AVP, Cybersecurity Enterprise Governance & Operations
Bursa Malaysia
Support the Vice President, Enterprise Governance & Operations in providing independent second-line oversight of cybersecurity risks, control effectiveness, operational resilience, third-party cyber risks and regulatory compliance across Bursa Malaysia.
The role is responsible for driving cyber assurance activities, challenging first-line cyber controls and risk management practices, monitoring remediation activities, and providing independent assessment of the organisation's cybersecurity posture. The position serves as a senior subject matter expert on cyber risk matters and contributes to strengthening the Exchange’s cyber resilience and regulatory compliance obligations.
- Cyber Risk Governance & Oversight
- Support the maintenance and enhancement of the enterprise cybersecurity risk management framework.
- Review and challenge cyber risk assessments performed by first-line functions.
- Monitor cybersecurity risk exposure, key risk indicators (KRIs), risk appetite metrics and risk treatment plans.
- Escalate emerging cyber risks and significant control weaknesses to management.
- Cyber Assurance & Independent Reviews
- Lead and oversee cybersecurity assurance reviews across technology, cloud, infrastructure, applications, identity management and security operations domains.
- Conduct thematic reviews and cyber maturity assessments against internal standards and recognised frameworks.
- Assess effectiveness of cybersecurity controls and provide independent challenge to first-line management.
- Validate closure of cybersecurity audit and assessment findings.
- Operational Resilience Oversight
- Assess the effectiveness of cyber incident response, crisis management, business continuity and disaster recovery capabilities.
- Review outcomes of cyber exercises, simulations and resilience testing activities.
- Challenge remediation plans arising from incidents and recovery exercises.
- Regulatory Compliance Oversight
- Monitor compliance with applicable cybersecurity regulatory requirements, standards and internal policies.
- Support regulatory reviews, inspections and examinations related to cybersecurity.
- Conduct regulatory gap assessments and monitor corrective actions.
- Third-Party Cyber Risk Oversight
- Lead oversight activities relating to external parties connected to Bursa Malaysia's ecosystem.
- Review cybersecurity assessments, penetration testing reports, forensic reports and remediation plans.
- Monitor closure of cyber findings and provide recommendations on risk treatment and assurance requirements.
- Emerging Technology & Strategic Cyber Risk Assessments
- Assess risks associated with emerging technologies including Artificial Intelligence (AI), cloud services, software supply chains and post-quantum cryptography.
- Conduct horizon scanning and identify potential cyber threats and vulnerabilities that may impact Bursa Malaysia.
- Incident & Remediation Governance
- Review cybersecurity incidents and independently assess the adequacy and closure of root causes, systemic issues, and corrective actions.
- Validate effectiveness of remediation measures and lessons learned.
- Support management reporting on cyber incidents, risk trends and remediation progress.
- Stakeholder Engagement & Advisory
- Act as a trusted cyber risk advisor to internal stakeholders.
- Provide technical cyber risk expertise during engagements with business divisions, technology teams, auditors and regulators.
- Mentor and guide junior team members in cyber risk and assurance activities.
- Board / Committee Reporting
- Support preparation and presentation of cybersecurity risk and assurance matters to Management Risk Committee, RMC and Board Committee forums.
- Monitor Cyber Risk Appetite metrics, report threshold breaches and risk trends to Management and Board committees.


