jobs in Affin Bank Berhad

Affin Bank Berhad Hiring! Full Time Head, Cyber Risk Management in WP Kuala Lumpur - Ricebowl

Head, Cyber Risk Management jobs

Head, Cyber Risk Management

Undisclosed

Bandar Kuala Lumpur, WP Kuala Lumpur

Be an early applicant!
Be an early applicant!
Share
Save

Working Location

  • Lingkaran TRX Bandar Kuala Lumpur WP Kuala Lumpur Malaysia 55100

Job Description

Requirements

Academic & Professional Qualifications

  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, Risk Management, or related discipline.

  • Professional certifications are highly preferred (e.g., CISSP, CISM, CRISC, CISA, or equivalent).

Experience

  • Minimum 8 of relevant experience in cyber risk, technology risk, or IT security, preferably within the financial services industry.

  • Proven experience in a leadership role managing cyber risk or technology risk functions.

  • Strong familiarity with regulatory requirements such as BNM RMiT, SC guidelines, and Bursa Malaysia expectations.

Technical & Functional Competencies

  • Strong understanding of cyber risk frameworks, IT governance, and security controls.

  • Experience in risk assessment methodologies, cyber threat landscape, and incident management oversight.

  • Ability to challenge technical stakeholders and provide independent risk perspectives.

Behavioural Competencies

  • Strong leadership and stakeholder management skills, with the ability to influence across all levels of the organisation.

  • High level of integrity, professionalism, and sound judgement.

  • Strong analytical thinking, decision-making, and problem-solving capabilities.

  • Effective communication and presentation skills, particularly at senior management and Board level.

Responsibilities

1. Cyber Risk Oversight & Governance

  • Lead the independent oversight of cyber and technology risks across the Group in line with the Bank’s Enterprise Risk Management Framework.

  • Establish and maintain cyber risk management policies, standards, and frameworks aligned to regulatory expectations and industry best practices.

  • Provide effective advisory to the First Line (Group Technology) on risk identification, mitigation plans, and control effectiveness.

2. Regulatory Compliance & Engagement

  • Ensure full compliance with regulatory requirements, including BNM Risk Management in Technology (RMiT), SC guidelines, and Bursa requirements.

  • Act as the central coordination point for regulatory reviews, audits, and submissions relating to cyber and technology risk.

  • Monitor regulatory developments and ensure timely implementation of new requirements across the Group.

3. Risk Assessment & Monitoring

  • Oversee the execution of cyber risk assessments, including IT risk assessments, vulnerability management oversight, and cyber resilience reviews.

  • Review and challenge risk and control self-assessments (RCSAs), key risk indicators (KRIs), and risk reporting provided by the First Line.

  • Ensure material risks are escalated appropriately to senior management and relevant governance committees.

4. Incident Oversight & Cyber Resilience

  • Provide oversight of major cyber incidents and ensure appropriate escalation, response, and post-incident review.

  • Assess the adequacy of incident response, disaster recovery, and business continuity plans from a cyber risk perspective.

  • Ensure lessons learned from incidents are embedded into risk mitigation strategies.

5. Stakeholder Management & Advisory

  • Serve as a trusted risk advisor to Group Technology, senior management, and business units on cyber risk matters.

  • Engage with internal stakeholders including Compliance, Internal Audit, and Business Units to ensure a coordinated risk management approach.

  • Present cyber risk insights, issues, and recommendations to senior management committees (e.g., Risk Management Committee, Board-level committees).

6. Team Leadership & Capability Building

  • Lead, develop, and mentor the Cyber Risk Management team to ensure strong technical and risk management capabilities.

  • Drive a culture of risk awareness and accountability across the organisation.

  • Ensure adequate resources, tools, and skillsets are in place to support evolving cyber risk landscape.

Benefits

  • Annual Leave
  • EPF
  • SOCSO
  • EIS

Skills

Communication

How to get to this company by public transport?

Bandar Kuala Lumpur

Nearby Public Transportation

All LRT MRT Monorail
  • MRT - TUN RAZAK EXCHANGE

    0.2 km

  • MRT - COCHRANE

    1.0 km

  • MRL - BUKIT BINTANG

    1.0 km

  • MRT - BUKIT BINTANG

    1.0 km

  • LRT - PUDU

    1.1 km

  • MRL - IMBI

    1.1 km

  • MRT - CONLAY

    1.2 km

  • MRT - CHAN SOW LIN

    1.4 km

  • LRT - CHAN SOW LIN

    1.4 km

  • MRL - HANG TUAH

    1.5 km

  • LRT - HANG TUAH

    1.5 km

  • MRL - RAJA CHULAN

    1.5 km

  • MRT - PERSIARAN KLCC

    1.8 km

  • MRT - MERDEKA

    1.9 km

  • LRT - PLAZA RAKYAT

    1.9 km

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More