jobs in Telekom Malaysia

Telekom Malaysia Hiring! Full Time Manager Cybersecurity Specialist (GRC) in Federal Territory - Ricebowl

Manager Cybersecurity Specialist (GRC)

Undisclosed

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

ABOUT THE JOB


The role is responsible for leading Cybersecurity Governance, Risk and Compliance (GRC) advisory engagements covering cyber strategy, maturity and assurance, cyber risk management, regulatory compliance, third-party risk, privacy, Business Continuity Management (BCM)/Business Continuity Planning (BCP) and technology governance.

The role owns engagements from opportunity identification, presales consulting and scoping through delivery, executive reporting, remediation planning and engagement closure. The position contributes to the growth and development of TM One's Cybersecurity GRC Advisory services.



KEY RESPONSIBILITIES


Presales & Business Development

  • Act as the lead customer-facing SME for Cybersecurity GRC opportunities.
  • Lead discovery, strategy, risk and regulatory-readiness workshops.
  • Translate customer objectives, risk appetite and regulatory obligations into suitable advisory approaches.
  • Develop proposals, Statements of Work (SOW), methodologies, assumptions, estimates and timelines.
  • Support RFP/RFQ/tender responses and technical clarifications.
  • Identify follow-on opportunities across TM One's wider cybersecurity portfolio.


Advisory & Consulting Delivery

  • Lead cyber maturity, regulatory compliance and control-effectiveness assessments.
  • Support cyber risk framework, risk appetite, risk register, scenario analysis and quantification engagements.
  • Lead third-party risk management (TPRM) tiering, due diligence and continuous monitoring engagements.
  • Lead privacy governance, data protection and technology/AI governance assessments.
  • Lead Business Impact Analysis, continuity risk assessment, BCP and crisis-management plan development.
  • Facilitate tabletop exercises, simulation exercises, call-tree tests and post-exercise reviews.
  • Develop policies, control frameworks, metrics and executive dashboards.
  • Present findings and recommendations to CISOs, risk owners and compliance stakeholders.


Engagement Governance & Quality Assurance

  • Serve as engagement lead for assigned GRC assignments.
  • Establish delivery plans, responsibilities, milestones and acceptance criteria.
  • Ensure findings are evidence-based and recommendations are practical, prioritized and risk-aligned.
  • Review maturity scores, risk statements, roadmaps and executive reports before customer submission.
  • Manage scope changes, dependencies, customer expectations and escalations.
  • Ensure confidentiality, independence and conflict-of-interest controls are maintained across engagements.


Practice & Service Development

  • Develop reusable methodologies, control libraries, maturity models and assessment accelerators.
  • Support productization of GRC services with standard scope, deliverables and pricing assumptions.
  • Maintain regulatory and standards mappings and help refresh the portfolio as requirements evolve.



CANDIDATE MUST HAVE


Bachelor's Degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, Accounting, Business or related field. A relevant Master's Degree or MBA is an advantage.


WE VALUE


  • Minimum 8 years in Cyber Security
  • Hands-on leadership of at least two end-to-end BCM/BCP engagements is strongly preferred.
  • Certification expectation: At least one senior cybersecurity/risk certification and one relevant specialist credential are preferred.
  • Leadership & Risk: CISSP, CISM, CRISC or CGEIT.
  • Audit & Compliance: CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, COBIT certification.
  • BCM & Resilience: CBCI/MBCI, CBCP, ISO 22301 Lead Implementer or Lead Auditor, or equivalent recognised BCM certification.
  • Privacy: CDPSE, CIPP, CIPM or ISO/IEC 27701 credential.
  • Emerging Technology: ISO/IEC 42001, CCSP, Open FAIR or equivalent.
  • Delivery: PMP, PRINCE2 or equivalent.


LOCATION


  • TM Annexe 2, Telekom Malaysia Berhad, Jalan Pantai Baharu, Kuala Lumpur.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More