Cloud security governance
Kuala Lumpur
about the company
A financial powerhouse with a strong presence in the region
about the requirements ...- Develop & Mature Governance Framework: Lead design, implementation, and continuous improvement of the cloud security governance framework (policies, standards, procedures) aligned with BNM RMiT, PDPA etc
- Policy & Standards Leadership: Develop, approve, and disseminate cloud security policies and standards reflecting the institution's risk appetite and regulatory duties. Ensure effective communication and enforcement.
- Cloud Risk Management: Lead identification, assessment, and mitigation of cloud security risks per the Enterprise Risk Management framework and BNM guidelines. Oversee third-party cloud provider risk assessments and remediation of vulnerabilities. Report risk posture to senior management.
- Regulatory Compliance & Audit: Act as primary contact for cloud security compliance (BNM, etc.). Oversee compliance programs and manage internal/external cloud security audits. Maintain compliance documentation.
- Security Controls & Automation: Provide strategic direction for cloud security controls (IAM, DLP, encryption, network security, SIEM). Champion automation of security controls, monitoring, and compliance (IaC, policy-as-code, CSPM).
- Security Awareness & Training: Oversee targeted cloud security training for all staff levels, focusing on financial sector risks. Foster a strong security culture.
- Stakeholder Management: Collaborate with Cloud Engineering, DevOps, IT, Risk, Compliance, Legal, and Audit to embed security governance in cloud initiatives. Advise leadership on cloud security matters.
- Incident Response Oversight: Provide leadership during cloud security incidents, ensuring effective response, regulatory notification (BNM), and post-incident reviews.
- Metrics & Reporting: Define and track cloud security governance KPIs/KRIs. Report program effectiveness to senior management and Board committees. Drive continuous improvement.
- Industry Engagement: Stay updated on cloud security threats, technologies, and regulatory changes. Represent the institution in relevant forums.
- salary up to RM20,000
- medical insurance and fixed allowances
- performance bonus
- experience
- skills
- qualifications
- Bachelor's Degree in relevant field
- education
Bachelor Degree
share this job.
Bank Islam Malaysia BerhadKuala Lumpur
challenges while ensuring controls are implemented in timely and stipulated time towards adhering to the regulatory compliance requirements. He/She shall conduct and effective internal governance, assurance, risk and compliance of cloud security...
Kuala Lumpur
in enterprise cloud solutions, network security, and robust architecture governance to support business growth.
• Values innovation, compliance, and structured planning in all aspects of IT strategy and operations.
• Offers a dynamic, multi-site environment...
Logicalis Asia PacificKuala Lumpur
through its deep understanding of key IT industry drivers such as security, cloud, data management and IoT, can address customer priorities such as revenue growth and business, operational efficiency, innovation, risk and compliance, data governance...