Manage security governance, risk management, and compliance matters, ensuring that human resources are engaged and trained with relevant skills and knowledge.
Provide strategic leadership and oversight in the development, implementation, and continuous review of KWAP’s Cyber Security Policy, ensuring alignment with applicable laws, regulations, and industry standards, including the Cyber Security Act (Act 854), National Cyber Security Baseline (NCSB v1.3), ISO/IEC 27001:2022, and Personal Data Protection Act (PDPA).
Lead and oversee enterprise cloud security architecture, including Cloud Security Posture Management (CSPM), Zero Trust security frameworks, and cloud risk management across hybrid environments.
...
Maintain a comprehensive and up-to-date Obligations Register covering all applicable laws, regulations, licenses, and permits relevant to the business.
Monitor and manage all branch-level licenses and approvals, ensuring timely renewals and compliance with operational requirements.
Assess regulatory developments and translate them into actionable business impact and remediation plans, in collaboration with Legal and relevant stakeholders.
...
Provide expert-level IT security advisory for business initiatives, systems implementations, and operational processes to ensure alignment with security policies and risk appetite.
Review and assess IT change requests, vendor solutions, technology initiatives and third-party controls for security risks and recommend mitigation strategies.
Lead the planning, execution, and analyse cybersecurity simulation exercises (e.g., phishing, smishing) to test and enhance organizational readiness.
...