Routiqo

AVP, Cybersecurity Enterprise Governance & Operations

Bursa Malaysia

  • Kuala Lumpur
  • Full-time

Support the Vice President, Enterprise Governance & Operations in providing independent second-line oversight of cybersecurity risks, control effectiveness, operational resilience, third-party cyber risks and regulatory compliance across Bursa Malaysia.

The role is responsible for driving cyber assurance activities, challenging first-line cyber controls and risk management practices, monitoring remediation activities, and providing independent assessment of the organisation's cybersecurity posture. The position serves as a senior subject matter expert on cyber risk matters and contributes to strengthening the Exchange’s cyber resilience and regulatory compliance obligations.

  1. Cyber Risk Governance & Oversight
  • Support the maintenance and enhancement of the enterprise cybersecurity risk management framework.
  • Review and challenge cyber risk assessments performed by first-line functions.
  • Monitor cybersecurity risk exposure, key risk indicators (KRIs), risk appetite metrics and risk treatment plans.
  • Escalate emerging cyber risks and significant control weaknesses to management.
  1. Cyber Assurance & Independent Reviews
  • Lead and oversee cybersecurity assurance reviews across technology, cloud, infrastructure, applications, identity management and security operations domains.
  • Conduct thematic reviews and cyber maturity assessments against internal standards and recognised frameworks.
  • Assess effectiveness of cybersecurity controls and provide independent challenge to first-line management.
  • Validate closure of cybersecurity audit and assessment findings.
  1. Operational Resilience Oversight
  • Assess the effectiveness of cyber incident response, crisis management, business continuity and disaster recovery capabilities.
  • Review outcomes of cyber exercises, simulations and resilience testing activities.
  • Challenge remediation plans arising from incidents and recovery exercises.
  1. Regulatory Compliance Oversight
  • Monitor compliance with applicable cybersecurity regulatory requirements, standards and internal policies.
  • Support regulatory reviews, inspections and examinations related to cybersecurity.
  • Conduct regulatory gap assessments and monitor corrective actions.
  1. Third-Party Cyber Risk Oversight
  • Lead oversight activities relating to external parties connected to Bursa Malaysia's ecosystem.
  • Review cybersecurity assessments, penetration testing reports, forensic reports and remediation plans.
  • Monitor closure of cyber findings and provide recommendations on risk treatment and assurance requirements.
  1. Emerging Technology & Strategic Cyber Risk Assessments
  • Assess risks associated with emerging technologies including Artificial Intelligence (AI), cloud services, software supply chains and post-quantum cryptography.
  • Conduct horizon scanning and identify potential cyber threats and vulnerabilities that may impact Bursa Malaysia.
  1. Incident & Remediation Governance
  • Review cybersecurity incidents and independently assess the adequacy and closure of root causes, systemic issues, and corrective actions.
  • Validate effectiveness of remediation measures and lessons learned.
  • Support management reporting on cyber incidents, risk trends and remediation progress.
  1. Stakeholder Engagement & Advisory
  • Act as a trusted cyber risk advisor to internal stakeholders.
  • Provide technical cyber risk expertise during engagements with business divisions, technology teams, auditors and regulators.
  • Mentor and guide junior team members in cyber risk and assurance activities.
  1. Board / Committee Reporting
  • Support preparation and presentation of cybersecurity risk and assurance matters to Management Risk Committee, RMC and Board Committee forums.
  • Monitor Cyber Risk Appetite metrics, report threshold breaches and risk trends to Management and Board committees.