Key Responsibilities
1. Security Financial Management & Reporting
- Manage the Information Security budget and expenditure tracking for Malaysia.
- Monitor security-related operational and project costs against approved budgets.
- Prepare monthly, quarterly, and annual financial reports for cybersecurity initiatives.
- Perform budget forecasting and variance analysis to support management decision-making.
- Track security investment utilization and benefits realization.
- Coordinate budget planning and funding requests with Technology, Finance, and Security stakeholders.
- Support procurement governance, vendor cost reviews, and contract renewals related to security services.
2. Security Service Management & Reporting
- Establish and maintain governance over cybersecurity services provided locally and by Group Information Security (GIS).
- Define, monitor, and report on security service performance metrics and KPIs.
- Produce regular management dashboards covering security operations, incidents, vulnerabilities, compliance status, and service performance.
- Track service delivery against agreed service levels (SLAs) and operational objectives.
- Coordinate service improvement initiatives and remediation actions arising from performance gaps.
- Ensure appropriate documentation of security services, procedures, and operational controls.
3. Security Project Management & Reporting
- Govern and oversee cybersecurity projects from initiation through implementation and closure.
- Monitor project progress, risks, dependencies, milestones, budget consumption, and resource utilization.
- Prepare management reports and executive updates on security project status.
- Coordinate with project managers, technology teams, vendors, and business stakeholders to ensure timely delivery.
- Support project governance forums and steering committee meetings.
- Ensure cybersecurity projects align with regulatory requirements, organizational priorities, and security strategy.
4. Security Service Reviews (GIS, APTB, AGB)
- Coordinate periodic service review meetings with Group Information Security (GIS), APTB, AGB, and relevant stakeholders.
- Assess service effectiveness, performance trends, operational risks, and improvement opportunities.
- Track action items, remediation plans, and service enhancement initiatives arising from reviews.
- Prepare comprehensive service review reports and management presentations.
- Facilitate discussions between local and regional stakeholders to resolve service issues and improve service delivery.
5. Business Continuity Planning for Cybersecurity
- Support development, maintenance, and testing of cybersecurity-related Business Continuity Plans (BCP) and Disaster Recovery (DR) arrangements.
- Coordinate cyber resilience exercises, tabletop simulations, and recovery testing activities.
- Ensure cybersecurity recovery requirements are integrated into business continuity and technology resilience frameworks.
- Monitor remediation actions arising from resilience assessments and testing activities.
- Support crisis management processes during major cybersecurity incidents.
6. Enhancing Cybersecurity Awareness
- Develop and execute cybersecurity awareness and education programs for employees.
- Coordinate phishing simulation campaigns and awareness assessments.
- Promote a strong cybersecurity culture through communication campaigns, training sessions, and engagement initiatives.
- Track and report security awareness metrics, participation rates, and effectiveness indicators.
- Work with business units and Human Resources to ensure awareness programs meet organizational and regulatory requirements.
7. Governance, Risk, and Stakeholder Management
- Prepare reports and presentations for management committees and governance forums.
- Identify and escalate operational, compliance, and service risks to management.
Key Performance Indicators (KPIs)
- Timely submission of security governance, service, project, and financial reports.
- Achievement of security budget targets and financial governance requirements.
- Security service performance against agreed KPIs and SLAs.
- On-time delivery of cybersecurity projects and initiatives.
- Closure rate of actions arising from service reviews and governance meetings.
- Successful completion of cyber resilience and business continuity testing.
- Security awareness participation rates and phishing simulation improvements.