Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BJAK

Chief Information Security Officer

BJAK

. Own information security and technology risk for doit Holdings, a regulated investment platform in Malaysia.

Posted 10/3/2026full-timePetaling Jaya • MalaysiaLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in information security and technology risk management, with a strong focus on cyber security frameworks, incident response, and compliance with regulatory standards. Proven ability to implement ISO/IEC 27001 and deliver cyber security awareness programs to diverse stakeholders.

Highest-signal resume keywords
CISSPCISMCISAISO/IEC 27001 ImplementationSecurities Commission Guidelines

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information SecurityCyber SecurityTechnology Risk ManagementIncident ResponseVulnerability ManagementData ProtectionCryptographySecure DevelopmentOperational ResilienceCloud Risk Management
Soft Skills
Hands-On Operating StyleLeadershipCommunication
Certifications & Qualifications
CISSPCISMCISAISO/IEC 27001 Lead ImplementerISO/IEC 27001 Lead AuditorCRISCCCSP
Industry Keywords
Financial ServicesRegulated SectorSecurities CommissionBank Negara MalaysiaTechnology Examination

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Own information security and technology risk for doit Holdings, a regulated investment platform in Malaysia.
  • Hold board-appointed responsibility for day-to-day technology risk oversight and deliver the board's cyber security strategy.
  • Build technology risk and cyber security frameworks, the risk appetite statement and underlying policies; keep them approved and current.
  • Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
  • Own incident response from detection through recovery, including same-day reporting to the Securities Commission.
  • Lead independent technology validation required for platform registration and close identified findings.
  • Take ISO/IEC 27001 from scoping through certification.
  • Deliver the annual cyber security awareness programme for the board, senior management and staff.

Requirements

What you’ll need
  • Deep information security background, with at least 8 years in the field including 5 in financial services or another regulated sector.
  • At least one of CISSP, CISM or CISA; this is a requirement.
  • Deep command of the Securities Commission's Guidelines on Technology Risk Management.
  • Real depth in cyber security, operational resilience, and cloud and third-party risk.
  • ISO/IEC 27001 implementation experience through to certification.
  • A degree in computer science, information technology, information security or a cognate discipline, and ability to meet the Securities Commission's fit and proper criteria.
  • Hands-on operating style; able to review controls, run simulations and close gaps personally.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor, CRISC or CCSP, or experience of a Securities Commission or Bank Negara Malaysia technology examination is useful.