Incident, Threat & Vulnerability Management (Mid Senior | 10-15 Years of Exp)

Reposted 12 Hours Ago
Be an Early Applicant
Hiring Remotely in Cyberjaya, Sepang, Selangor, MYS
Remote
Senior level
Financial Services
The Role
Lead Incident, Threat & Vulnerability Management for TISO, ensuring incident readiness and response, governance, threat intelligence, and vulnerability management effectiveness in compliance with regulations.
Summary Generated by Built In
WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

 Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future.

 We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.

Job Title: Incident, Threat & Vulnerability Management
 

Role Purpose

The role leads the Incident, Threat & Vulnerability Management pillar for Technology Information Security Office (TISO) Malaysia, with end‑to‑end accountability for cyber incident readiness and response governance, threat intelligence oversight, vulnerability management effectiveness, and regulatory incident obligations.

This position serves as the country authority and coordinator for cyber incidents, threats, and vulnerabilities, ensuring strong alignment with Group TISO, regulators (BNM, PayNet, SC), and local stakeholders. The role is responsible for strategy, governance, service oversight, crisis coordination, and executive reporting, rather than day‑to‑day technical execution.

Key Responsibilities:

1) Incident Response & DFIR Governance (Country Lead)

  • Act as TISO Malaysia’s Incident Response Lead, accountable for readiness, escalation, coordination, and post‑incident assurance.

  • Own and maintain Malaysia CSIRT procedures, playbooks, escalation models, and crisis communication frameworks.

  • Coordinate cyber incident response activities with Group DFIR, Group CSOC, and external DFIR retainers.

  • Oversee forensic investigations, impact assessments, and root‑cause analysis performed by Group teams or external providers.

  • Ensure timely, accurate, and regulatory‑compliant incident reporting to BNM and relevant authorities.

  • Represent TISO MY in major cyber incidents, war rooms, executive briefings, and regulatory engagements.

2) Threat Intelligence & Monitoring Oversight

  • Provide country governance over Cyber Threat Intelligence (CTI) applicable to Malaysia.

  • Assess emerging threats, adversary campaigns, and geopolitical risks impacting OCBC MY.

  • Ensure timely dissemination of actionable threat advisories and threat‑led risk assessments.

  • Partner with Group CTI to translate global intelligence into local risk context and preparedness actions.

  • Support realistic threat‑based scenarios for cyber drills and simulations.

3) Vulnerability Management Governance

  • Provide end‑to‑end governance over vulnerability management effectiveness, including risk‑based prioritisation and remediation tracking.

  • Review and challenge remediation SLAs, risk acceptances, and prolonged exposures.

  • Oversee vulnerabilities across on‑prem, cloud, internet‑facing, and third‑party environments.

  • Escalate systemic or unmanaged vulnerability risks to senior management and risk committees.

4) Cyber Posture Monitoring & External Exposure

  • Oversee external attack surface monitoring, cyber exposure trends, and posture indicators.

  • Monitor Malaysia’s cyber posture on BNM FinTIP and relevant external platforms.

  • Provide consolidated risk views on incidents, threats, and vulnerabilities for management and Board visibility.

  • Contribute to Cyber Defense Roadmap and remediation prioritisation discussions.

5) Cyber Drills, Exercise & Readiness

  • Own the Malaysia cyber incident readiness programme, including:

    • Annual cyber drills and crisis simulations

    • Tabletop exercises for senior management

    • Industry and regulator‑driven exercises (e.g. RE4CT)

  • Ensure outcomes are embedded into process improvements, controls uplift, and capability development.

6) Group Interface & Cross-Functional Representation

  • Act as a key interface between MY TISO and Group TISO for:

    • Incident response alignment

    • Threat intelligence and vulnerability management matters

    • DFIR coordination and assurance activities

  • Interface with Group Operations & Technology on:

    • Cyber incidents impacting MY assets

    • Operational risk, resilience, and remediation matters

    • Cross‑border technology and security dependencies

  • Ensure MY‑specific concerns, risks, and regulatory obligations are clearly represented and escalated at Group forums.

