Drive enterprise-wide assessment and governance of security risks across Artificial Intelligence and emerging technologies, including GenAI misuse, adversarial machine learning, and Large Language Model (LLM) vulnerabilities.
Provide strategic oversight and advisory on compliance with Act 854, National Cyber Security Agency (NACSA) directives, Bank Negara Malaysia Risk Management in Technology (RMiT), and PDPA, ensuring the organisation maintains a robust and effective compliance posture.
Collaborate with legal and regulatory requirements, such as General Data Protection Regulation (GDPR), PDPA, Network and Information Security Directive 2 (NIS2), System and Organisation Controls 2 (SOC 2), Payment Card Industry Data Security Standard (PCI-DSS), and other applicable laws. Conduct internal security audits, gap assessments, and compliance reviews.
...
Act as the primary liaison with regulators, handling enquiries, inspections, and submissions.
Oversee the end-to-end personal data protection programme, including consent management, data access requests, retention policies, and vendor agreements.
Act as the designated data protection lead, coordinating with regional or group functions where required.
...
Monitor the implementation of risk mitigation plans and follow up with relevant departments to ensure timely closure of issues.
Participate in governance forums and act as a liaison to internal committees (e.g., Risk Management Department, Data Governance Office, etc) on matters relating to IT risk and security governance.
Prepare reports, presentations, and dashboards on cybersecurity risk posture, incidents, and remediation progress for internal stakeholders and management.
...