Chief Information Security Officer

BJAK
Malaysia
Workplace: HybridFull timeFunction: CybersecurityExperience: 8+ yearsEducation: bachelorsSkills: ["Hands-on execution","Communication"]

Own information security and technology risk for a regulated investment platform in Malaysia, serving as the board-named responsible person for technology risk. Build and maintain the security risk framework, policies, risk appetite, and monitoring evidence to pass independent validation. Lead security operations, incident response and reporting, guide ISO/IEC 27001 through certification, and roll out board-level cyber awareness across senior management and staff.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BJAK
BJAK
3 days ago

Chief Information Security Officer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Own information security and technology risk for a regulated investment platform in Malaysia, serving as the board-named responsible person for technology risk. Build and maintain the security risk framework, policies, risk appetite, and monitoring evidence to pass independent validation. Lead security operations, incident response and reporting, guide ISO/IEC 27001 through certification, and roll out board-level cyber awareness across senior management and staff.
Location: Malaysia
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: CXO level

Key Responsibilities

  • •Own board-appointed day-to-day technology risk oversight and deliver the board’s cybersecurity strategy for the regulated investment platform.
  • •Build and maintain technology risk and cyber security frameworks, including risk appetite and the policy set beneath them, keeping them approved and current.
  • •Run security operations covering monitoring, vulnerability and patch management, access control, data protection, cryptography, and secure development.
  • •Own incident response from detection through recovery, including reporting to the Securities Commission on the day an incident occurs.
  • •Take the platform through independent technology validation for registration, close findings, and deliver ISO/IEC 27001 from scoping through certification.

Key Requirements

  • •Deep information security background with at least 8 years in the field, including 5 in financial services or another regulated sector.
  • •Have at least one of CISSP, CISM, or CISA (required).
  • •Demonstrate deep command of the Securities Commission Guidelines on Technology Risk Management, operationalised rather than restated.
  • •Experience with ISO/IEC 27001 implementation through to certification, including scoping and certification readiness.
  • •Have a degree in computer science, information technology, information security, or a cognate discipline, and meet the SC fit and proper criteria.
Experience:8+ yearsFinancial services
Education:Bachelor's in computer science, information technology, information security
Skills:Hands-on executionCommunication
Certifications:CISSPCISMCISAISO/IEC 27001 Lead ImplementerISO/IEC 27001 Lead AuditorCRISCCCSP
Languages:English
Tech Stack:ISO/IEC 27001ISO/IEC 27001 Lead ImplementerISO/IEC 27001 Lead AuditorCISSPCISMCISACRISCCCSPCryptographyVulnerability managementPatch managementAccess controlSecure development

Company Brief

BJAK
Bjak is a Malaysia-based insurtech that operates an online insurance comparison and distribution platform across SEA, simplifying purchase and servicing of motor and life insurance using digital tools and AI-enabled services.
Industry: InsurTech
Company Size: Medium (51 to 250 employees)
Growth: Growth Stage Startup
Headquarters: Selangor, Malaysia
Founded: 2019
Glassdoor
Glassdoor: 2.5
WebsiteLinkedInGlassdoor