Senior Principal Information Security Specialist

CISO OFFICE
Malaysia

Mid Senior level


SUMMARY OF RESPONSIBILITIES



  1. Assist in the development and execution of PayNet’s cyber and information security strategy.
  2. Provide technical and risk advisory on cyber and information security matters to various stakeholders.
  3. Assess the adequacy, effectiveness and relevancy of security controls through various assessment methods and approaches.
  4. Assess compliance to regulatory requirements and remediation efforts.
  5. Lead, execute or manage cybersecurity initiatives. 


KEY AREAS OF RESPONSIBILITIES


Cybersecurity strategy


  • Assist in the development, implementation, and operation of cyber security initiative and roadmap.
  • Responsible for the successful execution of cybersecurity initiatives.
  • Establish and enforce directive controls, validate internal detective and preventive security controls.


Work together with relevant stakeholders to achieve security objectives Security awareness Working and collaborating with a cross-functional team:


  • Develop new security awareness strategies leveraging new innovations.
  • Drive security culture and behavior internally through continuous security awareness programs.
  • Establish and embed cultural and behavioral goals in the cyber security strategy.


Lead continuous security awareness program for PayNet Cyber risk management, governance, and compliance Collaborating and teaming with Risk Management, IT Risk Management, and IT Security:



  • Provide advice to other stakeholders on technology risk and security matters, including developments in the PayNet’s technology security risk profile in relation to its business and operations.
  • Prepare security related reporting to the senior management, Group Risk Committee and the Board.
  • Establish and maintain threat models, monitor the cyber threat landscape and correlate with relevant cyber intelligence sources (formal and informal channels)
  • Perform risk and compliance assessments.


 QUALIFICATIONS & EXPERIENCE


Minimum Qualifications


  • Degree/Diploma in Information Technology (IT), Information Security or other related discipline
  • 12 or more years of working experience in data security, data protection, IT, cyber security, internal or external audit
  • Excellent people skills, decision making skills, organising and planning skills and leadership skills.


Technical requirements


  • Understanding of data privacy and data security principles
  • Familiarity with ISO 27001, NIST, CIS, MAS Technology Risk Management Guidelines or other information security management frameworks
  • Understanding of data protection laws and regulatory requirements such as MCIPD, PDPA, FSA or the GDPR, and experience with cybersecurity legislation
  • Knowledge of data protection related solutions and tools such as DLP, CASB and etc.
  • Knowledge of encryption algorithms, secure communications, and data protection methods
  • Understanding of data security and privacy laws and regulations
  • Understanding of IT operations and security and how IT interfaces with business, risk management and compliance processes would be an advantage
  • Experience in consulting background will be an added advantage
  • Relevant professional certifications such as CISSP, CISA, CEH, GPEN, CISM, ISO27001 auditor would be an advantage
  • Demonstrate ability to effectively apply knowledge of Project Management for efficient execution and management of assigned tasks
  • Strong conceptual, strategic and analytical thinking skills
  • Ability to document and explain technical details clearly and concisely to non-technical stakeholders
  • Able to work under broad direction and a self-motivated individual who is able to work independently
  • Responsible and accountable for work performed and decisions taken.  
APPLY

About the Company

Payments Network Malaysia

Embark on an exciting career journey with Payments Network Malaysia Sdn Bhd (PayNet), the heartbeat of Malaysia's financial markets!

As the national payments network and a pivotal infrastructure for Malaysia’s dynamic financial markets, PayNet is a linchpin in advancing the nation’s digital economy.

Our comprehensive suite of retail payment solutions - encompassing DuitNow (QR and P2P), JomPAY (Bill Payments), FPX (Online), MyDebit (Domestic Debit), MEPS (ATM), and IBG (Interbank GIRO) - not only offer wide accessibility but are seamlessly integrated into the fabric of daily life in Malaysia. These services have revolutionised the way Malaysians handle financial transactions, marking a significant leap in consumer convenience and efficiency.

At PayNet, our focus is on providing a safe, efficient, and innovative payments system. We are dedicated to improving and managing payment services that meet the evolving needs of consumers and businesses. Our work ensures the stability and reliability of Malaysia’s financial system, supporting the growth of the economy.

Learn more about our work and how we are contributing to Malaysia's financial future at www.paynet.my.

Join us in embracing digital payments and advancing Malaysia's financial landscape.