- Kuala Lumpur, Kuala Lumpur Kuala Lumpur WP Kuala Lumpur Malaysia
Working Location
Job Description
Responsibilities
We are Malaysia’s leading Credit Reporting Agency (CRA) and we are aggressively expanding our business, and looking for dynamic, driven and motivated individuals to join our team. Our Direct-To-Consumer segment (D2C), is one of our fastest growing product areas in the market, with an abundance of expansion plans and innovative ideas on hand.
ROLE OVERVIEW
The Group Chief Risk & Compliance Officer is responsible for establishing and leading the Group's integrated Risk, Cybersecurity, and Compliance functions to safeguard the organisation's assets, reputation, operations, and long-term sustainability.
The incumbent provides strategic leadership in developing enterprise-wide governance frameworks that proactively identify, assess, mitigate, monitor, and report risks across the organisation while ensuring full compliance with applicable laws, regulations, industry standards, and internal policies.
This role will partners closely with the Board, Risk Management Committee, regulators, and business leaders to strengthen organisational resilience, cybersecurity posture, governance standards, and regulatory compliance.
KEY RESPONSIBILITIES
Enterprise Risk Management
· Develop and execute the Group's Enterprise Risk Management (ERM) strategy and framework.
· Establish enterprise risk governance, policies, methodologies, and risk appetite aligned with business objectives.
· Oversee strategic, operational, financial, technology, legal, and emerging risks across the Group.
· Ensure consistent risk identification, assessment, mitigation, monitoring, and reporting across all business functions.
· Drive a proactive risk culture through effective governance, education, and accountability.
· Present enterprise risk reports, emerging risks, and mitigation strategies to the Executive Committee and Board Risk Committee.
· Ensure business continuity planning and crisis management frameworks remain effective and regularly tested.
Cybersecurity & Information Security
· Provide executive oversight of the Group's cybersecurity strategy, governance, and operational resilience.
· Ensure cybersecurity frameworks align with recognised industry standards (e.g. ISO 27001, NIST, CIS Controls).
· Oversee cyber risk management, security operations, vulnerability management, identity and access management, and threat intelligence.
· Ensure effective incident response, cyber crisis management, disaster recovery, and post-incident reviews.
· Monitor emerging cyber threats and technology risks, recommending strategic initiatives to strengthen the organisation's security posture.
· Oversee cybersecurity awareness programmes to foster a security-conscious culture across the organisation.
· Report cybersecurity risks, key metrics, and incidents to senior management and the Board.
Compliance Management
· Lead the Group's compliance function covering business, regulatory, and corporate compliance.
· Develop and maintain enterprise-wide compliance frameworks, policies, and governance standards.
· Ensure compliance with all applicable laws, regulations, licensing obligations, and industry requirements.
· Oversee regulatory engagement, inspections, audits, and reporting obligations.
· Monitor regulatory developments and assess business impact.
· Establish compliance monitoring, investigations, and remediation programmes.
· Ensure appropriate governance over conflicts of interest, ethical conduct, anti-bribery, whistleblowing, and corporate governance practices.
Governance & Board Advisory
· Advise the CEO, Executive Leadership Team, and Board on enterprise risks, cybersecurity, governance, and regulatory matters.
· Serve as the management liaison to the Board Risk Committee and other governance committees.
· Ensure Board reporting provides meaningful insights into the Group's overall risk profile.
· Recommend strategic improvements to governance frameworks, internal controls, and organisational resilience.
· Promote strong risk governance and accountability across all business units.
Internal Controls & Assurance
· Strengthen enterprise-wide internal control frameworks to minimise operational and compliance risks.
· Oversee risk and compliance monitoring activities and ensure timely remediation of identified gaps.
· Collaborate closely with Internal Audit while maintaining appropriate independence of assurance functions.
· Ensure corrective action plans are effectively implemented and monitored.
Regulatory & Stakeholder Management
· Build and maintain trusted relationships with regulators, industry bodies, auditors, external advisors, and key stakeholders.
· Represent the organisation during regulatory reviews, audits, and compliance assessments.
· Support regulatory submissions, licensing requirements, and governance reporting.
Strategic Leadership
· Develop and execute the Group Risk & Compliance strategic roadmap aligned with corporate objectives.
· Lead organisational transformation initiatives relating to governance, risk, compliance, and cybersecurity maturity.
· Drive continuous improvement through digitalisation, automation, data analytics, and emerging technologies.
· Establish enterprise risk indicators (KRIs), compliance metrics, and cybersecurity performance dashboards.
· Foster collaboration across business units to embed effective risk management and compliance practices.
Leadership & People Management
· Lead, mentor, and develop high-performing Risk, Compliance, and Cybersecurity teams.
· Build organisational capabilities through succession planning, coaching, and continuous learning.
· Promote a culture of integrity, accountability, transparency, and responsible risk-taking.
· Manage departmental budgets, resources, and strategic priorities to ensure effective delivery.
WHAT DOES IT TAKE TO BE SUCCESSFUL
Qualifications
· Bachelor's Degree in Risk Management, Information Security, Cybersecurity, Business, Finance, Law, Accounting, or a related discipline.
· Master's Degree or MBA is preferred.
· Professional certifications such as CRISC, CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, CPA, CA, CIA, CAMS, or equivalent are advantageous.
Work Experience
· 15+ years of progressive leadership experience in Enterprise Risk Management, Cybersecurity, Compliance, or Governance.
· 8+ years in a senior leadership or executive role.
· Experience leading enterprise-wide governance programmes within a large corporate, financial services, technology, fintech, or regulated industry.
· Proven experience engaging Boards, Executive Committees, regulators, and external auditors.
· Strong understanding of cybersecurity governance, enterprise risk management, regulatory compliance, and corporate governance frameworks.
· Experience leading organisational transformation and enterprise-wide change initiatives.
Skills & Competencies
· Demonstrates strong strategic leadership with the ability to align enterprise risk, cybersecurity, and compliance strategies with the Group's business objectives.
· Possesses deep expertise in enterprise risk management, cybersecurity governance, regulatory compliance, corporate governance, and internal control frameworks.
· Exhibits sound commercial acumen and exercises independent judgment in managing complex risks and making strategic decisions.
· Builds trusted relationships and effectively influences the Board, Executive Management, regulators, auditors, and key stakeholders.
· Leads and inspires high-performing teams while fostering a culture of integrity, accountability, collaboration, and continuous improvement.
· Communicates complex risk and compliance matters clearly and effectively to both technical and non-technical audiences.
· Demonstrates resilience, adaptability, and sound crisis management capabilities in a dynamic and evolving business environment.
· Upholds the highest standards of ethics, professionalism, and governance while driving sustainable business performance.
Min. Education: Degree
Back Apply
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.