7) Governance, Service Oversight & Assurance

  • Provide governance over outsourced cyber services (CSOC, CTI, Vulnerability Management, DFIR retainers, SMU).

  • Review service performance, KPIs, alerts quality, and improvement plans.

  • Chair or participate in Service Review meetings and assurance discussions.

  • Support internal audits, external audits, and regulatory examinations related to incident, threat, and vulnerability domains.

Key Qualifications & Experience:

Experience

  • 10–15+ years in cybersecurity, including senior leadership roles. in cybersecurity, including senior leadership roles.

  • Proven experience at VP / ED level within a regulated financial institution.

  • Direct exposure to major cyber incidents, regulatory escalations, and executive communications.

  • Strong understanding of BNM RMiT, PayNet, and Malaysian regulatory expectations.

  • Experience working with regional or global Group security functions.

Technical & Leadership Competencies

  • Strong understanding of:

    • Incident response lifecycle and crisis management

    • Threat actor TTPs and intelligence‑led defense

    • Vulnerability risk management and remediation governance

  • Ability to challenge technical outcomes and risk decisions without being hands‑on.

  • Strong executive presence, calm under pressure, and capable of Board‑level engagement.

Certifications (Preferred)

  • CISSP, CISM, GIAC (GCIH, GCFA, GREM) or equivalent senior‑level certifications.

What we offer:


Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Skills Required

  • 10-15+ years in cybersecurity, including senior leadership roles.
  • Proven experience at VP / ED level within a regulated financial institution.
  • Direct exposure to major cyber incidents, regulatory escalations, and executive communications.
  • Strong understanding of BNM RMiT, PayNet, and Malaysian regulatory expectations.
  • Experience working with regional or global Group security functions.
  • CISSP, CISM, GIAC (GCIH, GCFA, GREM) or equivalent senior-level certifications.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
0 Employees
Year Founded: 1932

What We Do

OCBC is the longest established Singapore bank, formed in 1932 from the merger of three local banks, the oldest of which was founded in 1912. It is now the second largest financial services group in Southeast Asia by assets and one of the world’s most highly-rated banks, with an Aa1 rating from Moody’s. Recognised for its financial strength and stability, OCBC is consistently ranked among the World’s Top 50 Safest Banks by Global Finance and has been named Best Managed Bank in Singapore by The Asian Banker. OCBC and its subsidiaries offer a broad array of commercial banking, specialist financial and wealth management services, ranging from consumer, corporate, investment, private and transaction banking to treasury, insurance, asset management and stockbroking services. OCBC’s key markets are Singapore, Malaysia, Indonesia and Greater China. It has more than 570 branches and representative offices in 19 countries and regions. These include about 300 branches and offices in Indonesia under subsidiary Bank OCBC NISP, and over 90 branches and offices in Mainland China, Hong Kong SAR and Macau SAR under OCBC Wing Hang. OCBC’s private banking services are provided by its wholly-owned subsidiary Bank of Singapore, which operates on a unique open-architecture product platform to source for the best-in-class products to meet its clients’ goals. OCBC's insurance subsidiary, Great Eastern Holdings, is the oldest and most established life insurance group in Singapore and Malaysia. Its asset management subsidiary, Lion Global Investors, is one of the largest private sector asset management companies in Southeast Asia.

Similar Jobs

MongoDB Logo MongoDB

Senior Solutions Architect

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
Malaysia
5550 Employees

Mondelēz International Logo Mondelēz International

Management Trainee

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
Selangor, MYS
90000 Employees

Mastercard Logo Mastercard

(Lead / Senior) Enterprise Operations Engineer (Tier 1 Global Network Support)

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
Selangor, MYS
38800 Employees

Mastercard Logo Mastercard

Senior Specialist, Specialist Sales, Acceptance and Merchant Solutions Southeast Asia

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
Selangor, MYS
38800 Employees

Similar Companies Hiring

Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account