Routiqo

VP, Cybersecurity Strategy Governance & Projects

Bursa Malaysia

  • Kuala Lumpur
  • Full-time

To lead the cybersecurity strategy, governance and transformation agenda for Bursa Malaysia Group by driving strategic planning, executive governance, performance management and transformation oversight across the cybersecurity function. The role is responsible for ensuring cybersecurity priorities remain aligned with business objectives, regulatory expectations and enterprise risk considerations through effective governance, executive reporting, stakeholder engagement and strategic programme oversight. The position serves as the governance and transformation arm of the CISO Office, supporting executive decision-making, Board reporting and enterprise-wide coordination of cybersecurity initiatives.

  1. Cybersecurity Strategy Execution
  • Lead the development, maintenance and execution of the Group Cybersecurity Strategy and multi-year roadmap.
  • Facilitate enterprise-wide consultation and alignment on cybersecurity strategic initiatives.
  • Lead the preparation and coordination of cybersecurity reports, briefings and presentations for Board Committees, Executive Committees and senior management.
  • Ensure timely reporting of cybersecurity performance, strategic risks and transformation progress.
  • Lead cybersecurity maturity assessments and benchmarking to identify improvement opportunities and monitor alignment with regulatory expectations and industry standards.
  1. Cyber Transformation
  • Identify emerging strategic opportunities and initiatives to improve cyber resilience and organisational maturity.
  • Lead enterprise-wide cyber transformation initiatives from planning through implementation.
  • Monitor programme delivery, milestones, benefits realization and strategic outcomes.
  • Identify and escalate delivery risks, resource constraints and interdependencies.
  • Drive accountability across stakeholders responsible for delivering strategic cyber initiatives.
  1. Cyber Governance Framework Management
  • Establish and maintain governance structures, decision-making processes and accountability mechanisms for cybersecurity initiatives.
  • Oversee cybersecurity policy governance, exception management and governance forums.
  • Promote consistency and effectiveness of cyber governance practices across the Group.
  • Drive alignment between business, technology, risk and compliance stakeholders
  1. Audit & Regulatory Coordination
  • Lead coordination of cybersecurity-related audits, reviews and regulatory engagements.
  • Oversee management responses, remediation governance and closure tracking.
  • Ensure timely reporting and escalation of significant governance or compliance issues.
  • Coordinate enterprise responses to regulatory enquiries and information requests.
  1. Stakeholder & Enterprise Engagement
  • Build and maintain effective relationships with business divisions, technology teams, risk functions and corporate stakeholders.
  • Facilitate cross-functional collaboration on cybersecurity governance and transformation matters.
  1. Resource, Budget & Portfolio Governance
  • Oversee cybersecurity portfolio planning, resource allocation and investment governance.
  • Support development of business cases and funding proposals.
  • Monitor strategic programme expenditures and benefits realization.
  • Provide management visibility over portfolio performance and strategic priorities.
  1. Leadership & Capability Development
  • Lead and develop the Cyber Strategy, Governance & Transformation team.
  • Foster strong governance, programme management and strategic planning capabilities.
  • Promote a culture of accountability, collaboration and continuous improvement.
  • Act as a trusted advisor to the CISO on strategic, governance and transformation matters.
  1. Cyber Innovation & Emerging Risk Governance
  • Lead governance and oversight of cybersecurity risks arising from AI, cloud, data security, software supply chains and emerging technologies.
  • Assess cybersecurity implications of emerging technologies and digital transformation initiatives.
  • Develop cybersecurity standards and governance requirements for emerging technology adoption.
  • Report emerging trends, systemic concerns and risk breaches to management and Board governance forums.
  • Conduct horizon scanning on emerging cyber threats, technologies, regulatory developments and industry trends.