Skip to content

Open nowPosted 2 days ago

Chief Information Security Officer

Workable (global search)108,016 open roles

Where
Petaling Jaya, Selangor, Malaysia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowChief Information Security OfficerWorkable (global search) · Petaling Jaya, Selangor, Malaysia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 2 days ago

Workable (global search) median: 7 days open

The posting

About the Role

The CISO will own information security and technology risk for doit Holdings, our regulated investment platform in Malaysia, and will be the person the board names as responsible for technology risk under the Securities Commission's Guidelines on Technology Risk Management. Nothing exists yet. The framework, the controls, the monitoring and the evidence all have to be built, and they have to hold up to an independent assessment before the platform can be registered.

What you will be doing

  • Hold the board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.
  • Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.
  • Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
  • Own incident response from detection through recovery, including the report to the SC on the day an incident occurs.
  • Take the platform through the independent technology validation that gates registration, and close what it finds.
  • Take ISO/IEC 27001 from scoping through to certification.
  • Deliver the annual cyber security awareness programme across the board, senior management and staff.

Location

This is a hybrid role. You are expected to work from our local office at least 3 days per week, with the remaining days offering flexibility to work remotely.

Candidates should be based in, or able to work from, the location where the role is advertised.

Language

English is our main working language across global teams. Strong English communication is required.

Interview Process

Our process is designed to move fast:

1. Introductory conversation

2. Technical and regulatory deep dive

3. CEO / final round

For strong candidates, we aim to complete the process and make an offer within 1 week from the start of the interview process. Candidates who complete assessments quickly will be prioritized.

Requirements

  • Deep information security background, with at least 8 years in the field including 5 in financial services or another regulated sector.
  • At least one of CISSP, CISM or CISA. This is a requirement. These are the certifications the SC names as acceptable for the external party who assesses technology risk controls, and the officer who owns those controls should not sit below the standard set for the officer who audits them.
  • Deep command of the SC's Guidelines on Technology Risk Management, operationalised rather than restated.
  • Real depth in cyber security, operational resilience, and cloud and third-party risk.
  • ISO/IEC 27001 implementation experience through to certification.
  • A degree in computer science, information technology, information security or a cognate discipline, and able to meet the SC's fit and proper criteria.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor, CRISC or CCSP, or experience of an SC or BNM technology examination, is useful.
  • Hands-on operating style. Able to review the controls, run the simulation and close the gaps personally.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.