Manager – ICT Governance & Compliance
Kuala Lumpur - Malaysia
Job Summary
This position is responsible for Information Security Governance and Compliance within the organization. It oversees the development distribution and management of information technology policies control procedures and standards which serve as the foundation for implementing technical and managerial security controls and validating compliance.
The role also owns the creation of security awareness content and training materials across various media along with managing the delivery of these programs both internally and externally working closely with internal communications and customer communication/relations teams to ensure consistent messaging.
Additionally this position is accountable for the functional performance and outcomes of ICT service desk operations.
Job Description:
Plan design and develop and improve the information security policies across the organization based on industry best practices. Stay relevant with latest publications of ISO27001 and other related security standards regulatory requirements and best practices.
To integrate new and existing policies into an established framework through use of ISO27001 mapping and other relevant frameworks. Improve and enhance the policies and align with corporate standards and guidelines. Develop and manage end to end process of policy management lifecycle.
Maintain operational baseline frameworks across technology infrastructure built upon ISO/IEC 27001 COBIT and ITIL standards.
Provide management and other stakeholders with indicators for validating information security maturity and measures for regulatory compliance. Highlight key information security risks and action plans and report to senior management.
Ensure all information security controls are in place and implemented
To co-ordinate with others in the Technology Security & Risk Management Group on related security policy controls and implementation.
Develop close working and technical relationships with all critical technology system owners to ensure that the policy controls are understood and implementation plans are in place.
To manage skills and knowledge transfer concerned with the security policies procedures and standards to respective team
Plan design and implement information security awareness programs internally and externally to customers (consumers and enterprise) to effectively mitigate the risk exposure and protect organization impact brand reputation.
Design Plan and Deliver sustainable Security awareness campaign including training sessions. Impart training and act as mentor to users and subordinates as required.
Drive continuous compliance audits evaluating adherence to Malaysias PDPA (BNM) RMIT guidelines (if applicable) and PCI-DSS requirements.
Liaise with internal and external auditors as and when required.
Design implement and police enterprise-wide DLP strategies to stop accidental or malicious leakage of Customer Personally Identifiable Information (PII) and Payment Card Industry (PCI) data across chat voice email and CRM environments.
Ensure SSL certificate usage and expiry to be tracked.
Asset Inventory both hardware and software is regularly monitored.
Conduct comprehensive BIA cycles across all core functions to map specific system dependencies and financial thresholds for downtime.
At regular intervals review routine backups and evaluate BCPs.
Liaise with Legal department to manage ICT contracts ensure SLAs are met and provide reminders to key internal stakeholders.
Overlook Helpdesk team and their day-to-day activities as and when required.
To contribute with all the inputs required for the budget planning for the functional units and prepare a complete budget file for ICT.
Qualifications and Skills:
Bachelors Degree with Business Management/Technology or equivalent
ITIL / ISO 27001/ PCI DSS etc.
Minimum of three (3) years of experience in ICT (Security Compliance Business IT or Service Desk Operations) methodologies tools and enablers.
Three (3) years management experience
In-depth knowledge of IT organization end-to-end areas and functions
Demonstrate in-depth technical capabilities and professional knowledge.
The Package:
- Attractive Salary up to RM7000
- Performance related allowance for confirmed staff
- Medical insurance provided
- Medical and Hospitalization Leaves