersecurity expectations.
  • Identify recurring assessment themes and recommend process improvements.
  • Improve automation, standardization, and efficiency of security assessment responses.

Required Qualifications

  • Bachelor's Degree in Information Security, Cybersecurity, Information Technology, Risk Management, Computer Science, or a related discipline.
  • Minimum 5-8 years of experience in:
  • Information Security
  • Technology Risk
  • Security Governance
  • Security Assurance
  • IT Audit
  • Third-Party Risk Management

Required Knowledge & Skills

Cybersecurity & Risk Knowledge

Strong understanding of:

  • Information Security Governance
  • Cybersecurity Risk Management
  • Cloud Security Controls
  • Identity & Access Management
  • Vulnerability Management
  • Incident Response
  • Data Protection and Privacy Controls
  • Business Continuity and Disaster Recovery

Frameworks & Regulations

Knowledge of:

  • ISO 27001
  • NIST Cybersecurity Framework
  • SOC Reports
  • CIS Controls
  • BNM RMiT
  • PDPA Malaysia
  • Operational Resilience principles

Communication & Stakeholder Management

  • Excellent written communication and documentation skills.
  • Ability to respond to detailed client security questionnaires.
  • Strong stakeholder engagement and influencing capabilities.
  • Ability to translate technical controls into concise business-friendly responses.
  • Strong presentation and facilitation skills.

Analytical Skills

  • Strong problem-solving and critical-thinking capabilities.
  • Ability to assess client requirements and map them to existing controls.
  • Ability to identify gaps, risks, and potential remediation actions.

Preferred Qualifications

Professional certifications such as:

  • CISSP
  • CISM
  • CRISC
  • CISA
  • ISO 27001 Lead Auditor / Lead Implementer
  • CCSP

Experience in:

  • Insurance industry
  • Financial services sector
  • Customer-facing security assurance roles
  • Responding to large enterprise or multinational client TPSAs

Key Performance Indicators (KPIs)

  • 100% completion of TPSA requests within agreed SLA.
  • Reduction in reverse TPSA turnaround time.
  • Zero unauthorized disclosure of confidential information.
  • Positive feedback from Corporate Solutions clients and internal stakeholders.
  • Continuous improvement of response repository and knowledge base.
  • Increased reuse of standardized responses and evidence artifacts.
  • Successful support of client onboarding and retention efforts through effective security assurance engagement.

 

More Info

Job Type:
Function:
Employment Type:

About Company

Accion Labs is an -, - headquartered in Pittsburgh. At the core is our mission to enhance lives by transforming businesses through innovation. We focus on applying next-generation technologies to solve complex challenges and accelerate enterprise transformation.

With a global presence across 23 locations and a team of 4,200+ employees, including 1,000+ trained in AI and GenAI, we help organizations modernize through a unique blend of engineering excellence, proprietary IP, and proven execution models. Our delivery methodology is built on a strong operational framework and a mature governance model that fosters true partnership and joint ownership through equal investments.

Recruiter

About Recruiter

Deepika Kadakanchi

0 Active Jobs

Similar Jobs

10-12 yrs
Malaysia, Kuala Lumpur
Skills:
Software Development LifecycleIT SecurityProject ManagementInfrastructure ProjectsProject Management MethodologiesEnterprise ArchitecturesRisk Management
8-10 yrs
Malaysia, Kuala Lumpur
Skills:
AmlChange ManagementOperational ExcellenceClient Due DiligenceCFTFinancial Crime ComplianceKycRegulatory ComplianceProcess ImprovementRisk Management
7-9 yrs
Malaysia, Kuala Lumpur
Skills:
CcnaAutomation ToolsCisco TechnologiesAgileSowCCST Securityproject managementAiFinancial ForecastingPMIContract Compliancerisk detectionCCST NetworkingPmpcustomer satisfaction metricsCPMAIdefect ratesdeployment timelinesReporting
5-7 yrs
Malaysia, Kuala Lumpur
Skills:
NetworkingData Centre ConstructionVendor managementCablingProject managementAI infrastructureStrategic PlanningProgram Portfolio managementProject scheduling and trackingComputeBudget ManagementRisk management
3-8 yrs
Remote, India
Skills:
Systems IntegrationSoftware Engineeringautomation AIsecurity reviewsRPA program operationsagentic automationSolution EngineeringDevOps automation developmentlegacy system integrationsUiPath automationstechnical deploymentaccreditation constraintsproduction deployment blockersnetwork accessAI-enabled workflows