Назад
Company hidden
11 дней назад

CISO (Fintech)

Формат работы
hybrid
Тип работы
fulltime
Грейд
c_level
Английский
b2
Страна
Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
CISO (Fintech): Building the information security and technology risk frameworks, controls, monitoring, and evidence for a regulated investment platform with an accent on regulatory compliance, operational resilience, and ISO/IEC 27001 certification. Focus on leading incident response, preparing for independent technology validation, operating security controls, and closing assessment gaps before platform registration.

Location: Bandar Utama, Petaling Jaya, Selangor, Malaysia; hybrid, with at least 3 days per week in the local office. Candidates must be based in, or able to work from, the advertised location.

Company

Regulated investment platform in Malaysia operated by doit Holdings.

What you will do

  • Own day-to-day technology risk oversight and deliver the board's cyber security strategy.
  • Build and maintain the technology risk and cyber security frameworks, risk appetite statement, and policy set.
  • Run security operations covering monitoring, vulnerability and patch management, access control, data protection, cryptography, and secure development.
  • Lead incident response from detection through recovery, including same-day reporting to the Securities Commission.
  • Prepare the platform for independent technology validation, close identified gaps, and take ISO/IEC 27001 from scoping through certification.
  • Deliver the annual cyber security awareness programme for the board, senior management, and staff.

Requirements

  • At least 8 years of information security experience, including 5 years in financial services or another regulated sector.
  • At least one of CISSP, CISM, or CISA is required.
  • Deep working knowledge of the Securities Commission's Guidelines on Technology Risk Management.
  • Strong experience in cyber security, operational resilience, cloud risk, and third-party risk.
  • ISO/IEC 27001 implementation experience through certification, plus a relevant degree and ability to meet the Securities Commission's fit and proper criteria.
  • Strong English communication is required.

Nice to have

  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification.
  • CRISC or CCSP certification.
  • Experience with a Securities Commission or Bank Negara Malaysia technology examination.
  • Hands-on experience reviewing controls, running simulations, and personally closing gaps.

Culture & Benefits

  • Hybrid work with flexibility to work remotely on days not spent in the office.
  • English is the main working language across global teams.
  • Fast-moving hiring process with an intended offer within one week from the start of interviews for strong candidates.

Hiring process

  • Introductory conversation.
  • Technical and regulatory deep dive.
  • CEO and final round.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →