NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
19 days ago
Apply with autofill
Apply with autofill
Bjak·Fintech·19 days ago
19 days ago

Chief Information Security Officer

MalaysiaFull-timeHybridSenior · 8+ yearsCybersecurity Consultant

Sign up free to see how well your resume matches this role.

Boost your chances at Bjak

How you compare FREE

?
Your scoreYour score: not yet known
→
44
Top 10%Top 10%: 44 out of 100

Top 10% of NextRaise users matched against Cybersecurity Consultant roles in Malaysia.

Must-have skills for this role

  • cissp
  • cism
  • cisa
  • iso/iec 27001

PDF or DOCX · no account needed

Apply faster with autofill FREEBjak uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

About this role

About Doit

We are focused on reinventing how people spend, save, invest, exchange, travel, and more. Our objective is to build tools that will help people get more from their money and and become an expert at ease. We believe AI will help make finance smart, assessible and safe.

We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few. We have teams working around the world, with over 20 nationalities and growing from our offices and remotely. Join us and build a better future for our society.

In 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, it's the leading insurance platform in Southeast Asia.

About the Role

The CISO will own information security and technology risk for doit Holdings, our regulated investment platform in Malaysia, and will be the person the board names as responsible for technology risk under the Securities Commission's Guidelines on Technology Risk Management. Nothing exists yet. The framework, the controls, the monitoring and the evidence all have to be built, and they have to hold up to an independent assessment before the platform can be registered.

What you will be doing

  • Hold the board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.

  • Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.

  • Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.

  • Own incident response from detection through recovery, including the report to the SC on the day an incident occurs.

  • Take the platform through the independent technology validation that gates registration, and close what it finds.

  • Take ISO/IEC 27001 from scoping through to certification.

  • Deliver the annual cyber security awareness programme across the board, senior management and staff.

What you will need

  • Deep information security background, with at least 8 years in the field including 5 in financial services or another regulated sector.

  • At least one of CISSP, CISM or CISA. This is a requirement. These are the certifications the SC names as acceptable for the external party who assesses technology risk controls, and the officer who owns those controls should not sit below the standard set for the officer who audits them.

  • Deep command of the SC's Guidelines on Technology Risk Management, operationalised rather than restated.

  • Real depth in cyber security, operational resilience, and cloud and third-party risk.

  • ISO/IEC 27001 implementation experience through to certification.

  • A degree in computer science, information technology, information security or a cognate discipline, and able to meet the SC's fit and proper criteria.

  • ISO/IEC 27001 Lead Implementer or Lead Auditor, CRISC or CCSP, or experience of an SC or BNM technology examination, is useful.

  • Hands-on operating style. Able to review the controls, run the simulation and close the gaps personally.

Location

This is a hybrid role. You are expected to work from our local office at least 3 days per week, with the remaining days offering flexibility to work remotely.

Candidates should be based in, or able to work from, the location where the role is advertised.

Language

English is our main working language across global teams. Strong English communication is required.

Interview Process

Our process is designed to move fast:

1. Introductory conversation

2. Technical and regulatory deep dive

3. CEO / final round

For strong candidates, we aim to complete the process and make an offer within 1 week from the start of the interview process. Candidates who complete assessments quickly will be prioritized.

Fintech

Company

BjakFintech
Malaysia

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Bjak's careers site·first seen 3 Sept 2026·last verified 8 Sept 2026·How we source jobs

Similar jobs

  • Senior Manager Global Security Investigations APAC at AstraZenecaPetaling Jaya, Malaysia–match not yet calculated
  • Engineer, Security System Service at Johnson ControlsPetaling Jaya, Malaysia–match not yet calculated
  • Security Officer at Marriott InternationalWilayah Persekutuan Kuala Lumpur, Malaysia–match not yet calculated
  • Security Officer at accorhotelJohor Bahru, Malaysia–match not yet calculated
  • Information Security Officer_2758 at AllianzKuala Lumpur, Malaysia–match not yet calculated

Browse more jobs

  • Cybersecurity Consultant jobs in United States
  • Cybersecurity Consultant jobs in United Kingdom
  • Cybersecurity Consultant jobs in India
  • Retail Sales Associate jobs in United States