SM, Cybersecurity Enterprise Governance & Operations
Bursa Malaysia
To support the execution of Bursa Malaysia’s second-line cybersecurity risk oversight, assurance and resilience activities through independent assessments, monitoring and challenge of cybersecurity risks, controls and regulatory compliance obligations.
The role is responsible for performing cyber risk assessments, assurance reviews, third-party cyber risk oversight, remediation validation and regulatory compliance monitoring to provide independent assurance of the Group's cybersecurity posture and operational resilience.
- Cyber Risk Assessment & Monitoring
- Conduct cybersecurity risk assessments across technology platforms, business processes and critical services.
- Review cybersecurity risks identified by first-line functions and challenge the appropriateness of risk ratings and treatment plans.
- Support maintenance of cyber risk registers, KRIs and risk reporting.
- Identify emerging cyber threats and risks that may impact the Exchange.
- Cyber Assurance Reviews
- Execute cybersecurity assurance reviews and thematic assessments to evaluate control effectiveness.
- Assess compliance against internal cybersecurity policies, standards and regulatory requirements.
- Document findings, recommendations and management action plans.
- Validate remediation activities to ensure identified gaps have been effectively addressed.
- Third-Party Cyber Risk Oversight
- Perform cybersecurity reviews of external parties connected to Bursa Malaysia's ecosystem.
- Review cybersecurity assessment reports, penetration testing reports and independent assurance reports.
- Monitor remediation status and closure of identified findings.
- Support third-party cyber assurance programmes and ecosystem-wide risk initiatives.
- Operational Resilience Oversight
- Assess effectiveness of cyber incident management, business continuity and disaster recovery capabilities.
- Review outcomes of cyber exercises, crisis simulations and resilience testing activities.
- Track remediation actions arising from incidents and operational resilience assessments.
- Regulatory Compliance Monitoring
- Support cybersecurity compliance reviews against applicable regulatory requirements and industry standards.
- Participate in regulatory assessments, inspections and reviews.
- Perform control gap assessments and monitor closure of regulatory findings.
- Incident & Remediation Governance
- Review significant cybersecurity incidents and evaluate adequacy of root cause analyses and corrective actions.
- Monitor progress of remediation efforts and provide independent assessment of closure effectiveness.
- Escalate significant cyber risk issues and recurring control weaknesses.
- Management Reporting & Documentation
- Prepare risk reports, assessment reports, dashboards and assurance summaries.
- Analyse trends, recurring findings and risk themes.
- Support preparation of materials for management committees and governance forums.
- Stakeholder Engagement & Advisory
- Engage technology teams, business units and risk stakeholders during assessments and reviews.
- Provide guidance on cybersecurity control expectations and regulatory requirements.
- Support awareness and adoption of cybersecurity risk management practices across the organization.


