Security Framework Alignment: Define and maintain the Bank’s technical security standards, aligning them with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Review and update technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, and Network Access Control (NAC) systems and other security devices.
Audit & Compliance Remediation: Lead technical readiness for internal and external audits. Work directly with teams to track, prioritize, and validate the remediation of security findings and vulnerabilities.
...
Manage the daily operations of all security appliances and equipment, including Firewalls, Web Application Firewalls (WAF), Endpoint Detection and Response (EDR) solutions (e.g., FireEye), Intrusion Prevention Systems (IPS), and Network Access Control (NAC) systems.
Ensure optimal performance, availability, and configuration for all managed security components.
Ensure adherence to internal policies, industry best practices, and regulatory guidelines, such as Bank Negara Malaysia's RMiT.
...
Security Maturity & Roadmaps: Evaluate organizational security maturity, compliance gaps and threat models to deliver actionable, business-aligned security roadmaps.
Architecture & Secure Design: Assess and guide secure architecture patterns across cloud, hybrid environments, zero-trust frameworks, network defense, and IAM systems.
Architecture Review Board (ARB) Alignment: Serve as the primary security engineering liaison to the ARB, ensuring proposed solutions align smoothly with enterprise architecture standards.
...
Manage the daily operations of all security appliances and equipment, including Firewalls, Web Application Firewalls (WAF), Endpoint Detection and Response (EDR) solutions (e.g., FireEye), Intrusion Prevention Systems (IPS), and Network Access Control (NAC) systems.
Ensure optimal performance, availability, and configuration for all managed security components.
Ensure adherence to internal policies, industry best practices, and regulatory guidelines, such as Bank Negara Malaysia's RMiT.
...
Lead the delivery of ICT and security workstreams throughout the data centre construction lifecycle, from design and procurement through installation, testing, and commissioning.
Manage the implementation of physical security technologies, including Access Control Systems (ACS), CCTV, Perimeter Intrusion Detection Systems (PIDS), Visitor Management Systems (VMS), and Security Operations Centre (SOC) integrations.
Coordinate closely with clients, consultants, general contractors, M&E teams, vendors, and commissioning teams to ensure timely project delivery.
...
Lead the delivery of ICT and security workstreams throughout the data centre construction lifecycle, from design and procurement through installation, testing, and commissioning.
Manage the implementation of physical security technologies, including Access Control Systems (ACS), CCTV, Perimeter Intrusion Detection Systems (PIDS), Visitor Management Systems (VMS), and Security Operations Centre (SOC) integrations.
Coordinate closely with clients, consultants, general contractors, M&E teams, vendors, and commissioning teams to ensure timely project delivery.
...
Lead the delivery of ICT and security workstreams throughout the data centre construction lifecycle, from design and procurement through installation, testing, and commissioning.
Manage the implementation of physical security technologies, including Access Control Systems (ACS), CCTV, Perimeter Intrusion Detection Systems (PIDS), Visitor Management Systems (VMS), and Security Operations Centre (SOC) integrations.
Coordinate closely with clients, consultants, general contractors, M&E teams, vendors, and commissioning teams to ensure timely project delivery.
...
Set the overall direction by formulating and executing a comprehensive Group IT Security strategy for RHB Banking Group (including regional offices), ensuring a secure, resilient, and risk‑minimised IT environment that supports business objectives and complies with all applicable regulatory, legal and industry requirements.
The role is accountable for Group‑wide cyber security governance, technology controls, incident readiness, and security culture, while providing strategic advisory to the Board, senior management and regulators.
Define, own and continuously evolve the Group IT Security strategy, roadmap, and target maturity model, aligned with business priorities and regulatory expectations
...